tencent cloud

Tencent Cloud Firewall

Creating a Probe

Baixar
Modo Foco
Tamanho da Fonte
Última atualização: 2026-09-03 17:05:40
Traduzido por IA

Overview

An exposure probe is a decoy deployed in the user's business system. It can be an IP address or a domain name, and it forwards traffic from specified ports/paths to designated honeypot services. This allows the honeypot services to record attacker information and trace attack techniques. Therefore, a Network Honeypot service must be associated with an exposure probe before it can function properly.

Operation Steps

1. Log in to the CFW console, and in the left sidebar, choose Network Honeypot > Probe Exposure.
2. On the Exposed Probes page, click Create Probe.
3. In the Create Exposure Probe dialog, select the region, instance name, deployment mode, and corresponding parameters, and then click Next.
Parameter
Description
Region
Select the region from the dropdown list. The region cannot be changed after the instance is created.
Instance Name
Customize the instance name.
Deployment Mode
Load balancer: Select an existing CLB instance to deploy the probe. Traffic from the path on the specified domain will be forwarded to the honeypot service.
Public IP: Select an existing public IP address to deploy the probe. Traffic from the specified port on this IP address will be forwarded to the honeypot service.
Private IP: Select a subnet, and we will automatically create an ENI and a private IP address. You can configure specified ports on this IP address to forward traffic to the honeypot service.
Instance
When the deployment mode is Load balancer, configure this item. Select a CLB instance in the same region as the honeypot.
Domain
When the deployment mode is Load balancer, configure this item. Specify a listener on the selected CLB instance.
Select a subnet
When the deployment mode is Load balancer or Private IP, configure this item.
Load balancer: Specify the subnet where the CLB backend servers (RSs) reside. The subnet list is filtered based on the VPC to which the selected CLB instance belongs.
Private IP: Select a subnet, and the system will automatically create an ENI and a private IP address in the subnet.
IP address
When the deployment mode is Load balancer or Private IP, configure this item.
Load balancer: The private IP address used by the CLB backend RSs supports automatic allocation or manual entry. After successful creation, the firewall automatically registers this IP address as a CLB backend RS, and automatically deregisters it when the probe is deleted.
Private IP: The private IP address of the ENI that is automatically assigned by the system.
EIP
When the deployment mode is Public IP, configure this item. Select a new elastic IP address.
4. Configure the forwarding honeypot service, and click OK to complete the creation.
Quick Create Honeypot: Click Create honeypot with template and select the desired honeypot services. Multiple selections are supported.
Note:
Because a WEB honeypot requires existing SSH/MySQL honeypots as baits, the WEB honeypot is not automatically associated with baits after quick selection. When you click Quick Select Honeypot and select a WEB honeypot while creating a probe, the honeypot service does not start working. You need to go to the honeypot service, find the corresponding WEB honeypot, edit it, and associate it with the corresponding SSH/MySQL honeypots before the honeypot service starts working.
Select from existing honeypots: Click Select from existing and select the desired honeypot services. Multiple selections are supported. You can modify the listening port or input path as needed.
Note:
When the deployment mode is public IP address, you can modify the listening port.
When the deployment mode is CLB, some honeypots support custom paths. For details, refer to the console.
5. You can enable probes individually or in batches.
To enable a single probe: select the target probe, click

in the toggle column, and then click OK in the confirmation dialog.
Batch: Select one or more probes, click Enable Probe, and then click OK in the confirmation dialog to enable multiple probes.

Ajuda e Suporte

Esta página foi útil?

comentários