Access control rules can filter specific domain names or filter traffic by geographic location.
The NAT firewall has two access control rule lists — Inbound Rules and Outbound Rules.
- Inbound Rules apply to incoming north-south traffic over the edge firewall.
- Outbound Rules apply to outgoing north-south traffic over the edge firewall.
This topic describes operations related to Inbound Rules; operations for Outbound Rules are similar.
Operation Guide
- Log in to the Converge Cloud Firewall Console.
- Select Access Control in the left navigation pane, and then select NAT Firewall Rules.
- On the NAT Firewall Rules page, select a region, and click Inbound Rules.
On the Inbound Rules page, you can:
- Create access control rules for different regions.
- View rule list details (used and total quotas).
- See recent operations and access control logs.
Recent operations include:
- Details – View specific operation details.
- View operation logs – Review detailed action history.
Adding Inbound Rules
- Click Add Rule on the Inbound Rules page.
- Configure the rule in the Add Inbound Rule window.
Access Source Type: IP Address, Geographic Location, Cloud Vendor, or Address Template
Access Destination Type: IP Address, Asset Instance, Resource Tag, Address Template, or Asset Group
Select Priority, specify Destination Port, Protocol, and Policy, enter a description, and click OK.
Access destination type region refers to the region where the cloud instance is located. Access source type refers to the type of external source when adding an inbound rule.
Field Descriptions
| Field | Description |
|---|---|
| Priority | Determines rule order. Higher priority rules are evaluated first. When modifying a rule’s priority, lower ones adjust accordingly. |
| Access Source | The source of inbound traffic. Supports IP, CIDR block, or geographic location. |
| Access Destination | The private network asset in the selected region. Supports IP, instance, tag, or group. |
| Destination Port | Supports single, range, or multiple ports (e.g., 80, 80/443, 80,443,3389). Not required for ICMP. |
| Protocol | Supported inbound: TCP, UDP. Supported outbound: TCP, UDP, ICMP, HTTP, HTTPS, SMTP, SMTPS, DNS, FTP. |
| Policy | Allow: Permit traffic and record hits (no access control logs).Observe: Permit and log all hits.Block: Deny traffic and log access attempts. |
| Description | Up to 50 characters. Use # for special flags (e.g., #long connection#). |
NAT Firewall Wildcard Rules
| Input Field | Example | Description |
|---|---|---|
| Access source/destination | 0.0.0.0/0 |
All IPs |
| Domain name | * |
All domains |
| Domain name | *.aa.com |
All subdomains of aa.com |
| Destination port | -1/-1 |
All ports |
| Destination port | 0/65535 |
All ports |
| Destination port | 80,443,3389 |
Specific ports |
| Destination port | 80/443 |
Range between 80 and 443 |
| Destination port | 80/443,3389 |
Ports 80–443 and 3389 |
Adding Rules in Bulk
Each rule occupies one line. New rules are added at the end by default and have the lowest priority.
Scenario 1: Adding Rules in Batch
- Click Copy in the action column to add multiple rules.
- Complete all fields.
- Check priorities.
- Click OK to submit.
Scenario 2: Multiple Rules for One IP
- Edit a rule, filling common fields.
- Click Copy to duplicate it (up to 10 rules).
- Adjust unique fields and priorities.
- Click OK to submit.
Importing Rules
Click Import Rule to import from a local file.
You can specify an import location, download templates, or export existing rules.
Backup and Rollback
- Click Backup Rules (top-right) to save current NAT firewall configurations.
- Click Roll Back beside a backup to restore previous rules.
- You can add a description and select NAT Firewall Rules as backup type.
More Information
For additional topics:
- Edge Firewall Rules – Managing inbound/outbound traffic on the edge firewall.
- Inter-VPC Firewall Rules – Managing communication between virtual networks.
- Special Scenarios – Access control in unique environments.
- NAT Firewall Overview – General information and troubleshooting.
Converge Cloud – Philippines’ Trusted Cloud Security Platform