Creating a NAT Firewall Instance

Last Updated At: 2025-10-30 14:19:45

Choosing Create Firewall Instance > New Mode

  1. Log in to the CFW console. In the left sidebar, choose Firewall Toggle > NAT Firewall Toggle. On the NAT Firewall Toggle page, you can perform operations such as creating instances, synchronizing assets, and viewing and monitoring the bandwidth information based on NAT Firewall. Under NAT Firewall Toggle, you can click Create Instance to add instances.
Warning:

Once a NAT Firewall toggle is enabled, the traffic of the corresponding subnet will pass through the firewall. At that time, access control rules and intrusion prevention will take effect for the firewall, and traffic logs will also be generated.

  1. In the Create NAT Firewall pop-up window, you can create a NAT Firewall instance for the current account, configure related fields, select the mode as needed, and then click Next.

  2. Under Step 2, select the VPC to be connected to CFW and click Next.

  3. Select a traffic routing mode. Three modes are provided: Proprietary IP Range Preferred, Extended IP Range Preferred, and Custom. Then, click Create and wait for the instance creation to complete.

Note:
  • CFW will create a /24 subnet in the connected VPC to redirect traffic to the firewall and public network traffic egress. You can select different ways to create subnets.
  • Proprietary IP range preferred: CFW automatically selects an idle subnet IP range in the selected VPC. If the VPC has no subnet quota, an extended IP range in the VPC is used.
  • Extended IP range preferred: CFW will choose an idle extended IP range reserved by the VPC first. This mode does not consume the VPC's subnet quota.
  • Custom: You can only specify a /24 subnet within the CIDR block of the current VPC.

Choosing Create Firewall Instance > Access Mode

  1. Choose VPC > NAT Gateway > Create NAT Gateway to configure the VPC to be connected.

  2. After the NAT Gateway is created successfully, you can modify the next hop route table of the VPC to point to the NAT Gateway. At this point, the VPC can access the public network through the NAT Gateway, and the gateway ID is recorded.

  3. Log in to the CFW console and click Create NAT Firewall. On the Create NAT Firewall page, configure the instance specification, select the access mode, and then click Next.

  4. Check the instance ID to be connected to the NAT gateway and click Next.

  5. Select a routing mode based on the VPC assignment information of your project and click Create.