Alibaba Cloud Cloud Firewall is a Software as a Service (SaaS) firewall that provides unified security isolation and control for your cloud assets across internet, VPC, and NAT boundaries. It is the first line of network defense for your cloud business.
Use cases
Cloud Firewall is suitable for the following typical scenarios:
Enterprise-grade security for cloud data centers
Ideal for enterprises migrating to the cloud or building large-scale data centers. Cloud Firewall provides unified traffic control and threat protection across internet, NAT, VPC, and host boundaries. It reduces the public attack surface, blocks lateral movement attacks, and prevents data exfiltration.
Advanced protection for hybrid clouds and cloud-based DMZs
Suitable for scenarios where services are deployed across both on-premises data centers and the cloud, or where the DMZ is migrated to the cloud. Cloud Firewall protects north-south traffic in the DMZ and east-west traffic between data centers and VPCs, ensuring secure communication in a hybrid cloud environment.
Unified security management for multiple accounts
Ideal for enterprises with resources distributed across multiple Alibaba Cloud accounts. Cloud Firewall integrates with Resource Directory to centralize asset management, policy configuration, traffic analysis, and log audit in a single console, reducing security operations costs.
Security for high-stakes scenarios and adversarial drills
Suitable for high-stakes scenarios such as major events and security drills. Cloud Firewall supports features like batch blocking of IP addresses or domains, attack tracing, and virtual patching for zero-day vulnerabilities to meet special security requirements.
Why choose Cloud Firewall
Compared to traditional hardware firewalls, Cloud Firewall offers the following core advantages:
Instant activation, ready to use
You can enable the Internet firewall with a single click without modifying your network architecture, significantly reducing deployment and configuration costs.
Unified boundary control, integrated protection
Cloud Firewall provides unified traffic control for internet, NAT, VPC, and host boundaries, enabling integrated management of access control, threat detection, and log audit for both north-south and east-west traffic.
Intelligent defense, proactive threat interception
Using its built-in intrusion prevention (IPS) engine and extensive threat intelligence, Cloud Firewall detects and blocks malicious traffic in real time, including vulnerability exploits, brute-force attacks, crypto-mining programs, and backdoors. It also supports virtual patching to protect vulnerable hosts before official patches are released.
Elastic and stable, on-demand scaling
Cloud Firewall's traffic processing capacity can scale smoothly with your business needs, making it ideal for peak traffic scenarios such as promotions, tests, or security drills. During off-peak periods, it can scale down seamlessly without impacting your services and effectively reduces costs. A built-in high-availability mechanism supports dual-AZ disaster recovery for different firewall clusters, ensuring business continuity.
Core features
Enable firewall protection
Cloud Firewall provides unified traffic control for the Internet boundary, NAT boundary, and VPC boundary. Once enabled, it applies access control and threat detection to north-south and east-west traffic for your cloud assets.
Internet firewall: Protects inbound traffic from the public internet. It supports policies based on IP address, port, protocol, and domain name to block scanning and attacks that target public assets such as ECS and Server Load Balancer (SLB) instances.
NAT firewall: Manages traffic from private assets that access the internet through a NAT Gateway. It prevents internal hosts from connecting to a C2 server or leaking data and supports deep inspection with IPS.
VPC firewall: Manages traffic between VPCs and between subnets within a VPC. It prevents lateral movement attacks and supports access control based on DNS domain names to achieve network micro-segmentation.
Traffic analysis
This feature provides traffic visualization to help you identify abnormal behavior and potential risks.
Outbound Connections: Monitors connections from internal hosts to the public internet. It identifies behaviors such as crypto-mining, remote control, and data exfiltration, and supports tracing by destination IP, port, protocol, and time.
Public Exposure: Automatically discovers publicly accessible assets and services, assesses exposure risks, and helps you reduce your attack surface.
VPC Inter-Traffic: Displays traffic topology and access relationships between and within VPCs to help you optimize your network architecture and security policies.
Protection configuration
This section allows you to configure access control and intrusion prevention policies.
IPS Protection: Uses threat intelligence and an attack detection engine to intercept attacks such as vulnerability exploits, webshell uploads, and SQL injection. It also supports virtual patching for protection before official patches are released.
Access Control Policies: Supports policies based on the 5-tuple (source/destination IP, port, protocol), domain name, application type, and geographic location. Policy templates and batch operations are also supported.
Detection and response
This feature provides security event alerts, log audit, and analysis functions.
Security Events: The IPS protection engine aggregates detections into the following three types of alerts:
Intrusion Prevention: Records and intercepts external attack attempts and malicious traffic.
Vulnerability Protection: Monitors exploitation attempts against known vulnerabilities.
Compromised Host Detection: Identifies abnormal outbound connections or lateral movement from compromised internal hosts.
Log audit: Provides 7 days of free log storage to meet basic compliance and forensics needs.
Log analysis: Supports extending the log storage duration (such as the 180-day storage duration required by Classified Protection compliance) and provides multi-dimensional search and statistical analysis capabilities.
Editions and billing
Cloud Firewall is available in four editions: Pay-as-you-go, Premium Edition, Enterprise Edition, and Ultimate Edition. Choose the edition that best suits your business needs.
This table highlights the core differences between editions. For a complete feature comparison, see Compare and select an edition.
