NAT Firewall Rules

Last Updated At: 2025-10-17 15:31:01

Access control rules can filter specific domain names or filter traffic by geographic location.
The NAT firewall has two access control rule lists — Inbound Rules and Outbound Rules.

  • Inbound Rules apply to incoming north-south traffic over the edge firewall.
  • Outbound Rules apply to outgoing north-south traffic over the edge firewall.

This topic describes operations related to Inbound Rules; operations for Outbound Rules are similar.


Operation Guide

  1. Log in to the Converge Cloud Firewall Console.
  2. Select Access Control in the left navigation pane, and then select NAT Firewall Rules.
  3. On the NAT Firewall Rules page, select a region, and click Inbound Rules.

On the Inbound Rules page, you can:

  • Create access control rules for different regions.
  • View rule list details (used and total quotas).
  • See recent operations and access control logs.

Recent operations include:

  • Details – View specific operation details.
  • View operation logs – Review detailed action history.

Adding Inbound Rules

  1. Click Add Rule on the Inbound Rules page.
  2. Configure the rule in the Add Inbound Rule window.

Access Source Type: IP Address, Geographic Location, Cloud Vendor, or Address Template
Access Destination Type: IP Address, Asset Instance, Resource Tag, Address Template, or Asset Group

Select Priority, specify Destination Port, Protocol, and Policy, enter a description, and click OK.

Note:

Access destination type region refers to the region where the cloud instance is located. Access source type refers to the type of external source when adding an inbound rule.


Field Descriptions

Field Description
Priority Determines rule order. Higher priority rules are evaluated first. When modifying a rule’s priority, lower ones adjust accordingly.
Access Source The source of inbound traffic. Supports IP, CIDR block, or geographic location.
Access Destination The private network asset in the selected region. Supports IP, instance, tag, or group.
Destination Port Supports single, range, or multiple ports (e.g., 80, 80/443, 80,443,3389). Not required for ICMP.
Protocol Supported inbound: TCP, UDP. Supported outbound: TCP, UDP, ICMP, HTTP, HTTPS, SMTP, SMTPS, DNS, FTP.
Policy Allow: Permit traffic and record hits (no access control logs).
Observe: Permit and log all hits.
Block: Deny traffic and log access attempts.
Description Up to 50 characters. Use # for special flags (e.g., #long connection#).

NAT Firewall Wildcard Rules

Input Field Example Description
Access source/destination 0.0.0.0/0 All IPs
Domain name * All domains
Domain name *.aa.com All subdomains of aa.com
Destination port -1/-1 All ports
Destination port 0/65535 All ports
Destination port 80,443,3389 Specific ports
Destination port 80/443 Range between 80 and 443
Destination port 80/443,3389 Ports 80–443 and 3389

Adding Rules in Bulk

Note:

Each rule occupies one line. New rules are added at the end by default and have the lowest priority.

Scenario 1: Adding Rules in Batch

  1. Click Copy in the action column to add multiple rules.
  2. Complete all fields.
  3. Check priorities.
  4. Click OK to submit.

Scenario 2: Multiple Rules for One IP

  1. Edit a rule, filling common fields.
  2. Click Copy to duplicate it (up to 10 rules).
  3. Adjust unique fields and priorities.
  4. Click OK to submit.

Importing Rules

Click Import Rule to import from a local file.
You can specify an import location, download templates, or export existing rules.


Backup and Rollback

  1. Click Backup Rules (top-right) to save current NAT firewall configurations.
  2. Click Roll Back beside a backup to restore previous rules.
  3. You can add a description and select NAT Firewall Rules as backup type.

More Information

For additional topics:

  • Edge Firewall Rules – Managing inbound/outbound traffic on the edge firewall.
  • Inter-VPC Firewall Rules – Managing communication between virtual networks.
  • Special Scenarios – Access control in unique environments.
  • NAT Firewall Overview – General information and troubleshooting.

Converge Cloud – Philippines’ Trusted Cloud Security Platform