|
Company Name:Kino Technology Limited
Website:www.kino86.com
Address :Room 312, Honghua Building, No. 1 Guangyayuan Road, Bantian Street, Longgang District, Shenzhen city, Guangdong Province, China
Contact Person:kiki
Tel :+8613040881925
E-mail:kiki@szkiki.com
Wechat:+8613040881925
Whatspp: +8613040881925
Teams:kiki@szkiki.com
|
|
|
| Product >> Huawei >> ALL |
| |
|
Product_Id: |
81912532816 |
ProductName: |
USG-CFW-F |
Specification: |
|
Product Notes: |
|
Product Category: |
Huawei |
| |
|
| Product Description |
Huawei USG‑CFW‑F
Product Overview
Huawei USG‑CFW‑F is the flagship cloud‑native SaaS cloud firewall service, tailored for container‑based, Kubernetes‑driven cloud‑native workloads. Delivered as fully‑managed cloud security service without physical hardware or local virtual machine deployment. Built for microservice‑oriented architectures, it provides granular traffic inspection for north‑south internet traffic, east‑west inter‑VPC traffic, and pod‑to‑pod traffic within Kubernetes clusters. It adapts to frequent instance scaling, dynamic service discovery and cloud‑native lifecycle changes for large‑scale container platforms and complex multi‑cloud environments.
Key Features
-
Full‑link multi‑layer traffic protection: Enforces fine‑grained access control for internet border traffic, cross‑VPC traffic and intra‑cluster pod‑to‑pod east‑west traffic. Supports policy matching by IP, port, domain, geographic location, asset tag, service label and Kubernetes namespace. Blocks unauthorized access and restricts lateral threat movement across containers, virtual machines and hybrid‑cloud resources.
-
Cloud‑native oriented advanced threat defense: Integrates high‑performance IPS engine, global threat intelligence feed and inline TLS/SSL decryption capability. Identifies and blocks vulnerability exploits, SQL injection, XSS, brute‑force attacks, reverse‑shell connections, ransomware C‑C communication and malware targeting container workloads. Effectively defends against container escape and microservice‑oriented attack vectors.
-
Kubernetes‑aware asset auto‑discovery: Automatically identifies cloud‑native assets including ECS, EIP, ELB, Kubernetes namespaces, pods and services. Real‑time security dashboard visualizes container traffic flows, attack events and risk exposure status. Provides intelligent policy recommendation, redundant rule cleanup and hit‑rate analysis to reduce configuration overhead for dynamically changing container resources.
-
Multi‑cloud and container‑platform adaptability: Supports Huawei public cloud, HUAWEI CLOUD Stack private cloud and hybrid‑cloud interconnection scenarios. Natively integrates with Kubernetes orchestration, supports service‑mesh compatible security enforcement. Adopts distributed redundant cluster architecture without single point of failure; protection bandwidth scales elastically to cope with burst traffic of containerized applications.
-
Container‑optimized audit & open API integration: Captures comprehensive access logs, attack logs and full traffic logs for container workloads, supports long‑term log retention, custom compliance reports and security forensics. Deeply interconnects with SecoMaster, LTS log service, CTS cloud audit and SMN alert notification. High‑performance RESTful open APIs enable automated security orchestration, policy synchronization and multi‑account centralized security management.
-
Granular cloud‑native permission control: Supports RBAC authorization, enterprise‑project isolation, multi‑tenant sub‑account management and namespace‑level permission division. Meets authority separation requirements for DevOps teams and large‑scale container platform O&M workflows.
Technical Specifications
-
Deployment form: Managed SaaS cloud‑native security service, no physical hardware or local VM
-
Protection scope: Internet border EIP traffic, cross‑VPC east‑west traffic, Kubernetes intra‑cluster pod‑to‑pod traffic, hybrid‑cloud cross‑site traffic
-
Supported platform: Huawei Public Cloud, HUAWEI CLOUD Stack private cloud, Kubernetes container environment, hybrid‑cloud deployment
-
Security functions: ACL access control, Kubernetes label‑based policy control, AI‑enhanced IPS intrusion prevention, antivirus, TLS decryption, container‑oriented threat detection, asset auto‑discovery, intelligent policy optimization, full‑log audit, RBAC multi‑tenant permission management
-
Orchestration interface: RESTful open API, Kubernetes‑compatible interface, supports DevOps automated security workflow
-
Management: Cloud‑based console, visualized security dashboard, real‑time threat alert, custom compliance report
-
Performance: Elastic bandwidth scaling for large‑scale container and cloud‑native workloads
Application Scenarios
Large‑scale Kubernetes container platform full‑traffic security protection, microservice‑oriented east‑west micro‑segmentation, multi‑cloud and hybrid‑cloud cloud‑native workload security, DevOps‑oriented automated security orchestration, regulated‑industry container‑based business compliance audit.
Short version for quotation / BOM
Huawei USG‑CFW‑F, Flagship Cloud‑Native SaaS Firewall Service optimized for Kubernetes and microservice workloads. Delivers multi‑layer protection for north‑south internet, cross‑VPC and intra‑cluster pod‑to‑pod traffic, integrates AI‑powered IPS threat prevention, TLS decryption, container‑aware asset discovery and compliance‑oriented log audit. Supports elastic scaling, Kubernetes‑compatible orchestration and RESTful open APIs, for large‑scale container‑based and multi‑cloud production‑grade security protection.
|
|
|
| Click:24 Entry Time:2026-08-19 【Print】 【Close】 |
|
|
|
|