After you purchase an Anti-DDoS Native instance, add your public IP assets as protected objects so Anti-DDoS Native can apply the default mitigation policy. This topic describes how to add protected objects, enable close-to-source suppression for cross-border attacks, and troubleshoot common failure scenarios when adding enhanced EIP assets.
Before you begin
To add protected objects (such as enhanced EIP assets) using an Anti-DDoS Native instance, you must complete Service Linked Role (SLR) authorization. Go to the Instance Management page and complete the authorization to allow the Anti-DDoS Native instance to access other cloud products.
Role name: AliyunServiceRoleForDDoSBgp. Policy: AliyunServiceRolePolicyForDDoSBgp.
Add a protected object
If this is your first time using Anti-DDoS Native, complete cloud product authorization when adding a protected object so that Anti-DDoS Native can access your other cloud products.
Standard-tier cloud products
Automatic
Applicable scope
-
All editions of Anti-DDoS Native 2.0 instances.
-
Supported assets:
-
Supports automatic addition of assets under the current Alibaba Cloud account.
-
If multi-account management is enabled, only ECS, EIP (including NAT), IPv6 gateway, and SLB assets under member accounts are supported. Other asset types are not supported.
-
Automatic addition rules
-
Trigger condition: A cloud product is automatically added only when its status is Scrubbing or Blackhole.
-
Existing assets: After you enable automatic addition, existing cloud products that meet the status requirements are added within 5 to 30 minutes.
-
Newly created assets: Newly created cloud products that meet the status rules are also automatically added as protected objects.
-
Multiple instances:
-
If you have purchased an Anti-DDoS Native 2.0 (pay-as-you-go) instance, assets are preferentially added to the pay-as-you-go instance.
-
If you have purchased multiple Anti-DDoS Native 2.0 (subscription) instances and all have automatic addition enabled, the instance that takes effect for protection is random.
-
Enable automatic addition
Log on to the Traffic Security console,In the left-side navigation pane, choose DDoS.
-
In the upper-left corner of the top navigation bar, select the resource group of the instance and select All Regions as the region.
In the left-side navigation pane, choose .
-
On the Protected Objects page, select the target instance and click Protection Status by Attack Status under Enable. Configure under which asset state the asset is automatically added as a protected object.
Manual
Applicable scope
|
Instance type |
Edition |
Asset scope that can be protected |
|
Anti-DDoS Origin 1.0 (Subscription) |
Enterprise |
Current account assets |
|
Anti-DDoS Origin 2.0 (Subscription) |
Anti-DDoS Native (SMB) |
Current account assets |
|
Enterprise |
Current account assets, ECS, EIP (including NAT), IPv6 gateway, and SLB assets from member accounts |
|
|
Anti-DDoS Origin 2.0 (Pay-as-you-go) |
Enterprise |
Current account assets, member account assets |
Add assets from the current account
Anti-DDoS Native 2.0
Log on to the Traffic Security console,In the left-side navigation pane, choose DDoS.
-
In the upper-left corner of the top navigation bar, select the resource group of the instance and select All Regions as the region.
In the left-side navigation pane, choose .
-
On the Protected Objects page, select the target instance and click Add Object for Protection.
-
Select Add Asset or Add Manually, and then click Confirm.
-
Add Asset: From the available assets, select public IP assets under the current Alibaba Cloud account.
-
Add Manually: Manually enter public IP assets under the current Alibaba Cloud account.
-
-
Verify that the added IP asset appears in the protected objects list with a Normal status.
Anti-DDoS Native 1.0
Log on to the Traffic Security console,In the left-side navigation pane, choose DDoS.
-
In the upper-left corner of the top navigation bar, select the resource group and region of the instance.
In the left-side navigation pane, choose .
-
On the Protected Objects page, select the target instance and click Add Object for Protection.
-
Select Add Asset or Add Manually, and then click Confirm.
-
Add Asset: From the available assets, select public IP assets under the current Alibaba Cloud account.
-
Add Manually: Manually enter public IP assets under the current Alibaba Cloud account.
-
-
Verify that the added IP asset appears in the protected objects list with a Normal status.
Add assets from member accounts
If the current Alibaba Cloud account has multi-account management enabled and is a management account, you can add public IP assets from member accounts as protected objects. For details, see Configuration instructions for multi-account unified management.
Log on to the Traffic Security console,In the left-side navigation pane, choose DDoS.
-
In the upper-left corner of the top navigation bar, select the resource group of the instance and select All Regions as the region.
