The VPC Firewall feature can detect and collect statistics on traffic between connected VPCs. This feature helps you detect attacks and perform troubleshooting. You can enable or disable this feature in the Cloud Firewall console.
Prerequisites
- A Cloud Enterprise Network (CEN) or Express Connect instance is purchased and two VPCs have been connected by using the instance. For more information, see Interconnect two VPCs under the same account.
- A VPC firewall is created. You must create a VPC firewall before you enable the VPC Firewall feature. For more information, see Create a VPC firewall.
Background information
After the VPC Firewall feature is enabled, a security group named Cloud_Firewall_Security_Group
and an allow policy appear on the Security Groups page of the ECS console. The allow policy is also referred to as an authorization policy, which is used to allow inbound traffic from a VPC firewall to ECS instances. To
go to the Security Groups page, log on to the ECS console and click Network & Security in the left-side navigation pane.
Note Do not delete the security group Cloud_Firewall_Security_Group and the allow policy.
Otherwise, the inbound traffic from the VPC firewall to ECS instances cannot be protected
by the VPC firewall.
Procedure
Result
- After you turn on Firewall Settings, Firewall Status becomes Enabling. If Firewall Status becomes Enabled, the VPC Firewall feature is enabled.
- After you turn off Firewall Settings, Firewall Status becomes Disabling. If Firewall Status becomes Disabled, the VPC Firewall feature is disabled.