This topic describes the key concepts and use cases of the Cloud Firewall VPC firewall.
What is a VPC firewall
A VPC firewall inspects and controls traffic between Virtual Private Clouds (VPCs) and between VPCs and on-premises data centers. If your VPCs are connected through a Cloud Enterprise Network (CEN) or an Express Connect circuit, you can create a VPC firewall to control traffic between VPCs and between VPCs and your on-premises data centers.
VPC firewalls also support cross-account management. For example, consider a scenario where account A owns a Cloud Enterprise Network (CEN) instance and VPC_1, while account B owns VPC_2. If both VPCs are connected through the CEN instance of account A, you can use account A to purchase Cloud Firewall Enterprise Edition or Ultimate Edition to protect the traffic between VPC_1 and VPC_2.
How it works
For architecture diagrams of how the VPC firewall works, see the following topics:
Protection scope
Cloud Firewall provides three types of VPC firewalls. You can choose the one that best fits your network topology.
|
VPC Firewall Type |
Scenario |
Operation Guide |
|
VPC Firewall for Enterprise Edition Transit Router |
Supports protection for:
Does not support protection for: Traffic between multiple CCNs |
|
|
VPC Firewall for Basic Edition Transit Router |
Supports protection for:
Does not support protection for:
|
|
|
VPC Firewall for Express Connect |
Supports protection for:
Does not support protection for:
Note
If you need to protect cross-region, cross-account VPC traffic, or traffic between VPCs and VBRs, we recommend using Cloud Enterprise Network. For more information, submit a . |
VPC firewalls do not support the jumbo frame feature.
Specifications
VPC firewall specifications have two key metrics: the number of VPC firewall instances and the traffic processing capacity.
|
Specification |
Description |
Subscription |
Pay-as-you-go |
|
Number of VPC firewall instances |
The maximum number of VPC firewall instances that you can create. |
The quota depends on the number of VPC firewall instances that you create and the VPC traffic processing capacity that you purchase. If your quota is insufficient, you can upgrade the specifications. For more information, see Configure a VPC firewall for an Enterprise Edition transit router. Quotas vary based on the Cloud Firewall edition. For more information, see Subscription 2.0. Note
If your traffic exceeds the purchased processing capacity of Cloud Firewall, the service level agreement (SLA) does not apply. This can trigger service degradation, such as failures of security features such as access control policies (ACLs), the intrusion prevention system (IPS), and log auditing. It may also result in the deactivation of firewall protection for assets that generate excessive traffic, or packet loss due to throttling. If you expect traffic spikes that may exceed your quota, we recommend that you use the pay-as-you-go for elastic traffic billing method. |
Billing is based on the actual number of protected instances and the total processed traffic. No quota limits apply. For more information about billing, see Pay-as-you-go 2.0. |
|
VPC traffic processing capacity |
The maximum peak traffic that can be protected between VPCs. |
Asset protection and quota usage
You can view the protection status of assets in your account on the VPC Firewall page.
-
Log on to the Cloud Firewall console. In the left-side navigation pane, click Firewall.
-
The VPC Firewall tab shows the number of uncreated and created VPC firewalls, and the available quota for your account. You can also view the total number of network elements, as well as the number of unprotected and protected network elements.
If you exhaust the available quota for your edition, click Increase Quota to increase it. For more information about the number of VPC firewall instances supported by each edition, see Subscription 2.0.
In the Protected Network Elements section, a tip indicates that the displayed data is deduplicated.
-
In the VPC Firewall section, click the
icon to view the number of uncreated and created firewall instances for Cloud Enterprise Network (CEN) (Enterprise Edition), Cloud Enterprise Network (CEN) (Basic Edition), and Express Connect. -
In the Protected Network Elements section, click the
icon to view the total, unprotected, and protected numbers of network elements, including VPCs, VBRs, TRs, and VPN gateways.
The data is calculated as follows:
-
Cloud Enterprise Network (CEN) (Enterprise Edition)
-
Unprotected network elements: The number of network elements that are not protected by a VPC firewall. This includes VPCs, VBRs, TRs, and VPN gateways. This count excludes network elements that are managed in manual mode.
-
Protected network elements: The number of network elements that are protected by a VPC firewall. This includes VPCs, VBRs, TRs, and VPN gateways. This count excludes network elements that are managed in manual mode.
-
Available quota: The number of VPC firewall instances that you have enabled. Each CEN transit router consumes one quota.
-
-
Cloud Enterprise Network (CEN) (Basic Edition)
-
Unprotected network elements: The number of VPCs that are not protected by a VPC firewall.
-
Protected network elements: The number of VPCs that are protected by a VPC firewall.
-
Available quota: The number of VPC firewall instances that you have enabled. Each VPC consumes one quota.
-
-
Express Connect
-
Unprotected network elements: The number of VPCs that are not protected by a VPC firewall.
-
Protected network elements: The number of VPCs that are protected by a VPC firewall.
-
Available quota: The number of VPC firewall instances that you have enabled. Each pair of VPCs, consisting of a local VPC and its peer VPC, consumes one quota.
-