In the left-side navigation pane, choose .
-
On the Protected Objects page, select the target instance and click Add Object for Protection.
-
On the Add Assets of Members tab, in the area of Owner Account of Asset, select the target account.
-
From the available assets, select the assets from the member account that need protection, and then click Confirm.
-
Verify that the added IP asset appears in the protected objects list with a Normal status.
Enhanced-tier cloud products
Applicable scope
-
Applies only to Anti-DDoS Origin 2.0 (Subscription)-Enterprise instances and Anti-DDoS Origin 2.0 (Pay-as-you-go) instances.
-
Supported cloud products: Anti-DDoS Native (Advanced) EIP (enhanced EIPs).
How enhanced EIPs work
After you purchase an enhanced EIP, the system automatically adds it as a protected object to an Anti-DDoS Origin 2.0 (Pay-as-you-go) instance or an Anti-DDoS Origin 2.0 (Subscription)-Enterprise instance. No manual configuration is required.
You cannot manually add enhanced EIPs from the console.
Automatic addition rules
-
Newly purchased enhanced EIPs (non-Resource Directory scenario):
-
If you have only an Anti-DDoS Origin 2.0 (Pay-as-you-go) instance, the EIP is automatically added to the pay-as-you-go instance.
-
If you have only an Anti-DDoS Origin 2.0 (Subscription)-Enterprise instance, the EIP is automatically added under the Anti-DDoS Native (Enterprise) instance.
-
If you have both a pay-as-you-go instance and a subscription Enterprise instance, the EIP is preferentially added to the pay-as-you-go instance.
-
-
Resource Directory (RD) multi-account scenario (sub-account purchases enhanced EIP assets): The EIP is automatically associated based on a hierarchical strategy:
-
Pay-as-you-go instances take priority over subscription instances.
-
Main account resources take priority over member account resources.
-
Subscription instances prefer the one with larger remaining capacity.
Priority
Account
Instance
1
RD management account
Anti-DDoS Native 2.0 (pay-as-you-go)
2
RD member account
Anti-DDoS Native 2.0 (pay-as-you-go)
3
RD main account
Anti-DDoS Native 2.0 (subscription) - Anti-DDoS Native (Enterprise)
NotePrefer the one with larger remaining capacity.
4
RD member account
Anti-DDoS Native 2.0 (subscription) - Anti-DDoS Native (Enterprise)
NotePrefer the one with larger remaining capacity.
-
Lifecycle of enhanced EIPs
The lifecycle of enhanced EIP assets is aligned with the Anti-DDoS Native 2.0 Anti-DDoS Native (Enterprise) instance:
-
When an enhanced EIP is released, the asset information is synchronized to Anti-DDoS Native via an API, and the asset is automatically removed from the instance.
-
When an Anti-DDoS Native (subscription) instance expires, a message is synchronized to the EIP to stop traffic forwarding. After forwarding stops, the EIP can continue to be used once you renew the instance. If the instance is not renewed, the EIP follows the Anti-DDoS Native lifecycle for suspension and release.
-
When the Anti-DDoS Native instance is suspended and released, the associated enhanced EIP is also automatically released. The enhanced EIP stops providing services, and related configurations and data are permanently deleted and cannot be recovered.
WarningMigrate your business and data from the enhanced EIP before the Anti-DDoS Native instance is released to avoid data loss.
Manage protected objects
Enable close-to-source suppression
Close-to-source suppression discards all cross-border traffic within a specified suppression period. It applies to scenarios where the service itself does not have cross-border traffic. Close-to-source suppression generally uses core routers on the carrier backbone network to discard traffic from specific regions close to the attack source.
-
Region support rules:
-
Public IP assets in the Chinese mainland: After close-to-source suppression is enabled, all traffic from outside the Chinese mainland (including overseas regions, Hong Kong, Macao, and Taiwan) is blocked.
-
Public IP assets outside the Chinese mainland (including overseas regions, Hong Kong, Macao, and Taiwan): Close-to-source suppression is not supported.
-
-
Unblock mechanism: The traffic block is automatically lifted when the suppression period ends. To lift the block early, manually disable close-to-source suppression.
-
Quota and limits: The effective close-to-source suppression policy has a time limit and a monthly quota of 10 uses.
Check the attack analysis page in the Traffic Security console to determine whether all attack traffic originates from cross-border IPs. If so, enable close-to-source suppression for the public IP asset to avoid wasting your monthly quota.
