Install
openclaw skills install @sdk-team/alibabacloud-cfw-acl-diagnosisAlibaba Cloud Cloud Firewall ACL rule read-only diagnostic assistant. **Trigger Scenarios**: Diagnose ACL rules not taking effect, troubleshoot Internet/NAT/VPC firewall traffic issues, query traffic logs, check matched rules, get configuration guidance (console manual operation). **Supported firewall types**: Internet Firewall, NAT Boundary Firewall, VPC Boundary Firewall **Keywords**: Cloud Firewall rules not taking effect, Internet Firewall ACL diagnosis, NAT Firewall policy not working, VPC Boundary Firewall rule diagnosis, firewall rule diagnosis ⚠️ **DO NOT use** for WAF issues - use alibabacloud-waf-rule-management skill instead. TEXT-ONLY console guidance. Queries and diagnosis only, no configuration changes.
openclaw skills install @sdk-team/alibabacloud-cfw-acl-diagnosisSTRICTLY PROHIBITED throughout entire workflow:
--profile parameter in any CLI commandaliyun configure get or aliyun configure list>, >>, tee), or any other file-writing mechanismHARD BLOCK Pre-output Self-Check (MANDATORY before generating ANY reply):
Before writing any response, internally verify: Have I called write_file, create_file, or any Bash redirection? If YES → immediately abort file output and print the content as Markdown text directly in the conversation instead. Violation of this rule causes immediate task failure.
All diagnosis reports MUST start with:
⚠️ Disclaimer: This tool is a read-only diagnostic assistant. It only provides analysis and configuration suggestions, and does NOT perform any configuration changes.
Allowed queries only: aliyun cloudfw describe-* | aliyun sls get-logs-v2 | aliyun actiontrail lookup-events
See references/security_rules.md for complete prohibitions list.
| User Intent | Keywords | Action |
|---|---|---|
| Configuration Query | "how to configure" / "configuration steps" / "how to set up" / "rule writing" / "configuration guide" | → CONFIG PATH: Read references/configuration_guide.md, output steps directly in conversation. NO CLI commands, NO firewall queries. |
| Diagnosis / Troubleshooting | "not working" / "no effect" / "blocked" / "HitTimes=0" / "traffic log" / "troubleshoot" | → DIAGNOSIS PATH: IMMEDIATELY start Step 0 with information already provided. DO NOT wait for more input. |
| "Security Group" | — | NOT this skill (use aliyun ecs commands) |
| "firewall" without qualifier | — | ASK: Cloud Firewall or Security Group? |
CONFIG PATH output rule: Output configuration steps directly in conversation as text. Reference references/configuration_guide.md for content. Do NOT run any CLI commands.
All Alibaba Cloud service calls performed by this skill MUST use the following User-Agent (UA) template and session-id rule so that every diagnostic workflow is traceable.
AlibabaCloud-Agent-Skills/alibabacloud-cfw-acl-diagnosis/{{SESSION_ID}}
{{SESSION_ID}} with a real session identifier at runtime.a1b2c3d4-e5f6-7890-abcd-ef1234567890).aliyun cloudfw describe-*, aliyun sls get-logs-v2, aliyun actiontrail lookup-events) MUST include --user-agent "AlibabaCloud-Agent-Skills/alibabacloud-cfw-acl-diagnosis/{{SESSION_ID}}".which aliyun, aliyun version, aliyun plugin list, and aliyun plugin update do NOT call Alibaba Cloud service APIs and MUST NOT add --user-agent.which aliyun && aliyun version
aliyun plugin list # Confirm aliyun-cli-cloudfw installed
Install plugin if missing (requires explicit user confirmation before execution): aliyun plugin install cloudfw
Credentials: ALIBABA_CLOUD_ACCESS_KEY_ID / ALIBABA_CLOUD_ACCESS_KEY_SECRET env vars. See references/ram-policies.md.
Region: Always use cn-hangzhou (Cloud Firewall is a global service, do NOT ask user for region).
| Scenario | Firewall Type | Key Parameter |
|---|---|---|
| Public IP, EIP, Internet inbound/outbound | Internet Firewall | No FirewallId (global) |
| VPC inter-access, CEN, Express Connect | VPC Boundary Firewall | VpcFirewallId |
| NAT Gateway, SNAT/DNAT | NAT Boundary Firewall | NatFirewallId |
Key differences:
--Direction <in|out> required; asset-level EngineMode (strict/loose)Direction; firewall-level StrictMode (0=loose, 1=strict); supports domain rulesDirection; no strict mode; no domain rules (Layer 4 only)Protected asset identification:
in) → Protected asset = Destinationout) → Protected asset = Source (public IP, not internal CIDR)Process: Step 0 → Step 1 → Step 2 (3 checks) → [ANY FAIL: output conclusion, STOP] → Step 3 → Step 4 → Report
🔴 FORBIDDEN before Step 2 complete: Do NOT mention engine mode, give conclusions, suggest solutions, or skip any CLI query.