For detailed pricing information, see Subscription (Billing 2.0) (for Premium, Enterprise, and Ultimate Editions) and Pay-as-you-go (Billing 2.0) (for the Pay-as-you-go edition).
Edition | Pay-as-you-go | Premium Edition | Enterprise Edition | Ultimate Edition |
Billing model | pay-as-you-go | subscription | ||
Feature support | Basic protection | Basic protection | Full-featured protection | Full-featured protection |
Recommended scenarios |
|
|
| |
Get started
After you activate Cloud Firewall, follow these steps to configure it:
Enable protection for your assets
Enable the Internet firewall for your public assets (required). For more information, see Internet firewall. Based on your business needs, enable protection for your public NAT gateways and VPC assets. For more information, see NAT firewall and VPC firewall.
Review the IPS configuration
The IPS threat engine is enabled by default for general protection. You can adjust the configuration later based on your business needs. For more information, see IPS configuration.
Configure access control policies
The default access control policies are permissive and do not block malicious traffic. You must configure policies based on your business needs to avoid blocking legitimate traffic. For more information, see Access control policies. If you are unsure what policies to configure, see Configure an access control policy.
Analyze traffic and audit logs
After Cloud Firewall has been running for some time, go to the Traffic analysis and log audit pages to view traffic patterns and security events. Adjust your IPS configuration and access control policies based on the analysis. To retain logs for a longer period, enable and configure the log analysis feature, which supports full log querying and auditing.
Configure advanced features
In addition to basic functions, Cloud Firewall offers advanced features such as Security Operation Agent, TLS Inspection, Application Control, and Web Filtering (some in public or invite-only beta) to meet more granular security and operational needs.
FAQ
Differences between WAF, Cloud Firewall, and Anti-DDoS
Web Application Firewall (WAF): A security product dedicated to the HTTP/HTTPS application layer. WAF performs deep inspection of web requests to defend against application-layer attacks.
Cloud Firewall (CFW): A unified network perimeter access control product for cloud environments. CFW manages traffic and provides intrusion prevention at Internet, VPC, and NAT boundaries to prevent network-layer intrusion and lateral movement.
Anti-DDoS: Protects against large-scale distributed denial-of-service (DDoS) attacks by redirecting traffic to globally distributed scrubbing centers. Anti-DDoS filters malicious traffic to maintain service stability and availability during attacks.
Cloud product | Web Application Firewall (WAF) | Cloud Firewall (CFW) | Anti-DDoS |
Protection level | Application layer (L7) | Provides primary network-layer and transport-layer (L3-L4) protection and includes an integrated IPS for Layer 4-7 intrusion detection. | Provides primary protection at the Network and Transport layers (L3-L4) and defends against high-volume CC and HTTP Flood attacks at the Application Layer (L7). |
Core mechanism | Semantic analysis, rule matching, and behavior modeling | Access control policies, stateful inspection, and intrusion prevention system (IPS) | Traffic scrubbing, signature-based filtering, and bandwidth scaling |
Defensible attacks | SQL injection, XSS, webshell uploads, HTTP flood attacks, malicious bots, and API abuse | Port scanning, brute-force attacks, unauthorized access, cryptomining worms, and east-west traffic threats | L3/L4 volumetric attacks such as SYN flood and UDP flood, and L7 application-layer attacks such as high-frequency HTTP floods |
Use cases | Defend websites and apps against tampering, malicious access, bot scraping, and API abuse. | Enforce unified access policies for cloud assets at public network entry and exit points. Prevent brute-force attacks on servers and lateral movement within internal networks. | Ensure service continuity and network availability during high-volume attacks with zero packet loss. |
For a defense-in-depth strategy, we recommend a combined architecture of Anti-DDoS Pro and Anti-DDoS Premium, Cloud Firewall, and WAF.
Product integration and traffic path
Yes. Cloud Firewall can be deployed with other cloud products. The traffic path is shown in the following figure.
Instance quantity calculation
By default, new users use Billing 2.0. In this model, a Cloud Firewall subscription provides a general-purpose instance specification, which can be used to create different boundary firewalls. For example, the Premium Edition subscription provides one general-purpose instance specification.
The number of consumed Cloud Firewall instances is calculated as follows:
Internet firewall: One instance is required for each protected region. Within the same region, only one instance specification is consumed, regardless of the number of protected public IP addresses or whether the IP addresses are IPv4 or IPv6.
NAT firewall: One instance is required for each NAT Gateway instance.
VPC firewall:
In a Cloud Enterprise Network (CEN) Enterprise Edition architecture, one instance is required for each Transit Router (TR).
In a CEN Basic Edition architecture, one instance is required for each VPC.
In a VPC peering connection architecture, one instance is required for each pair of VPCs.
Multi-account Management: If you enable this feature, the assets of each member account consume a Cloud Firewall instance specification and incur a separate instance fee.
Compliance certifications
Cloud Firewall is certified for ISO 9001, ISO 20000, ISO 22301, ISO 27001, ISO 27017, ISO 27018, ISO 29151, ISO 27701, BS 10012, CSA STAR, and PCI DSS.
Product origin
Alibaba Cloud developed Cloud Firewall entirely in-house. It is not an OEM product from a third-party vendor.