All Products
Search
Document Center

Anti-DDoS:Configure ACLs for the origin server

Last Updated:Sep 01, 2026

Protect the origin IP address after you add your website to Anti-DDoS Proxy. Otherwise, attackers may bypass Anti-DDoS Proxy and directly access the origin server. This topic describes how to configure ACLs for different network architectures.

ACLs on the origin server take effect only after attack traffic reaches the edge of the Alibaba Cloud network where the origin server resides.

ACLs can mitigate small-scale HTTP flood attacks and web attacks, but not volumetric DDoS attacks. If a volumetric DDoS attack reaches the network edge, it may exceed the origin server's mitigation capacity and trigger blackhole filtering.

If the origin IP address is exposed, change it as soon as possible. For more information, see Handle exposure of the origin IP address.

Network architecture of your website

ACL configuration description

Anti-DDoS Proxy + Elastic Compute Service (ECS) instance

The origin server is an ECS instance. The back-to-origin IP addresses of your Anti-DDoS Proxy instance are the source IP addresses of the requests that are forwarded to the origin server.

We recommend that you configure ACLs for the origin server by configuring the security group rules of the ECS instance. You can configure security group rules to allow traffic from only the back-to-origin IP addresses and deny all traffic from other IP addresses to protect the origin server. You can obtain the back-to-origin IP addresses of an Anti-DDoS Proxy instance in the Anti-DDoS Proxy console.

Anti-DDoS Proxy + Origin server that is not deployed on Alibaba Cloud

The back-to-origin IP addresses of your Anti-DDoS Proxy instance are the source IP addresses of the requests that are forwarded to the origin server.

We recommend that you configure ACLs for the origin server in the security software installed on the origin server, such as iptables and a firewall, to allow traffic only from the back-to-origin IP addresses and deny all traffic from other IP addresses to protect the origin server.

Anti-DDoS Proxy + Layer 4 Server Load Balancer (SLB) instance + ECS instance

The back-to-origin IP addresses of your Anti-DDoS Proxy instance are the source IP addresses of the requests that are forwarded to the origin server.

We recommend that you add the back-to-origin IP addresses of Anti-DDoS Proxy to the whitelist of the SLB instance. Then, enable access control to allow traffic only from the back-to-origin IP addresses to protect the origin server. For more information, see Enable access control.

Anti-DDoS Proxy + Layer 7 Application Load Balancer (ALB) instance + ECS instance

The origin server is an ECS instance. The back-to-origin IP addresses of the ALB instance are the source IP addresses of the requests that are forwarded to the origin server.

We recommend that you add the back-to-origin IP addresses of your Anti-DDoS Proxy instance to the whitelist of the ALB instance. Then, enable access control to allow traffic only from the back-to-origin IP addresses to protect the origin server. For more information, see Access control.

Anti-DDoS Proxy + Web Application Firewall (WAF), Alibaba Cloud CDN (CDN), or Dynamic Content Delivery Network (DCDN) + ECS instance

  • (Recommended) Solution 1: Enable the DDoS mitigation and WAF features on DCDN

    • If a DDoS attack occurs, service traffic is forwarded to Anti-DDoS Proxy, then to DCDN, and finally to the ECS instance.

    • If no DDoS attacks occur, service traffic is forwarded to DCDN and then to the ECS instance.

      Note
      • This solution is available only for DCDN. If you deploy CDN, use Solution 2 or migrate your website to DCDN.

      • The protection capabilities of WAF are integrated into DCDN points of presence. You service traffic does not need to be forwarded to WAF.

  • Solution 2: Use the CDN or DCDN interaction feature to allow service traffic to be forwarded to WAF and then the ECS instance

    • If a DDoS attack occurs, service traffic is forwarded to Anti-DDoS Proxy, then to WAF, and finally to the ECS instance.

    • If no DDoS attacks occur, service traffic is forwarded to CDN, then to WAF, and finally to the ECS instance.

Note

If your origin server is not an ECS instance, the network architecture is the same.

Solution 1: The origin server is an ECS instance. The back-to-origin IP addresses of DCDN are the source IP addresses of the requests that are forwarded to the origin server. When you use DCDN, the IP address of the ECS instance is hidden. In most cases, you do not need to configure ACLs. If you want to configure ACLs, contact Alibaba Cloud technical support.

Solution 2: The origin server is an ECS instance. The back-to-origin IP addresses of WAF are the source IP addresses of the requests that are forwarded to the origin server.

We recommend that you configure ACLs for the ECS instance. For more information, see Configure protection for an origin server.