Advantages

Last Updated At: 2025-10-29 15:32:09

Easy to Enable and Deploy

Based on SDN, CFW offers a public cloud SaaS firewall with simple policy configuration and no hardware deployment costs.
It can automatically identify cloud assets and allows you to enable or disable firewalls with one click.


Stable, Reliable, and Scalable

With a primary-secondary disaster recovery system and SaaS features, CFW provides high stability and reliability.
It supports easy scaling for:

  • Bandwidth
  • Assets
  • Storage

allowing your network protection to grow effortlessly with your cloud infrastructure.


Centralized Management for High Efficiency

CFW offers a centralized access control plane for managing access and ensuring security isolation across networks and VPCs.

Network Perimeter Access Control

  • Block or observe malicious traffic.
  • Prevent attacks from malicious sources on cloud assets based on access control rules configured for public IP addresses.

Inter-VPC Access Control

  • Control access between VPCs.
  • Ensure security isolation through inter-VPC access control rules.

Enterprise Security Group

  • Simplify security group configuration using the 5-tuple configuration model.
  • Easily build a cloud demilitarized zone (DMZ) with blocked request logs.
  • Protect traffic between subnets, VPCs, and hybrid cloud connections.

By following the rule configuration model of traditional firewalls, CFW is easy to learn and use for security operations and maintenance specialists.


Log Storage and Audit

Rule Hit Log

When an access control rule is matched and applied, CFW records the 5-tuple information of the matched traffic and rule.
This helps with:

  • Security operations and maintenance (SecOps)
  • Quick troubleshooting during network issues or failures

User Operation Log

Records user operations on CFW, including:

  • Account logins
  • Firewall toggle operations
  • Add/Delete/Edit actions on rules

These logs improve management efficiency, accountability, and cost transparency.


Note:

CFW's SDN-based design makes it simple to deploy, highly scalable, and ideal for enterprise-grade network visibility and control.