All Products
Search
Document Center

Cloud Firewall:What is Cloud Firewall

Last Updated:Sep 11, 2026

Alibaba Cloud Cloud Firewall is a Software as a Service (SaaS) firewall that provides unified security isolation and control for your cloud assets across internet, VPC, and NAT boundaries. It is the first line of network defense for your cloud business.

Use cases

Cloud Firewall is suitable for the following typical scenarios:

  • Enterprise-grade security for cloud data centers

    Ideal for enterprises migrating to the cloud or building large-scale data centers. Cloud Firewall provides unified traffic control and threat protection across internet, NAT, VPC, and host boundaries. It reduces the public attack surface, blocks lateral movement attacks, and prevents data exfiltration.

  • Advanced protection for hybrid clouds and cloud-based DMZs

    Suitable for scenarios where services are deployed across both on-premises data centers and the cloud, or where the DMZ is migrated to the cloud. Cloud Firewall protects north-south traffic in the DMZ and east-west traffic between data centers and VPCs, ensuring secure communication in a hybrid cloud environment.

  • Unified security management for multiple accounts

    Ideal for enterprises with resources distributed across multiple Alibaba Cloud accounts. Cloud Firewall integrates with Resource Directory to centralize asset management, policy configuration, traffic analysis, and log audit in a single console, reducing security operations costs.

  • Security for high-stakes scenarios and adversarial drills

    Suitable for high-stakes scenarios such as major events and security drills. Cloud Firewall supports features like batch blocking of IP addresses or domains, attack tracing, and virtual patching for zero-day vulnerabilities to meet special security requirements.

Why choose Cloud Firewall

Compared to traditional hardware firewalls, Cloud Firewall offers the following core advantages:

  • Instant activation, ready to use

    You can enable the Internet firewall with a single click without modifying your network architecture, significantly reducing deployment and configuration costs.

  • Unified boundary control, integrated protection

    Cloud Firewall provides unified traffic control for internet, NAT, VPC, and host boundaries, enabling integrated management of access control, threat detection, and log audit for both north-south and east-west traffic.

  • Intelligent defense, proactive threat interception

    Using its built-in intrusion prevention (IPS) engine and extensive threat intelligence, Cloud Firewall detects and blocks malicious traffic in real time, including vulnerability exploits, brute-force attacks, crypto-mining programs, and backdoors. It also supports virtual patching to protect vulnerable hosts before official patches are released.

  • Elastic and stable, on-demand scaling

    Cloud Firewall's traffic processing capacity can scale smoothly with your business needs, making it ideal for peak traffic scenarios such as promotions, tests, or security drills. During off-peak periods, it can scale down seamlessly without impacting your services and effectively reduces costs. A built-in high-availability mechanism supports dual-AZ disaster recovery for different firewall clusters, ensuring business continuity.

Core features

Enable firewall protection

Cloud Firewall provides unified traffic control for the Internet boundary, NAT boundary, and VPC boundary. Once enabled, it applies access control and threat detection to north-south and east-west traffic for your cloud assets.

  • Internet firewall: Protects inbound traffic from the public internet. It supports policies based on IP address, port, protocol, and domain name to block scanning and attacks that target public assets such as ECS and Server Load Balancer (SLB) instances.

  • NAT firewall: Manages traffic from private assets that access the internet through a NAT Gateway. It prevents internal hosts from connecting to a C2 server or leaking data and supports deep inspection with IPS.

  • VPC firewall: Manages traffic between VPCs and between subnets within a VPC. It prevents lateral movement attacks and supports access control based on DNS domain names to achieve network micro-segmentation.

Traffic analysis

This feature provides traffic visualization to help you identify abnormal behavior and potential risks.

  • Outbound Connections: Monitors connections from internal hosts to the public internet. It identifies behaviors such as crypto-mining, remote control, and data exfiltration, and supports tracing by destination IP, port, protocol, and time.

  • Public Exposure: Automatically discovers publicly accessible assets and services, assesses exposure risks, and helps you reduce your attack surface.

  • VPC Inter-Traffic: Displays traffic topology and access relationships between and within VPCs to help you optimize your network architecture and security policies.

Protection configuration

This section allows you to configure access control and intrusion prevention policies.

  • IPS Protection: Uses threat intelligence and an attack detection engine to intercept attacks such as vulnerability exploits, webshell uploads, and SQL injection. It also supports virtual patching for protection before official patches are released.

  • Access Control Policies: Supports policies based on the 5-tuple (source/destination IP, port, protocol), domain name, application type, and geographic location. Policy templates and batch operations are also supported.

Detection and response

This feature provides security event alerts, log audit, and analysis functions.

  • Security Events: The IPS protection engine aggregates detections into the following three types of alerts:

  • Log audit: Provides 7 days of free log storage to meet basic compliance and forensics needs.

  • Log analysis: Supports extending the log storage duration (such as the 180-day storage duration required by Classified Protection compliance) and provides multi-dimensional search and statistical analysis capabilities.

Editions and billing

Cloud Firewall is available in four editions: Pay-as-you-go, Premium Edition, Enterprise Edition, and Ultimate Edition. Choose the edition that best suits your business needs.

Note

Edition

Pay-as-you-go

Premium Edition

Enterprise Edition

Ultimate Edition

Billing model

pay-as-you-go
Billed based on actual usage (features + traffic) for flexible scaling.

subscription
Includes a fixed specification. Traffic that exceeds the bandwidth specification is billed on a pay-as-you-go basis. More cost-effective for stable traffic.

Feature support

Basic protection
Includes the Internet firewall and the NAT firewall (north-south protection).

