tencent cloud

Tencent Cloud Firewall

Complimentary Traffic Inspection

Baixar
Modo Foco
Tamanho da Fonte
Última atualização: 2026-09-03 17:01:40
Traduzido por IA

Introduction

Free Traffic Inspection is a full-traffic security detection service provided by CFW. You can initiate a deep inspection of all network traffic without purchasing any product. The system automatically generates a dedicated security inspection report to help you quickly understand the security risks facing your business network.
The inspection uses out-of-band traffic mirroring to passively analyze asset traffic without changing traffic paths or requiring application modifications. Through the inspection report, you can gain a clear picture of security risks such as network intrusions, malicious communications, asset exposure, and data exfiltration, providing a basis for subsequent security construction decisions.

Scenario

Free Traffic Inspection covers four major security risk scenarios across all network traffic:
Detection Scenario
Description
Detect network intrusions and malicious communication
Identify network attack behaviors and malicious communication traffic targeting assets
Identify sensitive data and credential leakage
Detect sensitive data, identity information, and credential keys leaked in business traffic.
Discover abnormal outbound communication behavior
Discover abnormal communication behavior between assets and suspicious external entities.
Scan exposed assets and risky ports
Inventory assets exposed to the public network and risky open ports.

Applicable Scope

Users who have not purchased CFW.
Users who have purchased CFW but have not enabled Network Detection and Response (NDR).

Complimentary Rules

Rule Item
Description
Health Check Eligibility
Each root account can receive one free inspection over its lifetime 1 time.
Number of Assets Eligible for Health Check
Up to 10 assets (public network assets by default)
Eligible Asset Types for Health Check
CVM, Containers, GAAP
Health Check Duration
Fixed 24 hours and not customizable.
Detection Method
During the inspection, detection components need to be temporarily deployed on the selected assets (deploy the Agent on CVMs and GAAPs, and deploy the probe container in the container cluster). The system uses bypass traffic mirroring to collect and analyze traffic, does not change the direction of business traffic, does not cause packet loss, but consumes certain CPU and memory resources.
Cancellation During Process
Not supported.
Modifying Assets During Health Check
Not supported.
Report Validity Period
The report is valid for 180 days after the inspection is completed and will be automatically deleted after expiration.
Resource Cleanup
After the inspection, the system automatically stops detection, uninstalls deployed Agents and probe containers, and cleans up temporary resources generated by this inspection. No manual handling is required.

Operation Steps

Step 1: Initiating an Inspection

1. Log in to the CFW console, select Overview or Network Detection and Response in the left sidebar.
2. In the Free Traffic Inspection module, click Health Check.

Step 2: Completing Authorization

After you start an inspection, the system checks whether CAM authorization has been completed. If not, click License Now (using the Tencent Cloud unified authorization component).

Step 3: Selecting Assets and Configurations

In the asset selection panel, select the assets to be inspected (public network assets by default, up to 10). When the asset list loads, the system automatically detects whether each asset supports NDR inspection and filters out unavailable assets by default to prevent accidental selection.
You can choose whether to Enable Encrypted Traffic Detection Simultaneously as needed to improve inspection coverage.

Step 4: Starting an Inspection

After confirming that the selected assets are correct, click Start health check. The system then enters a 24-hour inspection process. After the inspection is completed, a security inspection report is automatically generated and sent through in-app notifications and SMS.

Step 5: Viewing Reports

After the inspection is completed, the system automatically generates a security inspection report based on the detection results. You can view or download the report on the Overview or NDR page. The report contains the security risks detected during the inspection and their descriptions.
The report is valid for 180 days from the date of generation and will be automatically deleted after expiration. Please view and download it in a timely manner.

FAQs

Will I be charged for a free inspection?
No. Each root account can perform a free inspection once. Inspection resources generated during the inspection are automatically managed by the system and cleaned up automatically after the inspection, with no additional charges.
Will the inspection affect my business?
No. The inspection uses out-of-band traffic mirroring to passively analyze asset traffic without changing traffic paths, affecting normal business operations, or requiring application modifications.
Why can't some assets be selected?
When the asset list loads, the system automatically detects the NDR compatibility of each asset (region, operating system, instance type, TAT, and so on). Assets that do not meet the conditions are filtered out and hidden by default. After you disable the filter, you can see the grayed-out status and the specific reason.
Can the inspection be performed repeatedly?
Each root account has only one free inspection opportunity for its lifetime, and repeated inspections are not supported. Cancellation or replacement of assets is also not supported during the inspection. Make sure that the selected assets are correct before you start.
What should I do if the report has expired?
Reports are valid for 180 days after generation and will be automatically deleted upon expiration. You are advised to view and download the report promptly after receiving the notification.

Following Steps

If you have not purchased CFW and want to experience more features, see Trial Instructions. To purchase CFW, see Purchase Methods.
If you have purchased CFW but have not activated NDR and want to try or activate NDR, see Overview for details.


Ajuda e Suporte

Esta página foi útil?

comentários