tencent cloud

Product Strengths

Download
Mode fokus
Ukuran font
Terakhir diperbarui: 2026-07-30 15:56:03

Easy to Enable and No Deployment Required

CFW uses the software-defined networking (SDN) technology to provide a SaaS firewall on the public cloud, ensuring automatic identification of cloud assets and one-click enabling/disabling of the firewall service. It can be used with simple policy configurations and provides CFW features without deployment costs (when compared with traditional hardware deployment).

High Stability and Reliability, and Smooth Expansion

CFW has a primary-secondary disaster recovery mechanism to ensure stable and reliable performance. At the same time, it fully leverages the strengths of SaaS services to support elastic scaling of bandwidth, assets, and storage, enabling on-demand assignment and smooth scaling.

Unified Management and Control, High Efficiency, and Ease of Use

CFW provides unified access control and security isolation capabilities for traffic between the Internet or VPCs. In addition, it also offers a unified access control plane for users.
Internet boundary access control: Based on the access control rules configured for public IP addresses, CFW can be used to block or observe threatening access destination traffic, and prevent external threat access sources from launching attacks on cloud assets.
NAT firewall access control: Access control rules are configured based on private network assets to perform traffic control and security protection, blocking abnormal external connections.
VPC boundary access control: Based on the access control rules configured between VPCs within a tenant, CFW can be used to control access behaviors between VPCs, achieving security isolation between VPCs.
Enterprise Security Group: It retains the configuration habits based on the five-tuple, facilitating the management of security group configurations. It meets the protection requirements for scenarios between VPC subnets, between VPCs, and across hybrid cloud dedicated lines. In addition, it supports block logs, enabling you to easily build a DMZ zone on the cloud.
CFW adheres to the rule configuration modes of traditional firewalls and combines the use cases of security Ops personnel, which helps reduce your learning costs and improve usability.

Cybersecurity Classified Protection Compliance Service and Log Audit

CFW helps meet the requirements for boundary protection and Access Control specified in the Multi-Level Protection Scheme (MLPS).
Rule hit logs: When an access control rule takes effect and is hit, CFW will record the five-tuple information of the hit traffic and provide the corresponding rule to facilitate your security Ops. When a fault occurs, you can rapidly troubleshoot and fix it based on log retention.
User operation logs: Record the user operation information in CFW, including login operations of all accounts, CFW toggle operations, and operations such as adding, deleting, and editing rules. User operation logs help improve management efficiency and reduce management costs.

Bantuan dan Dukungan

Apakah halaman ini membantu?

masukan