What Is CFW?
Tencent Cloud Firewall (CFW) is a SaaS-based firewall designed for public cloud environments. It currently provides users with internet boundary protection and addresses unified management and Log Auditing for cloud-based Access Control. While offering traditional firewall features, it also supports multi-tenancy and elastic scaling in the cloud. CFW serves as the network security infrastructure for migrating user services to the cloud.
Product Features
Cloud Firewall Overview
CFW provides a unified network Access Control Center for users. On the Console Overview page, users can clearly and intuitively view firewall-related content, which includes the following modules: Asset Protection Overview: Displays the quantity of user public network assets, private network assets, exposed ports, and security events, and provides users with vulnerability intelligence for reference.
Firewall Status Monitoring: Displays the peak bandwidth values for the internet boundary and the NAT boundary over the past 7 days.
Traffic Statistics: Displays the inbound and outbound traffic volume, as well as the total traffic volume, within a time range from 24 hours to 6 months.
Security Policy Configuration: Displays the number of Access Control rules, the remaining quota, and the security policies adopted for Intrusion Defense for the internet boundary, NAT boundary, and VPC boundary.
Log Storage Statistics: Displays the total log memory, current memory, and remaining available capacity.
Cloud Firewall Switch
Internet Firewall Toggle: The system automatically identifies the public IP addresses, associated instances, and bound assets of cloud tenants, and manages Access Control protection at the public IP address granularity through the CFW toggle. Currently, CFW supports BGP public IP addresses (tri-carrier IP addresses are not supported, similarly hereinafter). Through the public IP address list (asset list) in the CFW toggle, users can quickly view the existing outbound or inbound rules associated with each public IP address and perform unified management via the Access Control module.
VPC Firewall Toggle: The system automatically identifies the number of VPCs within a cloud tenant's private network, along with their connectivity status and methods, and presents this information through a visual VPC network topology view. When using the VPC Firewall for the first time, you need to enable the unified VPC Firewall toggle. After the toggle is enabled, the system automatically configures sub-firewalls for all pairwise relationships between interconnected VPCs. You can enable or disable these sub-firewalls and also configure Access Control rules based on the pairwise relationships between VPCs.
NAT Firewall Toggle: The NAT Firewall is a virtualized firewall. Its principle is similar to that of a NAT Gateway. The NAT Firewall provides network address translation capabilities, as well as security auditing features such as Access Control and log retention.
After a NAT firewall instance is activated and created, the system automatically identifies the subnets within the VPC in the selected region. Users only need to locate the subnet to be connected and enable the firewall switch. The system then automatically modifies the subnet route to redirect the Internet traffic of the subnet to the NAT firewall. Users can configure access control lists on the NAT firewall to filter out and manage traffic.
Asset center
The Asset Center allows you to view and manage the relevant data and information of each asset. By reviewing the details of the TOP5 core assets, the TOP5 high-risk assets, and all your public network assets, private network assets, and VPCs, you can better control the asset status, manage assets, and predict and prevent security incidents.
Alarm Center
The Alarm Center allows you to view alarm events triggered when assets are under network attack. After you configure all the required security policies for CFW in the Access Control, Intrusion Defense, and Security Baseline modules, you can perform security Ops for network boundary protection by continuously monitoring alarms from CFW.
Traffic Center
The Traffic Center is a visual information page that categorizes traffic based on internet outbound and inbound traffic, as well as inter-VPC traffic access. It is divided into sections for external access statistics, active outbound connections analysis, and inter-VPC activity.
Access Control
Access Control rules are a collection of security policies, defined in the form of five-tuples and arranged in a list. For each data flow passing through the internet boundary, CFW matches the five-tuple information according to the execution order of the rule list. If a matching data flow is found, the corresponding operation is performed on that data flow according to the action of the hit rule. This meets tenants' needs for Access Control protection of public IP addresses and fulfills users' requirements for security Ops auditing through log recording. The Enterprise Security Group addresses protection scenarios between VPC subnets, between VPCs, and across hybrid cloud dedicated lines. By maintaining the configuration habit based on five-tuples, it becomes easier to manage and control security group configurations.
Intrusion Defense
CFW automatically identifies unknown risks beyond the access control rules based on its protection mode. It conducts intrusion prevention rule detection on the north-south traffic of public network IP addresses. It also prevents vulnerabilities in CVM from being exposed to the Internet.
Network honeypot
The Network Honeypot service is a simulated business system that does not actually host any real business. After being exposed in a tenant's network through probes, if it is triggered by an attacker, it actively records attacker information and traces attack methods. This provides accurate attacker intelligence and countermeasure tracing capabilities for the defense of real business. In guarantee for important periods scenarios, it buys sufficient time for real business to achieve the goal of successful defense.
Security Baseline
A security baseline refers to a process where CFW observes traffic access over a certain period to generate a preliminary list of IP addresses or domains. Users can then maintain this baseline list by adding or removing IP addresses or domains based on security scores, associated security events, and network access conditions, thereby forming the final security baseline.
Log Audit
CFW provides a rule hit log recording feature that retains data for 7 days. This feature records all network traffic processed by firewall actions and the corresponding effective rules, assisting security Ops personnel in audit work. When network connection failures or similar issues occur, you can quickly troubleshoot and fix them by searching the logs. Additionally, you can view operation history from the past 30 days, which improves the work efficiency of enterprise and network security administrators and reduces management costs.
Log Analysis
In Log Analysis, you can view the details of all traffic logs stored over the past 6 months by the CFW associated with your login account. Additionally, Log Analysis supports log search and query based on search statements and provides reporting and statistical analysis services.
Address Template
This feature provides users with a more convenient and faster way to manage IP addresses and domains in batches. In the address template, users can create IP address or domain templates, add multiple IP addresses or domains, and then match the created templates with relevant rules in Access Control.