If DDoS attacks occur on an Alibaba Cloud asset that uses a public IP address and the volume of the DDoS attacks exceeds the mitigation capability provided by Anti-DDoS Origin Basic for the asset, you can purchase an Anti-DDoS Origin Enterprise instance. The Anti-DDoS Origin Enterprise instance uses all the protection capacity within the region where the asset is deployed to protect your service from DDoS attacks.

Background information

Anti-DDoS Origin Enterprise provides best effort protection. When DDoS attacks are detected, an Anti-DDoS Origin Enterprise instance automatically uses all the protection capacity within the region where the instance is deployed to defend against the DDoS attacks.

Prerequisites

Before you purchase an Anti-DDoS Origin Enterprise instance, make sure that you know the IP address that is attacked and the region where the asset resides.

Step 1: Purchase an Anti-DDoS Origin Enterprise instance

  1. Go to the Anti-DDoS Origin buy page.
  2. Configure the following parameters and complete the purchase of an Anti-DDoS Origin Enterprise instance.
    ParameterDescription
    Product TypeThe service that you want to purchase. Select Anti-DDoS Origin.
    Mitigation PlanThe mitigation plan of the Anti-DDoS Origin instance. Default value: Enterprise. You cannot change the value of this parameter.
    IP VersionThe IP version of the Anti-DDoS Origin instance. Valid values: IPV4 and IPV6.
    RegionThe region where the Anti-DDoS Origin Enterprise instance resides.
    Important The Anti-DDoS Origin Enterprise instance must reside in the same region as the asset that you want to protect.
    Business ScaleThe average network bandwidth of the service that you want to protect.

    For more information about how to estimate the scale of your service, see Business scale estimation.

    IP AddressesThe total number of public IP addresses that you want to protect. The minimum value that you can specify for this parameter is 100. If you want to protect more public IP addresses, you can increase the value.
    Mitigation LogsSpecifies whether to enable the mitigation logs feature. The mitigation logs feature provides full log analysis and reports of protected traffic. Valid values: On and Off.
    Note This feature is in public preview. During the public preview, this feature is free of charge. After you enable this feature, Mitigation Analysis (Beta) appears in the left-side navigation pane of the console.
    Resource GroupThe resource group of the Anti-DDoS Origin instance. A resource group is a group of resources that belong to an Alibaba Cloud account. You can manage members, permissions, and resources in a resource group. You can select an existing resource group or create a resource group.

    For more information, see Create a resource group.

    DurationThe validity period of the Anti-DDoS Origin instance. You can select Auto-renewal based on your business requirements.
  3. Click Buy Now and complete the payment.
    After you purchase the Anti-DDoS Origin Enterprise instance, you can go to the Manage Instances page to view the instance and add the public IP addresses that you want to protect to the instance as protected objects. For more information, see Add an object for protection.

Step 2: Add the public IP address of an asset to the Anti-DDoS Origin Enterprise instance

The following sections describe the methods to add an object to the Anti-DDoS Origin Enterprise instance for protection.

Add an object on the Protected Asset IP page

  1. Log on to the Traffic Security console.
  2. In the left-side navigation pane, choose Network Security > Anti-DDoS Origin > Protected Objects.
  3. In the top navigation bar, select the resource group and region of your instance.
  4. On the Protected Asset IP page, select the Anti-DDoS Origin Enterprise instance that you purchased and click Add Protected Asset.
  5. If you use Anti-DDoS Origin Enterprise for the first time, you must follow the instructions that are provided on the page to complete the authorization for the assets within your Alibaba Cloud account.
  6. In the Add Protected Asset dialog box, enter the public IP address of your asset that you want to protect and click OK.
    Note
    • You must enter the public IP address of an asset within your Alibaba Cloud account. The asset must be in the same region as the Anti-DDoS Origin Enterprise instance.
    • You must separate multiple public IP addresses with commas (,).

Add an object on the Manage Instances page

You can also add your asset on the Manage Instances page. On the Manage Instances page, find the Anti-DDoS Origin Enterprise instance that you purchased and click Add Protected Asset in the Actions column.
Note Add Protected Asset appears only if no public IP addresses of assets are added to the instance. If the public IP address of an asset is added to the instance, you can click Manage in the Actions column. On the Protected Asset IP page, click Add Protected Asset.

Result

After the public IP address of the asset is added to the Anti-DDoS Origin Enterprise instance, you can find the asset on the Assets page, move the pointer over the value in the Mitigation Capabilities column, and then view the mitigation capability that the Anti-DDoS Origin Enterprise instance provides for the asset.