All Products
Search
Document Center

Cloud Firewall:VPC firewall overview

Last Updated:Jun 20, 2026

This topic describes the key concepts and use cases of the Cloud Firewall VPC firewall.

What is a VPC firewall

A VPC firewall inspects and controls traffic between Virtual Private Clouds (VPCs) and between VPCs and on-premises data centers. If your VPCs are connected through a Cloud Enterprise Network (CEN) or an Express Connect circuit, you can create a VPC firewall to control traffic between VPCs and between VPCs and your on-premises data centers.

VPC firewalls also support cross-account management. For example, consider a scenario where account A owns a Cloud Enterprise Network (CEN) instance and VPC_1, while account B owns VPC_2. If both VPCs are connected through the CEN instance of account A, you can use account A to purchase Cloud Firewall Enterprise Edition or Ultimate Edition to protect the traffic between VPC_1 and VPC_2.

How it works

For architecture diagrams of how the VPC firewall works, see the following topics:

Protection scope

Cloud Firewall provides three types of VPC firewalls. You can choose the one that best fits your network topology.

VPC Firewall Type

Scenario

Operation Guide

VPC Firewall for Enterprise Edition Transit Router

Supports protection for:

  • Traffic between multiple VPCs in the same region

  • Traffic between multiple VPCs across regions through Enterprise Edition Transit Router

  • Traffic between VPCs and Virtual Border Routers (VBRs) (that is, traffic between VPCs and on-premises data centers)

  • Traffic between VPCs and Cloud Connect Networks (CCNs)

  • Traffic between multiple VBRs

  • Traffic between CCNs and VBRs

  • Traffic between VPCs and public VPNs

Does not support protection for: Traffic between multiple CCNs

Connect multiple CCNs

VPC Firewall for Basic Edition Transit Router

Supports protection for:

  • Traffic between multiple VPCs in the same region

  • Traffic between multiple VPCs across regions through Basic Edition Transit Router

  • Traffic between VPCs and Virtual Border Routers (VBRs) (that is, traffic between VPCs and on-premises data centers)

  • Traffic between VPCs and Cloud Connect Networks (CCNs)

Does not support protection for:

  • Traffic between multiple VBRs

  • Traffic between CCNs and VBRs

  • Traffic between multiple CCNs

Configure the VPC firewall for a Cloud Enterprise Network

VPC Firewall for Express Connect

Supports protection for:

  • Traffic between multiple VPCs of the same account in the same region in Express Connect VPC mode

  • Traffic between multiple VPCs in the same region (including same-account and cross-account) in VPC peering mode

Does not support protection for:

  • Cross-account and cross-region traffic between multiple VPCs in Express Connect VPC mode

  • VPC and Virtual Border Router (VBR) (VBR) (Virtual Border Router) mutual access traffic

Note

If you need to protect cross-region, cross-account VPC traffic, or traffic between VPCs and VBRs, we recommend using Cloud Enterprise Network. For more information, submit a .

Configure the VPC firewall for a peering connection

Note

VPC firewalls do not support the jumbo frame feature.

Specifications

VPC firewall specifications have two key metrics: the number of VPC firewall instances and the traffic processing capacity.

Specification

Description

Subscription

Pay-as-you-go

Number of VPC firewall instances

The maximum number of VPC firewall instances that you can create.

The quota depends on the number of VPC firewall instances that you create and the VPC traffic processing capacity that you purchase. If your quota is insufficient, you can upgrade the specifications. For more information, see Configure a VPC firewall for an Enterprise Edition transit router.

Quotas vary based on the Cloud Firewall edition. For more information, see Subscription 2.0.

Note

If your traffic exceeds the purchased processing capacity of Cloud Firewall, the service level agreement (SLA) does not apply. This can trigger service degradation, such as failures of security features such as access control policies (ACLs), the intrusion prevention system (IPS), and log auditing. It may also result in the deactivation of firewall protection for assets that generate excessive traffic, or packet loss due to throttling.

If you expect traffic spikes that may exceed your quota, we recommend that you use the pay-as-you-go for elastic traffic billing method.

Billing is based on the actual number of protected instances and the total processed traffic. No quota limits apply. For more information about billing, see Pay-as-you-go 2.0.

VPC traffic processing capacity

The maximum peak traffic that can be protected between VPCs.

Asset protection and quota usage

You can view the protection status of assets in your account on the VPC Firewall page.

  1. Log on to the Cloud Firewall console. In the left-side navigation pane, click Firewall.

  2. The VPC Firewall tab shows the number of uncreated and created VPC firewalls, and the available quota for your account. You can also view the total number of network elements, as well as the number of unprotected and protected network elements.

    If you exhaust the available quota for your edition, click Increase Quota to increase it. For more information about the number of VPC firewall instances supported by each edition, see Subscription 2.0.

    In the Protected Network Elements section, a tip indicates that the displayed data is deduplicated.

  3. In the VPC Firewall section, click the 查看 icon to view the number of uncreated and created firewall instances for Cloud Enterprise Network (CEN) (Enterprise Edition), Cloud Enterprise Network (CEN) (Basic Edition), and Express Connect.

  4. In the Protected Network Elements section, click the 查看 icon to view the total, unprotected, and protected numbers of network elements, including VPCs, VBRs, TRs, and VPN gateways.

The data is calculated as follows:

  • Cloud Enterprise Network (CEN) (Enterprise Edition)

    • Unprotected network elements: The number of network elements that are not protected by a VPC firewall. This includes VPCs, VBRs, TRs, and VPN gateways. This count excludes network elements that are managed in manual mode.

    • Protected network elements: The number of network elements that are protected by a VPC firewall. This includes VPCs, VBRs, TRs, and VPN gateways. This count excludes network elements that are managed in manual mode.

    • Available quota: The number of VPC firewall instances that you have enabled. Each CEN transit router consumes one quota.

  • Cloud Enterprise Network (CEN) (Basic Edition)

    • Unprotected network elements: The number of VPCs that are not protected by a VPC firewall.

    • Protected network elements: The number of VPCs that are protected by a VPC firewall.

    • Available quota: The number of VPC firewall instances that you have enabled. Each VPC consumes one quota.

  • Express Connect

    • Unprotected network elements: The number of VPCs that are not protected by a VPC firewall.

    • Protected network elements: The number of VPCs that are protected by a VPC firewall.

    • Available quota: The number of VPC firewall instances that you have enabled. Each pair of VPCs, consisting of a local VPC and its peer VPC, consumes one quota.