All Products
Search
Document Center

Anti-DDoS:Protect website services

Last Updated:Sep 19, 2026

Anti-DDoS Proxy protects your website by routing traffic to Anti-DDoS nodes for scrubbing. It filters malicious attack traffic and forwards legitimate traffic to your origin server. This topic walks you through how to quickly add your website to Anti-DDoS Proxy and complete key configurations.

Applicable scope

  • Anti-DDoS Proxy instance: You have purchased an Anti-DDoS Proxy instance based on your business needs. For more information, see Purchase an Anti-DDoS Proxy instance.

  • ICP filing: If you use an Anti-DDoS Proxy instance deployed in the Chinese mainland, ensure that your domain has completed ICP filing.

Step 1: Add your website service

To protect your website with Anti-DDoS Proxy, first add the domain name of your website and configure a traffic forwarding rule in the Anti-DDoS Proxy console.

  1. Log on to the Website Config page in the Anti-DDoS Proxy console.

  2. In the top navigation bar, select the region of your instance.

    • Anti-DDoS Proxy (Chinese Mainland): Choose the Chinese Mainland region.

    • Anti-DDoS Proxy (Outside Chinese Mainland): Choose the Outside Chinese Mainland region.

  3. On the Website Config page, click Add Website.

    Note

    You can also click Batch Import at the bottom of the page to import multiple website configurations at once. The configurations must be in an XML file. For more information about the file format, see Other operations.

  4. Enter the Website Config information and click Next.

    Basic configuration

    • Function Plan: Select the function plan of the Anti-DDoS Proxy instance that you want to associate. Options: Standard and Enhanced.

      Note

      Hover over the Function plan description icon after Function Plan to view the feature differences between the Standard function plan and the Enhanced function plan. For more information, see differences between Standard and Enhanced function plans.

    • Instance: Select the Anti-DDoS Proxy instance that you want to associate.

      Important

      A domain name can be associated with a maximum of eight Anti-DDoS Proxy instances. The instances must use the same Function Plan.

    • Websites: Enter the domain name of the website that you want to protect. You can enter an exact-match domain name, such as www.example.com, or a wildcard domain name, such as *.example.com.

      Note
      • If configurations exist for both a wildcard domain name (for example, *.aliyundoc.com) and an exact-match domain name (for example, www.aliyundoc.com), Anti-DDoS Proxy prioritizes the forwarding rules and mitigation policies of the exact-match domain name (www.aliyundoc.com).

      • If you enter a root domain, only the root domain is protected. Second-level domains and other subdomains are not protected. If you want to protect a second-level domain, enter the second-level domain or a wildcard domain name.

      • You can enter only a domain name, not an IP address.

    • Protocol Type: Select the protocols that the website supports.

      • HTTP / HTTPS: The basic protocols for web services.

        Note

        For information about HTTPS settings, see the description on the HTTPS configuration tab.

      • Websocket / Websockets: Real-time communication protocols. If you select one of these protocols, HTTP or HTTPS is automatically selected.

    • Server Address: Set the address of the backend server (origin server) that Anti-DDoS Proxy uses during an origin fetch.

      • Origin IP Address: Enter the public IP addresses of the origin server. You can enter multiple IP addresses, separated by commas. Examples:

        • Origin server on Alibaba Cloud: Enter the public IP address of the origin ECS instance. If an SLB instance is deployed before the ECS instance, enter the public IP address of the SLB instance.

        • Origin server in a data center that is not managed by Alibaba Cloud or is on another cloud platform: Run the ping <domain name> command to query the public IP address to which the domain name resolves. Then, enter the public IP address.

      • Origin Domain Name:

    • Server Port: Set the port that the origin server uses to listen for website services.

      • HTTP/Websocket: The default port is 80.

      • HTTPS/Websockets: The default port is 443.

      • Custom Server Port:

        • Multiple ports: You can specify multiple ports, separated by commas. The total number of custom ports for all website services protected by the Anti-DDoS Proxy instance cannot exceed 10. This includes custom ports for different protocols.

        • Port range (HTTP/HTTPS): 80 to 65535

    HTTPS configuration

    If you select HTTPS for encrypted authentication, complete the following configurations.

    • Configure a certificate: To enable HTTPS, you must configure an SSL certificate that matches the website domain name.

    • Configure a TLS Security Settings:

      • TLS Versions for SSL Certificate: Select the TLS versions that the international standard HTTPS certificate supports.

        • TLS 1.0 and later. This setting provides the best compatibility but low security.: Supports TLS 1.0, TLS 1.1, and TLS 1.2.

