All Products
Search
Document Center

Cloud Firewall:VPC Access

Last Updated:Nov 22, 2023

The VPC access feature of Cloud Firewall provides real-time information about traffic between virtual private clouds (VPCs). The feature helps you identify unusual traffic and mitigate risks at the earliest opportunity. This topic describes how to view data that is displayed in the following sections and tabs: Ranking of IP Addresses by Traffic, Ranking of Sessions Between VPCs, Open Ports, and Asset.

Prerequisites

A VPC firewall is created and enabled. For more information, see Configure a VPC firewall for an Enterprise Edition transit router.

Procedure

  1. Log on to the Cloud Firewall console.

  2. In the left-side navigation pane, choose Traffic Analysis > VPC Access.

  3. In the upper-right corner of the VPC Access page, specify a time range for query.

    You can select a time range from the drop-down list. You can also specify a custom time range within the last seven days.

  4. In the upper-left corner of the VPC Access page, specify the local VPC and peer VPC for query.

    When you specify a peer VPC, you can select a specific VPC or select All VPC Firewalls.

    Section or tab

    Description

    Supported operation

    Traffic Between VPCs

    This section displays the peak traffic and average traffic between the specified VPCs, and trend charts for both inbound and outbound traffic.

    View traffic-based rankings: On a traffic trend chart, click a point in time. The top IP addresses that are involved in the traffic at that point in time are displayed in the Ranking of IP Addresses by Traffic section.

    Ranking of IP Addresses by Traffic

    This section displays the rankings of top 10, top 20, or top 50 IP addresses by traffic. You can view IP, Inbound, and Outbound. By default, the rankings of top 50 IP addresses are displayed.

    View logs: Find the IP address that you want to manage and click View Logs in the Actions column. On the VPC Border page, view the log details of the VPC to which the IP address belongs.

    Ranking of Sessions Between VPCs

    This section displays the rankings of sessions between VPCs. You can view Ranking, Session, Sessions, Traffic, Port, and View Proportion.

    View the proportion of ports by session: Find the session data record of an IP address and click View in the View Proportion column. In the Open Port Proportion section, view the proportion of ports that are involved in the session.

    Open Port Proportion

    By default, this section displays the distribution of all open ports.

    None.

    Open Ports

    This tab displays the data of open ports that are used for the traffic between VPCs. You can view Local Open Port, Protocol, Application, Access Traffic, Requests, Local Asset IP Address, and Risk Level.

    View the details of an open port: Find the local open port that you want to manage and click View Details in the Actions column. In the Port Access Details panel, view the details of the port.

    View logs: In the Port Access Details panel, find the peer IP address that corresponds to the local open port and click View Logs in the Actions column. On the VPC Firewall tab of the Traffic Logs tab, view the log details of the IP address.

    Note

    To download the data of open ports to a CSV file on your computer, you can click the 下载 icon in the upper-right corner above the port list. This way, you can view the data or use the data for analysis in a more convenient manner.

    Asset

    This tab displays the data of assets that are involved in traffic between VPCs. You can view Local Asset IP Address, Local Instance ID/Name, Local Port, Access Traffic, Requests, and Risk Level.

    View the details of an asset: Find the local asset that you want to manage and click View Details in the Actions column. In the Asset Access Details panel, view the details of the asset.

    View logs: In the Asset Access Details panel, find the peer IP address that corresponds to the asset and click View Logs in the Actions column. On the VPC Firewall tab of the Traffic Logs tab, view the log details of the IP address.

    Note

    To download the data of assets to a CSV file on your computer, you can click the 下载 icon in the upper-right corner above the asset list. This way, you can view the data or use the data for analysis in a more convenient manner.