tencent cloud

Firewall Manager
Firewall Manager (FWM) is a security policy management product that supports the centralized management of security policies across multiple accounts, products, and geographic regions, ensuring the consistency and efficient enforcement of security policies throughout the entire network. The product features intelligent analysis capabilities to identify rule redundancies, conflicts, and invalid configurations, while also providing optimization recommendations to effectively enhance rule quality and management efficiency.
Benefits of Firewall Manager
Full-Stack Rule Management

Firewall Manager supports unified management and automated deployment of rules across regions and multiple products, achieving centralized control of all policies, ensuring operational consistency, and reducing management costs in complex environments.

Full-Stack Rule Management

Firewall Manager supports unified management and automated deployment of rules across regions and multiple products, achieving centralized control of all policies, ensuring operational consistency, and reducing management costs in complex environments.

Intelligent Rule Analysis

Intelligent analysis identifies redundant, conflicting, and invalid rule configurations, providing optimization suggestions to effectively improve rule quality and product operation management efficiency.

Intelligent Rule Analysis

Intelligent analysis identifies redundant, conflicting, and invalid rule configurations, providing optimization suggestions to effectively improve rule quality and product operation management efficiency.

Full-Stack Rule Management

Firewall Manager supports unified management and automated deployment of rules across regions and multiple products, achieving centralized control of all policies, ensuring operational consistency, and reducing management costs in complex environments.

Intelligent Rule Analysis

Intelligent analysis identifies redundant, conflicting, and invalid rule configurations, providing optimization suggestions to effectively improve rule quality and product operation management efficiency.

Variety of solutions for your needs
Unified Policy Management
Policy Analysis and Maintenance
Scenario Pain Points
Currently, there are multiple forms of "firewalls" in the cloud, including VPC security groups, Lighthouse firewalls, CFW, WAF, etc. Users report functional overlaps between multiple products, and data independence between products prevents direct migration, making operations difficult when using them simultaneously, with expectations for unified management capabilities.
Solution
  • Build a unified cloud firewall management platform that integrates various firewall forms including enterprise security groups and Lighthouse firewalls.
  • Provides enterprise security groups with advanced rule encapsulation, automatically deploying rules to security groups based on customer protection requirements.
  • Significantly reduces operational complexity and ensures consistency and efficient execution of network-wide security policies.
Value Points
Reduces configuration complexity and improves operational efficiency.
Scenario Pain Points
Large number of existing rules, concerns about business impact prevent easy adjustments. Security product rule configuration is complex, unclear how to achieve desired protection effects.
Solution
  • Utilizes big data technology to deeply analyze existing rules, accurately identify redundant, conflicting, and invalid rule configurations
  • providing optimization suggestions to effectively improve product performance.
Value Points
Improves rule management efficiency, solves complex configuration challenges, and enhances network security.
Help and Documentation
Help and Documentation
Firewall Manager is currently in public beta and the product is available for free trial.
Quick Start
Helps you quickly understand, create, and log in to Firewall Manager. (Link not available)
FAQS

Frequently

asked questions

Which product rules does Firewall Manager support managing?

Firewall Manager currently supports managing enterprise security group and private network security group rules (current version enterprise security group supports asset types including: VPC, SUBNET, CVM, ENI, CLB, TDSQL, TDSQL-C, MYSQL, MARIADB, SQLSERVER, POSTGRESQL, REDIS, MONGODB, LIGHTHOUSE).

What is an enterprise security group?

Enterprise security group is a new security group control plane that redesigns security group configuration logic, maintains a unified access control management interface, greatly optimizing the security group user experience. Firewall Manager provides a five-tuple-based rule configuration interface and automatically deploys security group policies through intelligent conversion algorithms, significantly simplifying security group configuration operations.

What are the advantages of enterprise security groups?

1. Automatically generates one inbound rule and one outbound rule when configuring rules;

2. Eliminates the concept of inbound and outbound rule directions, only requiring definition of access source and destination to complete rule configuration;

3. Removes regional restrictions, all rules are displayed in the same interface, making operations management more convenient;

4. Adds configuration options such as IP/CIDR, regions, etc., with symmetric arrangement of options allowing arbitrary combinations;

5. When configuring IP addresses for access sources or destinations, automatically matches instances corresponding to the IP.

Can security groups maintained by Firewall Manager be directly modified in the private network console?

No. Rules deployed from Firewall Manager - Enterprise Security Group to Private Network - Security Group cannot be directly modified in the private network console. Reasons:

1. Rules manually modified in Private Network - Security Group will not be reflected in the Firewall Manager - Enterprise Security Group page, leading to inconsistent rule information display and hindering rule maintenance management.

2. When rules are updated in Firewall Manager - Enterprise Security Group, they are synchronously deployed to Private Network - Security Group, overwriting manually modified rules in Private Network - Security Group, affecting network security protection.

Is there an upper limit for rules deployed from enterprise security groups to Lighthouse application server firewalls?

The upper limit for rules deployed from enterprise security groups to Lighthouse application server firewalls is the inherent rule limit of Lighthouse itself, which cannot exceed 100 rules. Rules cannot be deployed if this limit is exceeded.

FAQS

Frequently

asked questions

Which product rules does Firewall Manager support managing?

Firewall Manager currently supports managing enterprise security group and private network security group rules (current version enterprise security group supports asset types including: VPC, SUBNET, CVM, ENI, CLB, TDSQL, TDSQL-C, MYSQL, MARIADB, SQLSERVER, POSTGRESQL, REDIS, MONGODB, LIGHTHOUSE).

What is an enterprise security group?

Enterprise security group is a new security group control plane that redesigns security group configuration logic, maintains a unified access control management interface, greatly optimizing the security group user experience. Firewall Manager provides a five-tuple-based rule configuration interface and automatically deploys security group policies through intelligent conversion algorithms, significantly simplifying security group configuration operations.

What are the advantages of enterprise security groups?

1. Automatically generates one inbound rule and one outbound rule when configuring rules;

2. Eliminates the concept of inbound and outbound rule directions, only requiring definition of access source and destination to complete rule configuration;

3. Removes regional restrictions, all rules are displayed in the same interface, making operations management more convenient;

4. Adds configuration options such as IP/CIDR, regions, etc., with symmetric arrangement of options allowing arbitrary combinations;

5. When configuring IP addresses for access sources or destinations, automatically matches instances corresponding to the IP.

Can security groups maintained by Firewall Manager be directly modified in the private network console?

No. Rules deployed from Firewall Manager - Enterprise Security Group to Private Network - Security Group cannot be directly modified in the private network console. Reasons:

1. Rules manually modified in Private Network - Security Group will not be reflected in the Firewall Manager - Enterprise Security Group page, leading to inconsistent rule information display and hindering rule maintenance management.

2. When rules are updated in Firewall Manager - Enterprise Security Group, they are synchronously deployed to Private Network - Security Group, overwriting manually modified rules in Private Network - Security Group, affecting network security protection.

Is there an upper limit for rules deployed from enterprise security groups to Lighthouse application server firewalls?

The upper limit for rules deployed from enterprise security groups to Lighthouse application server firewalls is the inherent rule limit of Lighthouse itself, which cannot exceed 100 rules. Rules cannot be deployed if this limit is exceeded.

Follow our Quick Start Guide to start using Firewall Manager with simple operations. Free trial is supported during the public beta period.