        • TLS 1.1 and later. This setting provides good compatibility and medium security.: Supports TLS 1.1 and TLS 1.2.

        • TLS 1.2 and later. This setting provides good compatibility and high security level.: Supports TLS 1.2.

        • Enable TLS 1.3 Support: Supports TLS 1.3.

      • Cipher Suites for SSL Certificate: Select a supported cipher suite for the international standard HTTPS certificate, or select a custom cipher suite. Move the pointer over the 问号 icon for a cipher suite option to view the cipher suites that it includes.

    • Mutual Authentication:

      • Issued by Alibaba Cloud: Select a default CA certificate from the A default CA certificate is required. drop-down list. This certificate is issued by Alibaba Cloud's Certificate Management Service (Original SSL Certificate).

      • Not Issued by Alibaba Cloud:

        • First, upload the self-signed CA certificate to Certificate Management Service (Original SSL Certificate). For detailed instructions, see Upload Certificate Repository.

        • In the A default CA certificate is required. drop-down list, select the uploaded self-signed CA certificate.

    • Enable OCSP Stapling: OCSP stands for Online Certificate Status Protocol. It is used to query the certificate authority (CA) that issued the server certificate to check whether the certificate has been revoked. During a TLS handshake with the server, the client must obtain both the certificate and its corresponding OCSP response.

      Important

      OCSP responses are digitally signed by the CA and cannot be forged. Enabling this feature does not introduce additional security risks.

      • Disabled (Default): The client sends an OCSP query to the CA during the TLS handshake to verify whether the certificate has been revoked. This process blocks the connection and may cause page loading delays if the network is poor.

      • Enabled: Anti-DDoS Proxy performs the OCSP query and caches the result for 3,600 seconds. When a client initiates a TLS handshake request to the server, Anti-DDoS Proxy sends the cached OCSP response along with the certificate chain to the client. This avoids the blocking issue caused by client-side queries and improves HTTPS performance.

    • SM Certificate: Only Anti-DDoS Proxy (Chinese Mainland) instances support uploading SM-based HTTPS certificates. Only the SM2 algorithm is supported.

      • Allow Access Only from SM Certificate-based Clients: Off by default. Options:

        • On: Accepts only SM-certificate clients.

          Note

          When enabled, TLS suites, mutual authentication, and OCSP stapling settings for international standard HTTPS certificates do not take effect.

        • Off: Accepts clients with either an SM or international standard certificate.

      • SM Certificate: Select an SM certificate from the list. Upload the certificate to Certificate Management Service first.

      • SM Cipher Suites for HTTPS Support: The following cipher suites are enabled by default (not configurable):

        • ECC-SM2-SM4-CBC-SM3

        • ECC-SM2-SM4-GCM-SM3

        • ECDHE-SM2-SM4-CBC-SM3

        • ECDHE-SM2-SM4-GCM-SM3

    Advanced settings

    • Enable HTTPS Redirection: This setting is suitable for websites that support both HTTP and HTTPS. After you enable this setting, all HTTP requests are forcibly redirected to HTTPS requests on port 443 by default.

      Important
      • You can enable this setting only if you select both the HTTP and HTTPS protocols and do not select the Websocket protocol.

      • If you access a website over a non-standard HTTP port (other than 80) and enable force redirect to HTTPS, the access requests are redirected to HTTPS port 443 by default.

    • HTTP/2 Listener: If this switch is turned on, clients that use HTTP/2 can access Anti-DDoS Proxy. However, Anti-DDoS Proxy still uses HTTP/1.1 for origin fetch. The specifications of the HTTP/2 feature are as follows:

      • Basic specifications:

        • Idle timeout after a connection is closed (http2_idle_timeout): 120 s

        • Maximum number of requests per connection (http2_max_requests): 1,000

        • Maximum number of concurrent streams per connection (http2_max_concurrent_streams): 4

        • Maximum size of the entire request header list after HPACK decompression (http2_max_header_size): 256 K

        • Maximum size of an HPACK-compressed request header field (http2_max_field_size): 64 K

      • Configurable specifications: You can Upper Limit for HTTP/2 Streams, which is the maximum number of concurrent streams allowed between the client and Anti-DDoS Proxy.

    • Set Forward Connection Timeout: This is the idle timeout period for a persistent TCP connection established between a client and Anti-DDoS Proxy. It is the maximum wait time between two client requests.

      Note

      If no new request is received within the specified period, Anti-DDoS Proxy closes the connection to release resources.

  5. Enter the Forwarding Settings and click Next.

    Back-to-Origin settings

    • Back-to-origin Scheduling Algorithm: If you configure multiple Origin IP Addresses or Origin Domain Names, you can change the load balancing algorithm or set weights for different servers to determine how traffic is distributed among the origin servers.