Procedure
Log on to the Traffic Security console,In the left-side navigation pane, choose DDoS.
In the top navigation bar, select the resource group to which the instances belong and the region in which the instances reside.
Anti-DDoS Origin 1.0 (Subscription) instances: Select the region in which the instance resides.
Anti-DDoS Origin 2.0 (Subscription) and Anti-DDoS Origin 2.0 (Pay-as-you-go) instances: Select All Regions.
In the left-side navigation pane, choose .
-
After selecting the target instance, locate the target IP and toggle the switch in the Cross-Border Traffic Blocking column. Set the suppression duration.
NoteThe suppression duration ranges from 30 minutes to 1 day, specified by the start time and end time. Once active, the duration cannot be modified. To change it, disable the active close-to-source suppression and re-enable it with a new duration.
-
View the configuration in the asset list. After the suppression duration ends, the traffic block is automatically canceled and the close-to-source suppression status changes to disabled.
View details of protected objects
Log on to the Traffic Security console,In the left-side navigation pane, choose DDoS.
In the top navigation bar, select the resource group to which the instances belong and the region in which the instances reside.
Anti-DDoS Origin 1.0 (Subscription) instances: Select the region in which the instance resides.
Anti-DDoS Origin 2.0 (Subscription) and Anti-DDoS Origin 2.0 (Pay-as-you-go) instances: Select All Regions.
In the left-side navigation pane, choose .
-
On the Protected Objects page, select the instance you want to view. View the protection configuration details of the public IP assets under this instance.
IP assets and WAF assets
Item
Description
Asset IP Address
The public IP asset bound to this instance.
Owner Account of Asset
Displayed when the current Alibaba Cloud account has multi-account management enabled, is a management account, and uses an Anti-DDoS Native 2.0 Anti-DDoS Native (Enterprise) instance. It indicates the Alibaba Cloud account to which the public IP asset belongs.
Traffic Scrubbing Threshold
The minimum access bandwidth that triggers traffic scrubbing, including traffic (Mbps) and packet rate (PPS). For more information, see Scrubbing threshold description for protected objects.
Asset Region
The region to which the public IP asset belongs.
Asset Type
The asset type of the public IP asset.
Status
The DDoS security status of the public IP asset.
-
Normal
-
Under blackhole: Click Actions in the Deactivate Blackhole Filtering column. In the Deactivate Blackhole Filtering dialog box, view the remaining blackhole deactivation times. After confirming the deactivation, click OK. View the blackhole event records. For details, see View blackhole event records.
Mitigation Policy
The protection policy template associated with the public IP asset.
If the value is Default, it indicates that the public IP asset uses the default protection capability of Anti-DDoS Native without a protection policy set. If it is a custom protection policy template, click the template to jump to the protection configuration page to view the template details.
Cross-Border Traffic Blocking
Whether close-to-source suppression is enabled.
Actions
-
Delete: Delete the protected object. This operation is supported only when the asset is in the blackhole state.
-
Deactivate Blackhole Filtering: This operation is supported only when the asset is in the blackhole state.
-
View Applied Policy: View the specific information of the protection policy that takes effect in real time for this public IP asset.
Anti-DDoS Native (Advanced) EIP (enhanced EIPs)
Item
Description
IP
Enhanced EIP address.
Owner Account of Asset
Displayed when the current Alibaba Cloud account has multi-account management enabled and is a management account. It indicates the Alibaba Cloud account to which the enhanced EIP belongs.
Traffic Scrubbing Threshold
The minimum access bandwidth that triggers traffic scrubbing, including traffic (Mbps) and packet rate (PPS). For more information, see Scrubbing threshold description for protected objects.
Asset Region
The region to which the enhanced EIP belongs.
Asset Type
EIP with Anti-DDoS (Enhanced) enabled (enhanced EIP).
Ports
The number of ports configured with port protection under the enhanced EIP. Click the icon to the left of the target IP to view which ports have protection policies configured.
Status
The DDoS security status of the enhanced EIP.
-
Normal
-
Under blackhole: Click Actions in the Deactivate Blackhole Filtering column. In the Deactivate Blackhole Filtering dialog box, view the remaining blackhole deactivation times. After confirming the deactivation, click OK. View the blackhole event records. For details, see View blackhole event records.
Mitigation Policy
The protection policy template associated with the enhanced EIP.
