What Is Internet Firewall?
The internet boundary refers to the boundary between the internet and the Tencent Cloud private network. Internet boundary traffic is the traffic communicated between your cloud assets and the internet, also known as north-south traffic.
The Internet Firewall is a firewall that inspects north-south traffic and is a cluster-based firewall.
The Internet Firewall takes effect between the assets associated with your EIP and the external internet.
What Assets Does Internet Firewall Protect?
The current version supports the following asset types: CVM, CLB, NAT Gateway, and VPN Gateway. Currently, it supports assets in the Chinese mainland and Hong Kong (China) regions.
What Types of Public IP Addresses Do Not Appear in the Internet Firewall Switch List?
The current version supports BGP IP address as the public IP address type and does not currently support triple-line IP address. When identifying user assets, CFW automatically filters out triple-line IP addresses.
How to Scale Out to Enhance Protection When Public IP Address Quotas Are Insufficient
The Premium Edition, Enterprise Edition, and Ultimate Edition can have their specifications upgraded through elastic scaling out. For each 1 Mbps of bandwidth extended, one public IP address quota is added concurrently.
What Are Assets Labeled as "Other"?
The Internet Firewall identifies assets based on the user's public IP addresses. If a public IP address is not bound to any asset, it will be identified as "Other". Rules associated with this IP address will take effect normally after the IP address is bound to an asset.
Why Can IP Addresses Still Be Accessed After I Enable the Internet Firewall Toggle?
After enabling the Firewall Toggle for an IP address, go to Access Control and Internet Border Rule to check whether the rule policy type for that IP address is Block or Observe. Traffic is only blocked when the policy is set to Block. Details of the IP address rule policy types are as follows:
Pass: Allow the traffic that hits rules, record the number of hits and traffic logs, but do not record access control logs.
Observe: Allow traffic that hits rules and record the hit count, access control logs, and traffic logs.
Block: Block traffic that hits a rule, record the number of hits and Access Control logs, and log the information of a request packet in the traffic log.