      Method

      Scenarios

      Description

      Round-robin (Default)

      Scenarios that use multiple origin servers and require high load balancing performance.

      All requests are distributed to all server addresses in turn. By default, all server addresses have the same weight. You can change the weights of servers. A larger weight indicates a higher probability of receiving requests.

      IP hash

      Scenarios that require session consistency. In extreme cases, load imbalance may occur.

      Requests from the same client IP address are always directed to the same origin server to ensure session consistency. You can set weights for servers while using the IP hash algorithm. This lets you distribute traffic based on server processing capabilities and prioritize servers with better performance.

      Least time

      Services that are highly sensitive to access speed and response latency, such as games and online transactions.

      The intelligent DNS parsing capability and the least time algorithm for origin fetch ensure the shortest latency for the entire link from the POP to the origin server.

    • Retry Back-to-origin Requests: The number of health check probes to check the availability of the origin server for domain forwarding. The default value is 3. The retry mechanism works as follows:

      1. The back-to-origin retry feature is triggered only when service traffic accesses an edge zone. When the edge zone detects that the origin server of a domain name is unavailable, it retries the origin fetch.

      2. If the origin server is still unreachable after the maximum number of retries, it enters a silence period. During this period, no traffic is forwarded to the origin server, and no probes are sent.

      3. After the silence period ends, the back-to-origin retry feature is triggered again based on service traffic. If the retry is successful, the origin server is reactivated.

    • Traffic Marking:

      • Request Header Forwarding Configuration: Anti-DDoS Proxy supports request header forwarding. You can add or modify HTTP request headers when forwarding requests to your origin server. This helps identify and mark traffic that passes through Anti-DDoS Proxy.

        • Insert X-Client-IP to Get Originating IP Address: Passes the client’s original IP address.

        • Insert X-True-IP to Forward Client IP: Passes the IP address the client used to establish the connection.

        • Insert Web-Server-Type to Get Service Type: Usually added by the first proxy. Tells the backend server which frontend web server or proxy handled the request.

        • Insert WL-Proxy-Client-IP to Get Connection IP: Same function as X-Client-IP. A header specific to Oracle WebLogic Server.

        • X-Forwarded-Proto (Listener Protocol): The protocol used between the client and the first proxy.

      • Traffic marks

        • Default marks

          Note
          • JA3 Fingerprint, JA4 Fingerprint, Client TLS Fingerprint, and HTTP/2 Fingerprint require assistance from your account manager to configure.

          • If your service uses custom fields instead of default marks, see Custom Header below. After you configure it, your origin server parses this field from requests forwarded by Anti-DDoS Proxy. For parsing examples, see Get the true source IP address after configuring Anti-DDoS Proxy.

          • Originating Port: The header field name for the client’s originating port in the HTTP header. Typically recorded in the X-Forwarded-ClientSrcPort field.

          • Originating IP Address: The header field name for the client’s originating IP address in the HTTP header. Typically recorded in the X-Forwarded-For field.

          • JA3 Fingerprint: The name of the HTTP header field that contains the MD5 hash of the client's JA3 fingerprint. The default field is ssl_client_ja3_fingerprinting_md5.

          • JA4 Fingerprint: The name of the HTTP header field that contains the MD5 hash of the client's JA4 fingerprint. The default field is ssl_client_ja4_fingerprinting_md5.

          • Client TLS Fingerprint: The name of the HTTP header field that contains the MD5 hash of the client's TLS fingerprint. The default field is ssl_client_tls_fingerprinting_md5.

          • HTTP/2 Fingerprint: The header field name for the MD5 hash value generated from the client HTTP/2.0 fingerprint in the HTTP header. Typically recorded in the http2_client_fingerprint_md5 field.

        • Custom Header: Add a custom HTTP header (including field name and value) to mark requests that pass through Anti-DDoS Proxy. When Anti-DDoS Proxy forwards website traffic, it adds the configured field value to requests sent to your origin server. This helps your backend service analyze and track traffic.

          • Naming restrictions: To avoid overwriting original request header fields, do not use the following reserved or common field names for your custom header:

            • Anti-DDoS Proxy default fields:

              • X-Forwarded-ClientSrcPort: Used by default to get the client port for Layer 7 engine access.

              • X-Forwarded-ProxyPort: Used by default to get the listening port for Layer 7 engine access.

              • X-Forwarded-For: Used by default to get the client IP address for Layer 7 engine access.