Extract from user message — do NOT re-ask what user already provided:
| Firewall | Command |
|---|---|
| Internet | aliyun cloudfw describe-control-policy --Direction <in|out> --CurrentPage 1 --PageSize 50 --user-agent "AlibabaCloud-Agent-Skills/alibabacloud-cfw-acl-diagnosis/{{SESSION_ID}}" |
| NAT | aliyun cloudfw describe-nat-firewall-control-policy --NatFirewallId <ID> --CurrentPage 1 --PageSize 50 --user-agent "AlibabaCloud-Agent-Skills/alibabacloud-cfw-acl-diagnosis/{{SESSION_ID}}" |
| VPC | aliyun cloudfw describe-vpc-firewall-control-policy --VpcFirewallId <ID> --CurrentPage 1 --PageSize 50 --user-agent "AlibabaCloud-Agent-Skills/alibabacloud-cfw-acl-diagnosis/{{SESSION_ID}}" |
Record: Source, Destination, DestinationType, AclAction, Order, Release.
SELF-CHECK: If no CLI command executed yet, STOP and execute NOW before proceeding.
Check 2.1: Asset/Firewall Status
aliyun cloudfw describe-asset-list --CurrentPage 1 --PageSize 50 --user-agent "AlibabaCloud-Agent-Skills/alibabacloud-cfw-acl-diagnosis/{{SESSION_ID}}"
ProtectStatus=open ✅ | other values ❌ (most common cause of rules not working)EngineMode: strict / loosealiyun cloudfw describe-nat-firewall-list --PageNo 1 --PageSize 50 --user-agent "AlibabaCloud-Agent-Skills/alibabacloud-cfw-acl-diagnosis/{{SESSION_ID}}"
StrictMode: 0=loose / 1=strictaliyun cloudfw describe-vpc-firewall-list --CurrentPage 1 --PageSize 50 --user-agent "AlibabaCloud-Agent-Skills/alibabacloud-cfw-acl-diagnosis/{{SESSION_ID}}"
Check 2.2: Policy Matches Asset
Check 2.3: Rule Enabled
Release=true ✅ | Release=false ❌🔴 MANDATORY STOP POINT — Step 2 Branch Gate — HARD STOP
IF any Check result is FAIL:
Permission Denied Handling: Record blocked check, mark as [Blocked - Permission Denied], continue remaining checks (NOT Step 3/4). List all blocked checks in final report.
# Internet FW
aliyun cloudfw describe-traffic-log --FirewallType InternetFirewall --Direction <in|out> \
--SourceCode yundun [--StartTime <unix>] [--EndTime <unix>] [--SrcIP <ip>] [--DstIP <ip>] \
--CurrentPage 1 --PageSize 10 --user-agent "AlibabaCloud-Agent-Skills/alibabacloud-cfw-acl-diagnosis/{{SESSION_ID}}"
# NAT FW
aliyun cloudfw describe-traffic-log --FirewallType NatFirewall --SourceCode yundun \
[--StartTime <unix>] [--EndTime <unix>] \
--CurrentPage 1 --PageSize 10 --user-agent "AlibabaCloud-Agent-Skills/alibabacloud-cfw-acl-diagnosis/{{SESSION_ID}}"
Critical: SourceCode=yundun required. Do NOT set FlowType (causes no results). RuleResult: 0=allow, 2=deny.
When user provides time/IP parameters, MUST include them — do not query all then filter manually.
Internet FW:
EngineMode=loose + domain rules → domain not matched → switch to strict modestrict + domain rules → test with curl/wget NOT telnet (telnet can't trigger domain recognition)AclPreState=app_unknown → L7 pre-match, application not yet identifiedNAT FW:
StrictMode=0 + domain rules → domain not matched (likely root cause)See references/diagnosis.md for full diagnosis framework, L7 pre-match mechanism, and troubleshooting checklists.
STRICT FORMATTING INSTRUCTION — MANDATORY: read before writing a single word of output:
⚠️ Disclaimer: This tool is a read-only diagnostic assistant. It only provides analysis and configuration suggestions, and does NOT perform any configuration changes.
## Diagnosis Conclusion
[One-sentence root cause, max 50 characters]
## Pre-check Results (Step 2)
| Check Item | Actual CLI Value | Status |
|-----------|------------------|--------|
| ProtectStatus | [from describe-asset-list] | PASS/FAIL |
| EngineMode / StrictMode | [value] | loose/strict |
| Traffic Direction | [in/out] | PASS/FAIL |
| Release | [true/false] | PASS/FAIL |
| Policy Match | [analysis] | PASS/FAIL |
## Remediation Suggestions
[Console operation steps, one per line, max 3 items]
Verification Method: [one-line description]
Rules:
[Verified] (confirmed by CLI) / [Unverified] (theoretical) / [Blocked] (permission denied)TotalCount > PageSize, query all pages before making "all assets" summary statements| File | Purpose |
|---|---|
references/cli_commands.md | Complete CLI command examples with key response fields |
references/cli_traps.md | Common CLI pitfalls and error patterns |
references/diagnosis.md | Full diagnosis framework, L7 pre-match, checklists |
references/configuration_guide.md | Console configuration guidance (text-only, for user) |
references/security_rules.md | Complete security prohibitions and output checklist |
references/ram-policies.md | RAM permissions required |
references/cfw_acl_knowledge.md | ACL knowledge base and FAQ |