Basic protection
Includes the Internet firewall and the NAT firewall (north-south protection).

Full-featured protection
Includes all Premium Edition features and advanced features such as security group configuration and service visualization.

Full-featured protection
Includes all Enterprise Edition features, with some features supporting higher, customizable specifications.

Recommended scenarios

  • Feature evaluation, testing, or personal learning

  • Workloads with large traffic peak fluctuations

  • Users who prefer to configure and enable features on demand

  • Public network (north-south) traffic protection for small and medium-sized enterprises

  • Smaller bandwidth requirements (<30Mbps)

  • Public network and VPC private network (north-south and east-west) traffic protection for large enterprises

  • Protection for architectures that use Cloud Enterprise Network, Express Connect, or on-premises IDCs connected to cloud VPCs

  • Large bandwidth requirements and complex traffic isolation and control needs

Get started

After you activate Cloud Firewall, follow these steps to configure it:

  1. Enable protection for your assets

    Enable the Internet firewall for your public assets (required). For more information, see Internet firewall. Based on your business needs, enable protection for your public NAT gateways and VPC assets. For more information, see NAT firewall and VPC firewall.

  2. Review the IPS configuration

    The IPS threat engine is enabled by default for general protection. You can adjust the configuration later based on your business needs. For more information, see IPS configuration.

  3. Configure access control policies

    The default access control policies are permissive and do not block malicious traffic. You must configure policies based on your business needs to avoid blocking legitimate traffic. For more information, see Access control policies. If you are unsure what policies to configure, see Configure an access control policy.

  4. Analyze traffic and audit logs

    After Cloud Firewall has been running for some time, go to the Traffic analysis and log audit pages to view traffic patterns and security events. Adjust your IPS configuration and access control policies based on the analysis. To retain logs for a longer period, enable and configure the log analysis feature, which supports full log querying and auditing.

  5. Configure advanced features

    In addition to basic functions, Cloud Firewall offers advanced features such as Security Operation Agent, TLS Inspection, Application Control, and Web Filtering (some in public or invite-only beta) to meet more granular security and operational needs.

FAQ

Differences between WAF, Cloud Firewall, and Anti-DDoS

  • Web Application Firewall (WAF): A security product dedicated to the HTTP/HTTPS application layer. WAF performs deep inspection of web requests to defend against application-layer attacks.

  • Cloud Firewall (CFW): A unified network perimeter access control product for cloud environments. CFW manages traffic and provides intrusion prevention at Internet, VPC, and NAT boundaries to prevent network-layer intrusion and lateral movement.

  • Anti-DDoS: Protects against large-scale distributed denial-of-service (DDoS) attacks by redirecting traffic to globally distributed scrubbing centers. Anti-DDoS filters malicious traffic to maintain service stability and availability during attacks.

Cloud product

Web Application Firewall (WAF)

Cloud Firewall (CFW)

Anti-DDoS

Protection level

Application layer (L7)

Provides primary network-layer and transport-layer (L3-L4) protection and includes an integrated IPS for Layer 4-7 intrusion detection.

Provides primary protection at the Network and Transport layers (L3-L4) and defends against high-volume CC and HTTP Flood attacks at the Application Layer (L7).

Core mechanism

Semantic analysis, rule matching, and behavior modeling

Access control policies, stateful inspection, and intrusion prevention system (IPS)

Traffic scrubbing, signature-based filtering, and bandwidth scaling

Defensible attacks

SQL injection, XSS, webshell uploads, HTTP flood attacks, malicious bots, and API abuse

Port scanning, brute-force attacks, unauthorized access, cryptomining worms, and east-west traffic threats

L3/L4 volumetric attacks such as SYN flood and UDP flood, and L7 application-layer attacks such as high-frequency HTTP floods

Use cases

Defend websites and apps against tampering, malicious access, bot scraping, and API abuse.

Enforce unified access policies for cloud assets at public network entry and exit points. Prevent brute-force attacks on servers and lateral movement within internal networks.

Ensure service continuity and network availability during high-volume attacks with zero packet loss.

For a defense-in-depth strategy, we recommend a combined architecture of Anti-DDoS Pro and Anti-DDoS Premium, Cloud Firewall, and WAF.

Product integration and traffic path

Yes. Cloud Firewall can be deployed with other cloud products. The traffic path is shown in the following figure.

image

Instance quantity calculation

By default, new users use Billing 2.0. In this model, a Cloud Firewall subscription provides a general-purpose instance specification, which can be used to create different boundary firewalls. For example, the Premium Edition subscription provides one general-purpose instance specification.

The number of consumed Cloud Firewall instances is calculated as follows:

  • Internet firewall: One instance is required for each protected region. Within the same region, only one instance specification is consumed, regardless of the number of protected public IP addresses or whether the IP addresses are IPv4 or IPv6.

  • NAT firewall: One instance is required for each NAT Gateway instance.

  • VPC firewall:

    • In a Cloud Enterprise Network (CEN) Enterprise Edition architecture, one instance is required for each Transit Router (TR).

    • In a CEN Basic Edition architecture, one instance is required for each VPC.

    • In a VPC peering connection architecture, one instance is required for each pair of VPCs.

  • Multi-account Management: If you enable this feature, the assets of each member account consume a Cloud Firewall instance specification and incur a separate instance fee.

Compliance certifications

Cloud Firewall is certified for ISO 9001, ISO 20000, ISO 22301, ISO 27001, ISO 27017, ISO 27018, ISO 29151, ISO 27701, BS 10012, CSA STAR, and PCI DSS.

Product origin

Alibaba Cloud developed Cloud Firewall entirely in-house. It is not an OEM product from a third-party vendor.