Anti-DDoS Pro provides an active flow blocking functionality to the China Telecom ISP line of Anti-DDoS Pro instances. You can manually block the flow to the China Telecom ISP line of your Anti-DDoS Pro instance.
When the China Telecom ISP line of your Anti-DDoS Pro instance suffers huge traffic attacks, you can temporarily block the flow at the server side of the Anti-DDoS Pro service, to reduce the possibility of the black hole penalty against the China Telecom ISP line. Because the black hole policy considers multiple factors such as the size of traffic attacks and the attack origin, flow blocking can reduce the possibility of the black hole penalty under certain conditions.
- Currently, only the China Telecom ISP line supports flow blocking.
- Each Anti-DDoS Pro service user have totally three chances to block the flow to the China Telecom ISP line of an Anti-DDoS Pro instance that has more than 60G basic protection bandwidth.
- You can choose to block flow from the International ISPs or Chinese non-China Telecom ISPs two region. But, you cannot block flow from the both regions at the same time.
- Single flow blocking can last from 5 minutes to 23 hours and 59 minutes. During the blocked period, you can actively reopen it at any time.
Log on to the Anti-DDoS Service console.
Go to Anti-DDoS Pro>Instance List, locate a China Telecom ISP line to be blocked, and click Setting under the Protection Info column.
Note: You can also go to Anti-DDoS Pro>Setting>DDoS Attack Protection page, and locate the China Telecom ISP line to be blocked.
Click Block Flow, select the China Telecom ISP line, click Block.
In the Flow Block dialog box, select the Blocked Region, set the Blocked Time, and then click OK.
- If the flow blocking fails, you may receive an error message. Troubleshoot the issues accordingly and try it again.
- If you do not receive any error, the flow is blocked successfully, and you can see the blocked region and blocked period in the list. To reopen the flow, click Reopen.