              • ssl_client_ja3_fingerprinting_md5: Used by default to retrieve the MD5 hash of the client's JA3 fingerprint.

              • ssl_client_ja4_fingerprinting_md5: Used by default to retrieve the MD5 hash of the client's JA4 fingerprint.

              • ssl_client_tls_fingerprinting_md5: Used by default to retrieve the MD5 hash of the client's TLS fingerprint.

              • http2_client_fingerprint_md5: Used by default to get the MD5 hash value of the client HTTP/2.0 fingerprint.

            • Standard HTTP fields: Such as host, user-agent, connection, and upgrade.

            • Common proxy fields: Such as x-real-ip, x-true-ip, x-client-ip, web-server-type, wl-proxy-client-ip, eagleeye-rpcid, eagleeye-traceid, x-forwarded-cluster, and x-forwarded-proto.

          • Quantity limit: You can add up to five custom header labels.

          • Configuration recommendations:

            • Use default marks first.

            • Verify the header field configuration in the staging environment before applying it to the production environment.

            • We recommend keeping field values to 100 characters or less to avoid affecting forwarding performance.

    • CNAME Reuse: Select whether to enable CNAME reuse. After you enable CNAME reuse, you can add multiple domain names that are hosted on the same server to Anti-DDoS Proxy by pointing their DNS records to the same Anti-DDoS Proxy CNAME. You do not need to add a separate website configuration for each domain name. For more information, see CNAME reuse.

      Important

      This parameter is supported only by Anti-DDoS Proxy (Outside Chinese Mainland).

    Other settings

    • Enable HTTP Redirection of Back-to-origin Requests: If your website does not support HTTPS for origin fetch, you must enable this setting. After you enable this setting, all HTTPS requests are sent to the origin server over HTTP, and all Websockets requests are sent over Websocket. The default origin port is 80.

      Note

      If you access a website over a non-standard HTTPS port (other than 443) and enable HTTP for origin fetch, the access requests are redirected to HTTP port 80 of the origin server by default.

    • HTTP/2.0 Origin: After you enable HTTP/2.0 for back-to-origin requests, Anti-DDoS Proxy uses HTTP/2.0 to send requests to the origin.

      Warning
      • To configure this feature, contact your account manager.

      • If your origin server does not support HTTP/2.0, do not configure this feature. Otherwise, your website becomes inaccessible.

    • Cookie Settings

      • Delivery Status: Enabled by default. Anti-DDoS Proxy inserts a cookie into the client, such as a browser, to differentiate clients or obtain client fingerprints. For more information, see Configure HTTP flood protection.

        Important

        If you experience logon failures or session losses after you add your application to Anti-DDoS Proxy, you can try to disable this switch. Note that if you disable this switch, some HTTP flood protection features become ineffective.

      • Secure Attribute: Disabled by default. If you enable this attribute, the cookie is sent only over HTTPS connections, not HTTP connections. This helps protect the cookie from being stolen.

        Note

        We recommend that you enable this attribute if your website service supports only HTTPS connections.

    • Configure New Connection Timeout Period: The time that Anti-DDoS Proxy waits to establish a connection to the origin server.

      Note

      If a connection is not established within this period, the attempt is considered a failure.

    • Configure Read Connection Timeout Period: The maximum time that Anti-DDoS Proxy waits for a response from the origin server after it establishes a connection and sends a read request.

    • Configure Write Connection Timeout Period: The time that Anti-DDoS Proxy waits after sending data and before the origin server starts processing it.

      Note

      If Anti-DDoS Proxy fails to send all data to the origin server or the origin server does not start processing the data within this period, the attempt is considered a failure.

    • Back-to-origin Persistent Connections: A TCP connection between a cache server and an origin server remains active for a period instead of closing after each request. This can waste resources. Enable Back-to-origin Persistent Connections to reduce connection establishment time and resource consumption, and to improve request processing efficiency and speed.

      • Requests Reusing Persistent Connections: The number of HTTP requests that can be sent over a single TCP connection from Anti-DDoS Proxy to the origin server. This reduces latency and resource consumption caused by frequent connection establishment and termination.

        Note

        We recommend that you set this value to be less than or equal to the number of requests per persistent connection configured on the backend origin server, such as a WAF or SLB instance. This prevents service inaccessibility caused by connection termination.

      • Timeout Period of Idle Persistent Connections: The maximum time that an idle persistent TCP connection from Anti-DDoS Proxy to the origin server can remain open in the connection pool of Anti-DDoS Proxy. If no new request is received within this period, the connection is closed to release system resources.

        Note

        We recommend that you set this value to be less than or equal to the timeout period configured on the backend origin server, such as a WAF or SLB instance. This prevents service inaccessibility caused by connection termination.

