Oracle Cloud Infrastructure (OCI) Network Firewall is a cloud native, machine learning–powered firewall with advanced intrusion detection and prevention capabilities, supported by Palo Alto Networks® NGFW technology that scales automatically.
You can add OCI Network Firewall to your environment without disturbing existing network flows.
OCI Network Firewall offers granular security policies that include traditional protocol filtering and (as of mid-2024) application-specific traffic recognition, reducing the attack surface beyond just protocols and ports.
OCI Network Firewall offers a best-in-class threat engine designed to automatically act against known malware, spyware, command-and-control attacks, and vulnerability exploits. Benefit from Palo Alto Networks’ advanced technology to detect and prevent intrusions.
OCI Network Firewall is a next-generation, managed network firewall and intrusion detection and prevention service for OCI VCNs, powered by Palo Alto Networks.
OCI Network Firewall is a highly available and scalable instance that you create in a subnet. The firewall applies business logic specified in a firewall policy attached to the network traffic. Routing in the VCN is used to direct traffic to and from the firewall. OCI Network Firewall provides a throughput of 4 Gb/sec, but you can request an increase up to 25 Gb/sec. The first 10 TB of data is processed at no additional charge.
Firewall policies identify traffic based on a combination of attributes: network protocol types, TCP or UDP protocols with port numbers, fully qualified domain names with optional wildcards, URLs, and IP addresses (both IPv4 and IPv6 are supported). A policy can accept traffic, reject traffic, inspect it for intrusion, or actively defend against intrusion.
OCI Network Firewall is typically deployed to secure traffic between OCI and external environments, such as on-premises systems, the internet, and other clouds. The firewall can also secure internal OCI traffic, e.g., between two VCNs.
A well-planned network design can set the stage for a successful implementation—and make the network easier for your team and organization to use. By planning your network design before deployment, you can ensure that your design meets all your requirements and avoid potential barriers to a successful deployment later on.
This blog covers the general functions of OCI Network Firewall and how to deploy it.
This hands-on tutorial shows how to protect traffic directed to multiple websites and applications deployed in multiple backends using OCI Network Firewall and OCI Load Balancers.
This blog covers the inbound SSL decryption in OCI Network Firewall using an RSA public certificate.
Build, test, and deploy applications on Oracle Cloud—for free. Sign up once, get access to two free offers.
Interested in learning more about Oracle Cloud Infrastructure? Let one of our experts help.
* Network Firewall requires a paid OCI account, either as a pay-as-you-go or Universal Credits contract.