Network Threat Protection
Azure Firewall
Azure Firewall is a managed, cloud-native next-generation firewall providing centralized network-layer threat protection across Azure Virtual Networks. Deployed as a regional service with built-in high availability and autoscaling, it enforces application- and network-level rules, threat-intelligence-based filtering, IDPS, TLS inspection, web category filtering, and DNS proxying. It is billed per provisioned instance and processed throughput rather than per protected asset alone.
Azure
Service information
Shortname: Azure Firewall
Huawei equivalent shortnames: CFW, DDoS
Keywords: firewall, network security, threat
Differences vs Huawei
Azure Firewall maps most directly to Huawei Cloud Firewall (CFW), a next-generation cloud firewall offering north-south (EIP) and east-west (inter-VPC) access control, IPS, and antivirus (Professional edition). CFW uses Standard/Professional editions with protected-EIP and protected-VPC quotas and peak protection traffic caps, whereas Azure Firewall autoscales throughput per virtual hub/VNet without fixed EIP or VPC count limits. CFW rule prioritization, ACL limits (~20,000 ACLs), and edition-gated features differ from Azure Firewall Rule Collection Groups and DNAT/NAT rules. Map enforcement points explicitly: CFW Internet-border protection correlates to Azure Firewall on a VNet/subnet, while CFW VPC-border protection adds inter-VPC segmentation.
DDoS protection is a separate concern. Azure DDoS Protection is distinct from Azure Firewall, and Huawei likewise separates CFW from Anti-DDoS Service (AAD). Huawei AAD provides Tbit/s volumetric scrubbing through high-defense IPs and protects assets even outside Huawei Cloud, plus application-layer (WAF/CC) mitigation. It is not a firewall replacement and lacks CFW's IPS/ACL segmentation. Treat targets as complementary, not interchangeable: CFW for stateful NGFW policy enforcement, AAD for volumetric attack mitigation.
Operational model and integrations diverge. CFW streams logs to Log Tank Service (LTS) and SecMaster for SIEM-style correlation, uses Cloud Trace Service (CTS) for audit and SMN for alarms, and supports multi-account/enterprise-project management. Azure Firewall pairs with Azure Monitor, Log Analytics, Defender for Cloud, and Azure Policy with built-in ARM template and policy hierarchy semantics. Expect to re-map detection rules, alert routing, and RBAC; neither service offers one-click parity, and SecMaster integration must be configured separately.
Migration to Huawei
Start with an assessment of every Azure Firewall policy, Rule Collection Group, NAT rule, DNAT rule, network rule, application rule, IP group, and threat-intelligence mode in use. Inventory enforcement points (VNet/subnet and hub), existing IDPS signatures, TLS inspection certificates, web-category usage, and DNS proxy dependencies. Decide target composition: CFW for stateful NGFW control (Standard for Internet-border EIP protection, Professional for east-west inter-VPC protection and IPS/antivirus), plus AAD where volumetric DDoS mitigation on protected IPs is required. Confirm CFW edition quotas (protected EIPs, protected VPCs, peak protection traffic) can absorb peak load.
Recreate policy in CFW using its ACL, IPS, and access-control constructs. Convert Azure Firewall network/application rules into CFW access-control rules and IP groups, translating FQDN-based application rules carefully since CFW's FQDN-based control is scoped by edition and rule type. Migrate NAT/DNAT behavior using CFW NAT rules (with NAT gateway where required, per best-practice guidance for SNAT protection). For DDoS exposure, attach AAD high-defense IPs to public-facing EIPs/ELB. There is no automated Azure-to-CFW policy importer; budget manual or scripted conversion using each cloud's APIs and validate rule-by-rule.
Validate before cutover: replay representative traffic through CFW in audit/observe mode where available, confirm IPS and antivirus signatures surface expected detections, verify inter-VPC and Internet-border enforcement, test failover/cluster HA behavior, and exercise log delivery to LTS and SecMaster and alarms via SMN. Run AAD in parallel for public endpoints under load or simulated attack to confirm mitigation thresholds. Compare throughput and latency against Azure Firewall baselines before switching DNS or route tables to the Huawei path.
Account for cost and gap changes. CFW bills by edition plus protected EIP/VPC quotas and peak protection traffic, not by provisioned throughput like Azure Firewall; AAD bills separately by high-defense IP and protection traffic/instance. Recompute TCO including SecMaster/LTS log retention, cross-VPC protection traffic scaling with VPC count, and AAD scrubbing. Note gaps: Azure Firewall native features such as TLS inspection, web categories, and DNS proxy may have limited or edition-gated CFW equivalents; verify regional availability of CFW and AAD and any import/export control restrictions before production cutover.
Huawei Cloud
Huawei equivalent service
Shortname: CFW
General function: Network Threat Protection
Managed cloud firewall protection service.
Keywords: firewall, network security, threat
Huawei equivalent service
Shortname: DDoS
General function: Network Threat Protection
Distributed denial-of-service protection service.
Keywords: ddos, attack mitigation, protection