Step 2: Switch website traffic to Anti-DDoS Proxy

Website traffic must first pass through Anti-DDoS Proxy for scrubbing before being forwarded to the origin server. This enables Anti-DDoS Proxy to protect your website against DDoS attacks.

Warning

Test the forwarding configuration locally before updating DNS. Switching DNS without prior verification risks service interruption.

Complete these three tasks in order:

  1. Allow back-to-origin IP addresses. Add Anti-DDoS Proxy back-to-origin IP address ranges to your origin server's firewall or security group allowlist. This prevents the proxy's forwarded traffic from being blocked. For instructions, see Add back-to-origin IP addresses to allowlist.

  2. Verify the configuration locally. Before changing your DNS record, test the forwarding configuration by modifying your local hosts file. This confirms traffic is forwarded and the origin server responds correctly. For instructions, see Locally validate your forwarding configuration.

  3. Update your DNS record. After local verification passes, update your domain's DNS record to point to the CNAME address provided by Anti-DDoS Proxy. This routes live traffic through the Anti-DDoS scrubbing nodes. For instructions, see Point a domain name to Anti-DDoS Proxy.

Step 3: Configure mitigation policies

After adding your website, Anti-DDoS Proxy enables Anti-DDoS Global Mitigation Policy, Intelligent Protection, and Frequency Control by default. You can also enable additional protection features or modify protection rules on the Protection for Website Services tab.

  1. On the Website Config page, find the target domain name and click Actions > Mitigation Settings.

  2. On the Protection for Website Services tab, create a mitigation policy for the target domain name.

    Configuration Item

    Description

    Intelligent Protection

    Enabled by default. Intelligent Protection uses an intelligent and big data-based analysis engine to learn traffic patterns, detect and block new types of HTTP flood attacks, and dynamically adjust policies to block malicious requests. You can manually change the protection mode and level. For more information, see Use the intelligent protection feature.

    Anti-DDoS Global Mitigation Policy

    Enabled by default. Anti-DDoS Proxy provides three built-in global mitigation policies classified by traffic scrubbing intensity. These policies help you respond to volumetric attacks immediately and improve response timeliness. For more information, see Configure the global mitigation policy.

    Blacklist and Whitelist

    After enabling this policy, requests from IP addresses or CIDR blocks in the blacklist are blocked, and requests from IP addresses or CIDR blocks in the whitelist are allowed without filtering by any mitigation policy. For more information, see Configure blacklists and whitelists for domain names.

    Location Blacklist

    Block all website access requests from IP addresses in specified locations. For more information, see Configure a location blacklist for a domain name.

    Accurate Access Control

    Configure custom access control rules to filter requests based on commonly used HTTP fields such as IP, URI, Referer, User-Agent, and parameters. You can allow, block, or verify requests that match the rules. For more information, see Configure accurate access control rules.

    Frequency Control

    Enabled by default. Restrict the frequency of access from a single source IP address to your website. Frequency Control takes effect immediately after it is enabled. By default, the Normal mode is used to protect your website against common HTTP flood attacks. You can manually change the protection mode and create custom rules to reinforce protection. For more information, see Configure frequency control.

Step 4: View protection data

After adding your website to Anti-DDoS Proxy, use the security reports and log features in the Anti-DDoS Proxy console to view protection data.

  1. On the Security Overview page, view statistics for the instance and domain name, and details of DDoS attacks. For more information, see Security Overview.

  2. On the Operation Logs page, view important operation records. For more information, see Operation logs.

  3. On the Log Analysis page, view logs for your website. For more information, see Use the Log Analysis feature.

    Note

    The log analysis feature is a value-added service. To use this service, you must purchase and enable it. After enabling log analysis, Simple Log Service collects and maintains logs for website access and HTTP flood attacks. You can search and analyze log data in real time and view results on dashboards. For more information, see What is Simple Log Service?.

FAQ

  • After adding my website to Anti-DDoS Proxy, users report login failures or session loss.

    This issue is likely caused by the cookie insertion feature of Anti-DDoS Proxy, which is used for HTTP flood protection. Try disabling the Delivery Status switch in Forwarding Settings > Cookie Settings.

    Warning

    Note that disabling this feature affects the effectiveness of some HTTP flood protection rules.

  • I just purchased an instance. Is my website protected now?

    No. Purchasing an instance is only the first step. You must complete the Add Website configuration in the console and update your domain's DNS record to point to the CNAME address provided by Anti-DDoS Proxy. Your website traffic is protected only after the DNS change takes effect.