Purchase an Anti-DDoS Origin instance to protect your Alibaba Cloud public IP assets against DDoS attacks. The service provides native, zero-architecture-change protection for multiple assets and ports.
Choose a billing method
Anti-DDoS Origin protects Alibaba Cloud public IP assets without requiring changes to your business architecture. It supports multiple assets and ports with native integration. The service is available in two billing models:
Comparison item | Anti-DDoS Origin 2.0 (Subscription) | Anti-DDoS Origin 2.0 (Pay-as-you-go) End of sale |
Billing method | Subscription | Pay-as-you-go |
Supported asset types |
| Supports standard cloud products and enhanced cloud products (DDoS Mitigation Enhanced EIP). |
Protected region scope |
| All regions. |
Mitigation attempts |
| Unlimited. |
For more information about Anti-DDoS Origin, see What is Anti-DDoS Origin, Product overview, and Pricing.
Anti-DDoS Origin 2.0 (Subscription)
Before you begin, ensure the following:
You have a valid Alibaba Cloud account.
If this is your first time purchasing, you will be prompted to authorize the service-linked role (SLR) during the purchase process. Click OK in the authorization dialog to allow Anti-DDoS Origin to access related services such as ECS, SLB, NAT, and Elastic IP (EIP).
Go to the Anti-DDoS Origin 2.0 buy page and select Anti-DDoS Origin 2.0 (Subscription) as the product type.
Choose an edition based on the following comparison.
Comparison item
Standard edition
Enterprise edition
Supported asset types
Standard cloud products only.
Standard cloud products.
Enhanced cloud products—Anti-DDoS Native (Advanced) EIP.
Protected region scope
Single region only.
All regions under your Alibaba Cloud account.
Region matching rule for DDoS Mitigation (Enhanced) EIPs: The region of the enhanced EIP must exactly match the protected region set for the Anti-DDoS Origin instance.
If your Anti-DDoS Origin instance is restricted to the "Chinese mainland" region, you cannot add enhanced EIPs from overseas or other regions, and you cannot purchase Anti-DDoS Native (Advanced) EIP from overseas regions. Upgrade the Anti-DDoS Origin instance to adjust the protected region before purchasing an enhanced EIP in the corresponding region.
Protection Mode
Default: Insurance (2 Sessions/Month).
Default: Unlimited (Unlimited Sessions/Month).
Configure the following parameters to purchase an Anti-DDoS Origin 2.0 (Subscription) instance.
Parameter
Description
Edition
Anti-DDoS Native (SMB): Recommended if your public IP assets are in the same region and you have fewer than 30 IP addresses.
Enterprise:
Use if your public IP assets are distributed across multiple regions, if you have more than 30 IP addresses, or if your assets use both IPv4 and IPv6.
Required if you need to protect EIPs.
Protection Mode
Insurance (2 Sessions/Month): Provides two advanced mitigation attempts per month.
Unlimited (Unlimited Sessions/Month): Unlimited advanced mitigation attempts per month.
NoteContact your sales representative before purchasing the unlimited mitigation mode for Anti-DDoS Native (SMB) or the insurance mitigation mode for Enterprise.
For details about mitigation attempts, see Mitigation session overview.
Application Scope
Anti-DDoS Native (SMB): A single instance can protect public IP assets under one region only.
Enterprise: A single instance can protect all public IP assets across the Chinese mainland and non-Chinese mainland regions.
Protocol
The IP protocol types supported by the Anti-DDoS Origin instance.
Anti-DDoS Native (SMB): A single instance supports either IPv4 or IPv6, but not both.
Enterprise: A single instance supports both IPv4 and IPv6 simultaneously.
Clean Bandwidth
The normal business bandwidth to protect.
Metering Method of 95th Percentile Burstable Clean Bandwidth
Anti-DDoS Native (SMB) and Enterprise: Daily 95th Percentile is enabled by default. When your actual business bandwidth exceeds the base Clean Bandwidth, the instance uses elastic bandwidth by default. For more information, see Anti-DDoS Origin 2.0 billing items.
IP Addresses
The total number of IP addresses to protect.
Mitigation Logs
Available for Enterprise edition only. Provides full traffic log analysis and reporting.
