What is Converge Cloud Firewall (CFW)?
Converge Cloud Firewall (CFW) is a SaaS firewall built for the public cloud environment that provides network perimeter protection and addresses security and management needs such as unified access control and log auditing.
In addition to the capabilities of traditional firewalls, CCFW supports multi-tenancy, elastic scaling, and serves as a core network security infrastructure for organizations undergoing cloud migration.
Features Overview
1. Cloud Firewall Overview
Cloud Firewall offers centralized network access control. The console overview page provides a clear visualization of key modules:
- Asset Protection Overview – Displays asset counts in public and private networks, exposed ports, and security events, including vulnerability intelligence.
- Firewall Status Monitoring – Shows peak bandwidth for edge and NAT firewalls within the last 7 days.
- Traffic Statistics – Monitors inbound, outbound, and total traffic for time periods ranging from 24 hours to 6 months.
- Security Policy Configuration – Displays counts of access control rules for edge, NAT, and inter-VPC firewalls, along with remaining quota and intrusion prevention policies.
- Log Storage Statistics – Shows total, used, and remaining log storage capacity.
2. Cloud Firewall Toggles
- Edge Firewall: Automatically identifies public IP addresses and associated instances, allowing you to manage access control by public IP.
Supports public BGP IPs (IPs from CMCC, CUCC, or CTCC are not supported).
You can view all inbound and outbound rules for each public IP and manage them through the Access Control module.
- Inter-VPC Firewall: Automatically detects all VPCs in your private network, visualizing them through a VPC topology.
- NAT Firewall: A virtual firewall that operates similarly to a NAT gateway, providing network address translation and security audit features (access control + logs).
Once the feature toggle is enabled:
- A sub-firewall is created automatically for each connected VPC pair.
- You can enable/disable sub-firewalls and configure access control rules for each.
After creation:
- The system identifies the subnets of selected VPCs.
- You can enable firewalls for subnets to route traffic through the NAT firewall.
- Configure access control lists (ACLs) to filter and manage traffic.
---
3. Asset Management
Asset Management enables you to view and manage detailed data for all assets — helping identify top 5 core and risky assets, as well as full visibility over public, private, and VPC-based assets.
It supports proactive monitoring to prevent potential security threats.
4. Alert Management
Alert Management keeps you informed when your assets are under attack.
After configuring rules under Access Control, Intrusion Defense, and Security Baseline, CCFW continuously notifies you of critical alerts for Security Operations & Maintenance (SecOps).
5. Traffic Monitoring
Traffic Monitoring provides visualized data on:
- External access statistics
- Outgoing request analysis
- Inter-VPC activity
This helps identify anomalies and optimize network flow security.
6. Access Control
Access Control rules are defined using a 5-tuple model (protocol, source IP, destination IP, source port, destination port).
These rules:
- Are applied according to priority for each data flow passing through the edge firewall.
- Allow administrators to control access to public IPs.
- Provide logging for auditing, troubleshooting, and compliance.
This structure supports cross-subnet, VPC-to-VPC, and hybrid cloud protection scenarios.
7. Intrusion Defense
Intrusion Defense] automatically detects unknown risks beyond standard access control rules.
It monitors north-south traffic for public IPs and applies intrusion defense rules to protect against CVM vulnerabilities and Internet-based attacks.
8. Security Baseline
Security Baseline uses long-term traffic analysis to build a trusted access list (IP or domain).
Administrators can adjust this baseline by adding/removing entities based on:
- Security scores
- Detected events
- Traffic patterns
This ensures ongoing adaptive security optimization.
9. Log Audit
Log Audit records rule hit data for the last 7 days and provides:
- Traffic rule matching history
- Searchable logs for fast troubleshooting
- Operation history for up to 30 days
This enables efficient auditing, reduces O&M effort, and improves security governance.
10. Log Analysis
Log Analysis stores and processes traffic logs for 6 months, supporting:
- Search-based queries (e.g., by user, resource, or action)
- Report generation
- Advanced analytics
Ideal for trend identification and compliance reviews.
11. Address Template
Address Template simplifies batch IP management.
You can:
- Create templates for IPs or domain names
- Add multiple entries
- Reuse templates in Access Control Rules
This improves administrative efficiency and rule consistency.
Converge Cloud Firewall unifies protection for both public and private network traffic, combining visibility, control, and compliance for all connected resources within the Converge Cloud ecosystem.