Protect the origin IP address after you add your website to Anti-DDoS Proxy. Otherwise, attackers may bypass Anti-DDoS Proxy and directly access the origin server. This topic describes how to configure ACLs for different network architectures.
ACLs on the origin server take effect only after attack traffic reaches the edge of the Alibaba Cloud network where the origin server resides.
ACLs can mitigate small-scale HTTP flood attacks and web attacks, but not volumetric DDoS attacks. If a volumetric DDoS attack reaches the network edge, it may exceed the origin server's mitigation capacity and trigger blackhole filtering.
If the origin IP address is exposed, change it as soon as possible. For more information, see Handle exposure of the origin IP address.
Network architecture of your website | ACL configuration description |
Anti-DDoS Proxy + Elastic Compute Service (ECS) instance | The origin server is an ECS instance. The back-to-origin IP addresses of your Anti-DDoS Proxy instance are the source IP addresses of the requests that are forwarded to the origin server. We recommend that you configure ACLs for the origin server by configuring the security group rules of the ECS instance. You can configure security group rules to allow traffic from only the back-to-origin IP addresses and deny all traffic from other IP addresses to protect the origin server. You can obtain the back-to-origin IP addresses of an Anti-DDoS Proxy instance in the Anti-DDoS Proxy console. |
Anti-DDoS Proxy + Origin server that is not deployed on Alibaba Cloud | The back-to-origin IP addresses of your Anti-DDoS Proxy instance are the source IP addresses of the requests that are forwarded to the origin server. We recommend that you configure ACLs for the origin server in the security software installed on the origin server, such as iptables and a firewall, to allow traffic only from the back-to-origin IP addresses and deny all traffic from other IP addresses to protect the origin server. |
Anti-DDoS Proxy + Layer 4 Server Load Balancer (SLB) instance + ECS instance | The back-to-origin IP addresses of your Anti-DDoS Proxy instance are the source IP addresses of the requests that are forwarded to the origin server. We recommend that you add the back-to-origin IP addresses of Anti-DDoS Proxy to the whitelist of the SLB instance. Then, enable access control to allow traffic only from the back-to-origin IP addresses to protect the origin server. For more information, see Enable access control. |
Anti-DDoS Proxy + Layer 7 Application Load Balancer (ALB) instance + ECS instance | The origin server is an ECS instance. The back-to-origin IP addresses of the ALB instance are the source IP addresses of the requests that are forwarded to the origin server. We recommend that you add the back-to-origin IP addresses of your Anti-DDoS Proxy instance to the whitelist of the ALB instance. Then, enable access control to allow traffic only from the back-to-origin IP addresses to protect the origin server. For more information, see Access control. |
Anti-DDoS Proxy + Web Application Firewall (WAF), Alibaba Cloud CDN (CDN), or Dynamic Content Delivery Network (DCDN) + ECS instance
Note If your origin server is not an ECS instance, the network architecture is the same. | Solution 1: The origin server is an ECS instance. The back-to-origin IP addresses of DCDN are the source IP addresses of the requests that are forwarded to the origin server. When you use DCDN, the IP address of the ECS instance is hidden. In most cases, you do not need to configure ACLs. If you want to configure ACLs, contact Alibaba Cloud technical support. Solution 2: The origin server is an ECS instance. The back-to-origin IP addresses of WAF are the source IP addresses of the requests that are forwarded to the origin server. We recommend that you configure ACLs for the ECS instance. For more information, see Configure protection for an origin server. |