Cloud Firewall (CFW) is a next-generation cloud-native firewall. It protects the Internet border and VPC border on the cloud by real-time intrusion detection and prevention, global unified access control, full traffic analysis, log audit, and tracing. It employs AI for intelligent defense, and can meet changing business needs, helping you easily handle security threats. CFW is a basic service that provides network security protection for user services on the cloud.

Protection Type | Protected Object | Reference |
|---|---|---|
Internet border | Elastic IPs (EIPs). The Elastic Cloud Servers (ECSs), NAT gateways, Elastic Load Balance (ELB), or other resources that are bound to EIPs can be protected. | |
VPC border | Virtual Private Cloud (VPC), Virtual Gateway (VGW), and Virtual Private Network (VPN) |
CFW has integrated security capabilities and network threat intelligence. Its AI intrusion prevention engine can detect and block malicious traffic in real time. It works with other security services globally to defend against Trojans, worms, injection attacks, vulnerabilities, and phishing attacks.
CFW can implement refined control on all traffic, including Internet border and cross-VPC traffic, to prevent external intrusions, internal penetration attacks, and unauthorized access from internal to external networks. Its cluster is deployed in HA mode to protect your workloads under heavy traffic.
As a cloud-native firewall, CFW can be enabled easily to import multi-engine security policies with a few clicks, automatically check assets within seconds, and to provide a UI to simplify operations, greatly improving management and defense efficiency.
For details about the features and differences between editions, see Features.