Network Threat Protection
AWS Network Firewall
AWS Network Firewall is a managed stateful network inspection and threat prevention service deployed at VPC boundaries via firewall subnets. It filters east-west and north-south traffic using rule groups and stateful/stateless policies, integrates with AWS VPC routing, and feeds alerts through Amazon CloudWatch. The operating model is in-cloud traffic redirection to inspection endpoints the customer owns and configures.
AWS
Service information
Shortname: Network Firewall
Huawei equivalent shortnames: CFW, DDoS
Keywords: firewall, network security, threat, ddos
Differences vs Huawei
AWS Network Firewall is a single managed service attaching to VPC firewall subnets through route-table redirection, inspecting both east-west (VPC-to-VPC) and north-south (internet/IGW) traffic with stateful Suricata-compatible rule groups plus stateless match rules. Huawei Cloud Firewall (CFW) is the closer functional analog: a cloud-native firewall for VPC, internet, and east-west boundaries, but its object model (protection objects, access control/IP black-white lists, intrusion prevention) differs from AWS firewall/rule-group APIs, and CFW enforcement is policy-scoped per VPC or EIP rather than per-firewall-subnet you wire through routes. Treat CFW as the core equivalent for stateful inspection and IPS, not a drop-in AWS API replacement.
DDoS in Huawei is a separate family (AAD: Anti-DDoS) not bundled with CFW, whereas AWS distributes DDoS capacity across Shield, ALB, and other services without a dedicated managed network firewall layer for it. Huawei AAD has three tiers: free Basic traffic cleaning on Huawei EIPs, paid Native Advanced (20G–1T, transparent, in-cloud), and Advanced Anti-DDoS (Advanced Anti-DDoS, proxy/redirect, supports non-Huawei origin, up to ~1T per IP). AWS Network Firewall does not perform volumetric scrubbing at all, so any AWS design relying on it for L3/L4 flood protection must map to AAD, not CFW; conversely, AWS WAF/Shield concepts do not all map onto CFW.
Operational integration and scaling differ. AWS Network Firewall is regional, autoscales the inspection endpoints transparently, and emits metrics/logs to CloudWatch, Firehose, and S3 with no separate quota appliance. CFW provides per-tenant throughput by edition and exposes alerts to SecMaster/SMN/LTS, while AAD reporting is its own console and bestpractice pipelines. Quotas, region availability, and API surface (CFW OpenAPI vs AWS firewall policies/RuleGroup APIs) are not parity-confirmed; plan to restate policies by hand and validate cross-region/interconnect traffic handling before cutover.
Migration to Huawei
Assess the source posture by inventorying AWS Network Firewall firewall policies, rule groups, stateful Suricata rules, and the VPC route tables that redirect traffic to inspection subnets. Decide the Huawei target per workload: CFW for VPC-boundary stateful inspection and IPS, AAD Native Advanced for in-cloud EIP/ELB DDoS, and AAD Advanced Anti-DDoS for non-Huawei origins or large volumetric exposure. No CFW/AAD API import path exists for AWS rules, so budget manual translation and do not assume feature parity for custom Suricata signatures.
Rebuild policy in Huawei incrementally: translate allow/deny and IPS rules into CFW access-control and intrusion-prevention policies, recreate IP address groups and application/protocol matchers, and replicate AWS logging/alert sinks to SecMaster and SMN. For DDoS, define AAD protection objects per EIP/ELB, set cleaning thresholds and black/white lists, and use the documented DDoS Native Advanced + cloud WAF (ELB access) linkage when application-layer floods are in scope; Advanced Anti-DDoS requires DNS/IP redirect and ICP-filed domains in mainland China.
Validate in a staged tenant rather than direct cutover: run parallel inspection, baseline legitimate flows, and run controlled attack/deny tests against CFW and AAD to confirm detection and scrub behavior. Because no automated migration tool covers AWS Network Firewall to Huawei CFW/AAD, capture rule-to-policy test evidence per boundary and keep the original AWS policies immutable during rollback until Huawei observability (SecMaster, CFW logs, AAD dashboards) shows matched alerts.
Recalculate TCO and watch gaps. AWS Network Firewall bills per endpoint plus processed traffic; CFW bills by edition and protected assets/EIPs, while AAD bills per instance plus clean/elastic traffic (Advanced) or business bandwidth. Adjust for peak bandwidth, retention, and cross-region traffic, and confirm quotas for CFW throughput and AAD instances/objects per region before production. Suricata-rule portability, east-west coverage parity, and cross-account enforcement are the most likely gaps to document.
Official Huawei Cloud documentation
Huawei Cloud
Huawei equivalent service
Shortname: CFW
General function: Network Threat Protection
Managed cloud firewall protection service.
Keywords: firewall, network security, threat
Huawei equivalent service
Shortname: DDoS
General function: Network Threat Protection
Distributed denial-of-service protection service.
Keywords: ddos, attack mitigation, protection