If your Virtual Private Clouds (VPCs) are connected by a VPC Peering Connection, you can use a VPC Firewall to protect the traffic between them. This topic describes how to configure a VPC Firewall for a VPC Peering Connection.
Features
Protection topology
For more information about the protection scope, see What is Cloud Firewall?
Impact on services
You can create a VPC Firewall to protect your assets without changing your network topology. The creation process takes about 5 minutes and does not affect your services. We recommend that you enable the VPC Firewall during off-peak hours.
Enabling or disabling a VPC Firewall takes 5 to 30 minutes, depending on the number of route entries. During this process, long-lived connections may experience brief disconnections lasting a few seconds. Short-lived connections are not affected.
Before you enable the VPC Firewall, we recommend that you check whether your applications support automatic TCP retransmission. You should also closely monitor the connection status of your applications to prevent interruptions caused by a missing retransmission mechanism.
Limitations
Limit | Description | Recommendation |
Traffic type limit |
| None |
Routing limit | VPC Firewall does not support the protection of routes with a /32 subnet mask in a VPC Peering Connection. If you enable the VPC Firewall for such a route, network access to the destination CIDR block is interrupted. | We recommend that you change the subnet mask prefix to a value of 30 or smaller before you enable the VPC Firewall. If you have questions, submit a to consult product technical experts. |
Create and enable a VPC Firewall
Prerequisites
You have activated Cloud Firewall Enterprise Edition, Ultimate Edition, or Pay-As-You-Go Edition. For more information, see Purchase Cloud Firewall.
NoteOnly Cloud Firewall Enterprise Edition, Ultimate Edition, and Pay-As-You-Go Edition support VPC Firewall. Premium Edition does not support this feature.
You have authorized Cloud Firewall to access your cloud resources. For more information, see Authorize Cloud Firewall to access cloud resources.
You have created a VPC Peering Connection instance to connect VPCs. For more information, see Use VPC Peering Connection to connect VPCs.
Make sure that your network resources are deployed in regions that support VPC Firewall. For more information, see Supported regions.
After you create a VPC Firewall, modifying the VSwitches or route tables in the associated VPC may cause traffic interruptions.
Rollback and pause are not supported during the VPC wall-opening process. If an exception occurs, the system automatically rolls back.
Procedure
Log on to the Cloud Firewall console. In the left-side navigation pane, click Firewall.
On the VPC Firewall tab, click the Peering Connection subtab.
On the Peering Connection subtab, click Synchronize Assets. The system synchronizes assets for your account and its member accounts.
This process takes 1 to 2 minutes.
Find the VPC Peering Connection instance that you want to protect and click Create in the Actions column.
If you have a large number of VPC Peering Connection instances, you can filter the list by region or VPC instance.
In the Create VPC Firewall dialog box, configure the parameters.
Parameter
Description
Instance Name
Use a descriptive name for easy identification.
Connection Type
This field is automatically set to VPC Peering Connection and cannot be changed.
VPC
Confirm the VPC region and instance, select the Route Table to protect, and then enter the Destination CIDR Block.
Route table
When you create a VPC, a default route table is automatically created to manage traffic by adding system routes. You can create multiple route tables as needed. For more information, see Route table overview.
In the Cloud Firewall console, the console automatically reads your VPC route table information. A VPC Peering Connection supports multiple route tables. You can view and select the specific route tables that you want to protect.
Destination CIDR block
When you select a route table, its default destination CIDR block automatically appears. You can manually modify the destination CIDR block to protect other network segments. You can add multiple CIDR blocks, separated by commas (,).
ImportantAfter the VPC Firewall is enabled, you must manually edit its configuration to add protected CIDR blocks.
Peer VPC
Confirm the peer VPC's region and instance, select the Route Table to protect, and then enter the Destination CIDR Block.
ImportantAfter the VPC Firewall is enabled, you must manually edit its configuration to add protected CIDR blocks.
IPS
Select an Intrusion Prevention System (IPS) policy:
IPS mode
Monitor Mode: Identifies and logs malicious traffic without blocking it.
Block Mode: Blocks malicious traffic to prevent intrusions. Three strictness levels are available:
Block Mode - Loose
Blocking Mode - Medium
Block Mode - Strict
IPS Capabilities
Basic Rules: Provides basic protection against threats such as brute-force attacks, command execution vulnerabilities, and command and control (C&C) server callbacks.
Virtual Patching: Provides real-time defense against high-risk application vulnerabilities.
Enable VPC Firewall
Enable this option to automatically activate the VPC Firewall after it is created.
Click Submit and confirm the action.
NoteAfter you enable the VPC Firewall, it may take 15 to 30 minutes for Cloud Firewall to learn the routes if you add or delete VPC route table information. We recommend that you wait for the route learning process to complete and then verify that the route table is effective. If you have any questions, submit a to consult product technical experts.
After you create the VPC Firewall, Cloud Firewall automatically creates the following resources in the associated VPC:
Custom route table entries with the following remarks:
Created by cloud firewall. Do not modify or delete it..When you enable the VPC Firewall, the system automatically creates a security group named Cloud_Firewall_Security_Group and configures an Authorization Policy for it to allow traffic to the VPC Firewall.
ImportantDo not delete the Cloud_Firewall_Security_Group security group or its authorization policy. Otherwise, traffic cannot be redirected to the VPC Firewall.
To prevent service interruptions, perform batch operations or frequently enable and disable the VPC Firewall only during off-peak hours.
On the Peering Connection subtab, turn on the switch for the VPC Firewall that you created.
Cloud Firewall can protect your network resources only when the VPC Firewall is enabled. The VPC Firewall is enabled when its Firewall Status changes to Enabled.
More operations
Disable a VPC Firewall
Disabling a VPC Firewall may cause transient traffic disconnections.
If you need to disable a VPC Firewall, go to the Peering Connection subtab, find the target firewall instance, and then turn off its Firewall.
The VPC Firewall is disabled when its Firewall Status changes to Disabled.
Delete a VPC Firewall
Deleting a VPC Firewall may cause transient traffic disconnections.
If you no longer need a VPC Firewall, go to the Peering Connection subtab, find the target firewall instance, and then click Delete in the Actions column.
Edit a VPC Firewall
If you need to modify the configuration of a VPC Firewall, go to the Peering Connection subtab, find the target firewall instance, and then click Edit in the Actions column.
Modify IPS configuration
To change the IPS mode or capabilities, add IP addresses to a whitelist, or modify IPS rules, click Configure IPS in the Actions column for the firewall instance. Configure the settings on the VPC Border tab of the IPS Configuration page. For more information, see Configure IPS settings.
Related documents
After you enable a VPC Firewall, you can configure VPC Firewall access control policies to control traffic between VPCs.
Once you enable the VPC Firewall, you can use the VPC traffic logs feature to view traffic between VPCs.
After you enable a VPC Firewall, you can use the VPC Protection feature to view information about security events that Cloud Firewall intercepts between VPCs.