Resource Group
A resource group organizes related resources under your Alibaba Cloud account for independent management of permissions and resource members. Select an existing resource group or create a resource group.
Subscription period
The validity period of the Anti-DDoS Origin instance. You can enable auto-renewal as needed.
Read and select the Service Agreement, then click Buy Now to complete the payment.
Log on to the Anti-DDoS Origin console to verify that your instance appears and is in the Running state.
Add protected assets to start protection. For more information, see Add protected assets.
After you authorize the service-linked role, the system automatically creates the role AliyunServiceRoleForDDoSBgp and the policy AliyunServiceRolePolicyForDDoSBgp. On subsequent purchases, the authorization dialog does not appear if the role already exists.
Anti-DDoS Origin 2.0 (Pay-as-you-go)
Anti-DDoS Origin 2.0 (Pay-as-you-go) is no longer available for purchase. If you have existing Pay-as-you-go instances, you can continue to use them. To purchase new instances, use the Subscription billing method.
Protection scenarios
After purchasing an Anti-DDoS Origin instance, you can protect different types of cloud products depending on the edition you selected. For details on configuring protection, see the linked topics.
Protect standard cloud products
Standard edition and Enterprise edition both support protecting standard cloud products. After purchase, add your public IP assets as protected assets to enable native DDoS protection without any architecture changes. For detailed steps, see Add protected assets.
Protect enhanced cloud products (DDoS mitigation enhanced EIP)
Enterprise edition is required to protect DDoS Mitigation (Enhanced) EIPs, which combine Anti-DDoS Origin's low-latency network path with Tbps-level defense capacity. Enhanced EIPs are automatically associated with the Protection instance that has the largest remaining IP quota. For more information, see Purchase a DDoS Protection (Enhanced) EIP and Add protected assets.
FAQ
What should I do if I selected the wrong region when purchasing an Anti-DDoS Origin instance?
Terminology: The "region" of an Anti-DDoS Origin instance refers to the sales region, which is independent of the region where your cloud assets reside. When purchasing, you must specify the "asset region," including single region, multiple regions in the Chinese mainland, international and China (Hong Kong) and Macao (China) and Taiwan (China), or global multi-regions.
Solution: If the IP addresses you need to protect are in a different region from the selected "asset region," contact technical support to request a refund, then repurchase an instance in the correct asset region.
What is the difference between the billing models of best-effort mitigation in Anti-DDoS Origin and elastic mitigation in Anti-DDoS Pro?
Anti-DDoS Origin provides Best practices for DDoS mitigation capability. When under attack, the system automatically dispatches the maximum DDoS mitigation capacity in the region where the Anti-DDoS Origin instance is located to provide best-effort mitigation. The best-effort mitigation service is included in the Anti-DDoS Origin instance package and does not incur additional elastic mitigation charges.
Elastic mitigation billing for Anti-DDoS Pro (Chinese mainland) is based on the peak bandwidth of the elastic bandwidth for the day. For more information, see Anti-DDoS Origin pricing details.
What are the core technical advantages of DDoS Protection Enhanced EIP (native high-defense EIP)? What business scenarios is it suitable for?
Core technical advantages
DDoS Protection Enhanced EIP combines the low-latency characteristics of Anti-DDoS Origin with the Tbps-level defense capability of Anti-DDoS Pro. Key advantages include:
Transparent deployment: Traffic is automatically scrubbed at the edge of the high-defense center. Scrubbed traffic flows directly to your servers through EIPs and shared bandwidth without significant changes to your business architecture.
Low latency and high-bandwidth defense:
Low latency: Retains the network path advantages of Anti-DDoS Origin, meeting the needs of latency-sensitive applications.
Tbps-level defense: Capable of mitigating large-scale DDoS attacks at the Tbps level, addressing the limited defense ceiling of traditional Anti-DDoS Origin.
Full asset coverage: Supports comprehensive protection for multiple IPs, multiple domain names, and multiple ports, suitable for business systems with large numbers of public IP assets.
Applicable business scenarios: This solution is designed for customers who need both "high-volume DDoS defense" and "ultra-low business latency," such as premium gaming and game distribution scenarios.