If the value is Default, it indicates that the enhanced EIP uses the default protection capability of Anti-DDoS Native without a protection policy set. If it is a custom protection policy template, click the template to jump to the protection configuration page to view the template details.
Cross-Border Traffic Blocking
Whether close-to-source suppression is enabled.
Actions
-
Add Port: Add a specified port. This operation is supported only when the enhanced EIP is in the blackhole state.
-
Deactivate Blackhole Filtering: This operation is supported only when the enhanced EIP is in the blackhole state.
-
View Applied Policy: View the protection policy details of the enhanced EIP.
-
Delete a protected object
-
On the Protected Objects page, select the target instance.
-
In the asset list, locate the target public IP asset or enhanced EIP and click Delete in the Actions column.
-
In the Delete Protected Object dialog box, review the warning and click OK.
Batch adjust instance binding
Log on to the Traffic Security console,In the left-side navigation pane, choose DDoS.
-
In the upper-left corner of the top navigation bar, select the resource group of the instance and select All Regions as the region.
In the left-side navigation pane, choose .
-
Navigate to the corresponding asset tab, such as EIPs with Anti-DDoS (Enhanced) Enabled, and click Batch Adjust Instance Binding below the list.
-
In the dialog box, select the target Anti-DDoS Native instance and click Confirm.
WarningThe entire batch migration fails if any of the following conditions occur. Partial migration is not supported:
-
Asset region mismatch: The destination instance does not support the region of the assets to be migrated (for example, mainland China assets being migrated to an instance that supports only non-mainland China regions).
-
Insufficient capacity: The number of assets to be migrated exceeds the protected IP limit of the destination instance.
-
Under attack: IPs in a scrubbing state cannot switch binding instances.
-
What's next
FAQ
-
Are enhanced EIPs automatically added as protected objects?
Yes. After you purchase an enhanced EIP, it is automatically added as a protected object. No manual configuration is required. For details, see Automatic addition rules.
-
Can I enable close-to-source suppression for enhanced EIPs?
Yes. As a protected object, an enhanced EIP can enable close-to-source suppression when under cross-border DDoS attacks to block traffic from outside the Chinese mainland. The close-to-source suppression policy has a monthly quota of 10 uses. Use it only when under attack.
-
How does the enhanced EIP lifecycle relate to the Anti-DDoS Native instance?
The lifecycle of enhanced EIPs is aligned with Anti-DDoS Native 2.0 Anti-DDoS Native (Enterprise) instances. When an enhanced EIP is released, the asset is automatically removed from the Anti-DDoS Native instance. When an Anti-DDoS Native instance expires and is released, the associated enhanced EIP is also automatically released. For details, see Lifecycle of enhanced EIPs.
-
What do I do if the IP capacity is full?
Increase the protected IP capacity of your Anti-DDoS Native instance, or purchase a new instance. For related operations, see Instance management and Pricing.
-
How do I switch an asset from a member account to the management account?
A public IP asset can be protected by only one instance. Delete the protected object under the member account first, then add it under the management account.
-
What do I do if I receive the error "The IP address does not belong to you"?
Troubleshoot by following these steps:
-
Verify that the IP address you entered is correct.
-
Check the region of the cloud product that corresponds to the protected IP, and confirm it matches the region of the Anti-DDoS Native instance.
-
If the protected IP is a WAF IP, check the region of the WAF instance and confirm that Anti-DDoS Native supports that region. For supported regions, see What is Anti-DDoS Native.
-
If the protected IP type is IPv6, check whether public bandwidth is enabled. For how to enable IPv6 public bandwidth for ECS, see IPv6 communication.
-
-
What should I do if an enhanced EIP fails to be added?
If an enhanced EIP fails to be added as a protected object, check the following common causes and solutions:
-
SLR not authorized: The enhanced EIP feature requires Service Linked Role (SLR) authorization. Go to the Instance Management page and complete the authorization as prompted.
-
Region mismatch: The enhanced EIP region does not match the Anti-DDoS Native instance region. Upgrade the instance to include the region of the enhanced EIP.
-
Insufficient capacity: The IP capacity of the instance is full. Upgrade the instance to increase the IP capacity.
-
Edition mismatch: The current instance edition does not support this feature. Upgrade to Anti-DDoS Native 2.0 Anti-DDoS Native (Enterprise).
-
Instance expired: The instance has expired. Renew the instance.
-
Instance released: The instance has been released. Purchase a new instance.
-
STS check error: A service-side error occurred. Try again later or contact technical support.
-