Add your public IP assets as protected objects so Anti-DDoS Native can apply the default mitigation policy. This topic describes how to add protected objects, enable cross-border traffic blocking, and troubleshoot common issues when adding an Anti-DDoS Advanced EIP asset.
Before you begin
To add protected objects (such as Advanced EIP assets) using an Anti-DDoS Native instance, you must first complete Service Linked Role (SLR) authorization. Go to the Instance Management page and complete the authorization. This allows the Anti-DDoS Native instance to access other cloud products.
Role name: AliyunServiceRoleForDDoSBgp. Policy: AliyunServiceRolePolicyForDDoSBgp.
Add a protected object
If this is your first time using Anti-DDoS Native, complete cloud product authorization when adding a protected object so that Anti-DDoS Native can access your other cloud products.
Standard cloud products
Automatic
Applicable scope
All editions of Anti-DDoS Native 2.0 instances.
Supported assets:
Supports automatic addition of assets under the current Alibaba Cloud account.
If multi-account management is enabled, only ECS, EIP (including NAT), IPv6 gateway, and SLB assets under member accounts are supported. Other asset types are not supported.
Addition rules
Trigger condition: A cloud product is automatically added only when its status is Traffic Scrubbing or Blackhole.
Existing assets: After you enable automatic addition, existing cloud products that meet the status requirements are added within 5 to 30 minutes.
Newly created assets: Newly created cloud products that meet the status rules are also automatically added as protected objects.
Multiple instances:
If you have purchased an Anti-DDoS Native 2.0 (Pay-as-you-go) instance, assets are preferentially added to that pay-as-you-go instance.
If you have purchased multiple Anti-DDoS Native 2.0 (Subscription) instances and all have automatic addition enabled, a random instance takes effect for protection.
Enable automatic addition
Log on to the Traffic Security console. In the left-side navigation pane, choose DDoS.
In the upper-left corner of the top navigation bar, select the resource group of the instance and select All Regions as the region.
In the left-side navigation pane, choose .
On the Protected Objects page, select the target instance and click Protection Status by Attack Status under Enable. Configure under which asset state the asset is automatically added as a protected object.
Manual
Applicable scope
Instance type | Edition | Asset scope that can be protected |
Anti-DDoS Native 1.0 (Subscription) | Anti-DDoS Native (Enterprise) | Current account assets |
Anti-DDoS Native 2.0 (Subscription) | Anti-DDoS Native (SMB) | Current account assets |
Anti-DDoS Native (Enterprise) | Current account assets; ECS, EIP (including NAT), IPv6 gateway, and SLB assets from member accounts | |
Anti-DDoS Native 2.0 (Pay-as-you-go) | Anti-DDoS Native (Enterprise) | Current account assets; ECS, EIP (including NAT), IPv6 gateway, and SLB assets from member accounts |
Add assets from the current account
Anti-DDoS Native 2.0
Log on to the Traffic Security console. In the left-side navigation pane, choose DDoS.
In the upper-left corner of the top navigation bar, select the resource group of the instance and select All Regions as the region.
In the left-side navigation pane, choose .
On the Protected Objects page, select the target instance and click Add Object for Protection.
Select Add Asset or Add Manually, and then click Confirm.
Add Asset: From the available assets, select public IP assets under the current Alibaba Cloud account.
Add Manually: Manually enter public IP assets under the current Alibaba Cloud account.
Verify that the added IP asset appears in the protected objects list with a Normal status.
Anti-DDoS Native 1.0
Log on to the Traffic Security console. In the left-side navigation pane, choose DDoS.
In the upper-left corner of the top navigation bar, select the resource group and region of the instance.
In the left-side navigation pane, choose .
On the Protected Objects page, select the target instance and click Add Object for Protection.
Select Add Asset or Add Manually, and then click Confirm.
Add Asset: From the available assets, select public IP assets under the current Alibaba Cloud account.
Add Manually: Manually enter public IP assets under the current Alibaba Cloud account.
Verify that the added IP asset appears in the protected objects list with a Normal status.
Add assets from member accounts
If the current Alibaba Cloud account has multi-account management enabled and is a management account, you can add public IP assets from member accounts as protected objects. For details, see Configuration instructions for multi-account unified management.
Log on to the Traffic Security console. In the left-side navigation pane, choose DDoS.
In the upper-left corner of the top navigation bar, select the resource group of the instance and select All Regions as the region.
In the left-side navigation pane, choose .
On the Protected Objects page, select the target instance and click Add Object for Protection.
On the Add Assets of Members tab, in the area of Owner Account of Asset, select the target account.
From the available assets, select the assets from the member account that need protection, and then click Confirm.
Verify that the added IP asset appears in the protected objects list with a Normal status.
Enhanced cloud products
Applicable scope
Applies only to Anti-DDoS Native 2.0 (Subscription) - Enterprise and Anti-DDoS Native 2.0 (Pay-as-you-go) instances.
Supported cloud products: Anti-DDoS Advanced EIP assets.
How Advanced EIPs work
After you purchase an Advanced EIP, the system automatically adds it as a protected object to an Anti-DDoS Native 2.0 (Pay-as-you-go) or an Anti-DDoS Native 2.0 (Subscription) - Enterprise instance. No manual configuration is required.
You cannot manually add Advanced EIPs from the console.
Automatic addition rules
Newly purchased Advanced EIP (non-Resource Directory scenario):
If you have only one Anti-DDoS Native 2.0 (Pay-as-you-go) instance, the EIP is automatically added to that instance.
If you have only one Anti-DDoS Native 2.0 (Subscription) - Enterprise instance, the EIP is automatically added to that instance.
If you have both a Pay-as-you-go instance and a Subscription - Enterprise instance, the EIP is preferentially added to the Pay-as-you-go instance.
Resource Directory (RD) multi-account scenario (sub-account purchases Advanced EIP): The EIP is automatically associated based on a hierarchical strategy:
Pay-as-you-go instances take priority over subscription instances.
Main account resources take priority over member account resources.
Subscription instances prefer the one with larger remaining capacity.
Priority
Account
Instance
1
RD main account
Anti-DDoS Native 2.0 (Pay-as-you-go)
2
RD member account
Anti-DDoS Native 2.0 (Pay-as-you-go)
3
RD main account
Anti-DDoS Native 2.0 (Subscription) - Enterprise
NotePrefer the instance with the largest remaining capacity.
4
RD member account
Anti-DDoS Native 2.0 (Subscription) - Enterprise
NotePrefer the instance with the largest remaining capacity.
Lifecycle of Advanced EIPs
The lifecycle of Advanced EIP assets is aligned with the Anti-DDoS Native 2.0 (Enterprise) instance:
When an Advanced EIP is released, the asset information is synchronized to Anti-DDoS Native via an API, and the asset is automatically removed from the instance.
When an Anti-DDoS Native (Subscription) instance expires, a message is synchronized to the EIP to stop traffic forwarding. After forwarding stops, the EIP can continue to be used once you renew the instance. If the instance is not renewed, the EIP follows the Anti-DDoS Native lifecycle for suspension and release.
When the Anti-DDoS Native instance is suspended and released, the associated Advanced EIP is also automatically released. The Advanced EIP stops providing services, and related configurations and data are permanently deleted and cannot be recovered.
WarningMigrate your business and data from the Advanced EIP before the Anti-DDoS Native instance is released to avoid data loss.
Manage protected objects
Enable cross-border traffic blocking
When enabled, this feature discards all cross-border traffic within a specified block period. It applies to scenarios where the service itself does not have cross-border traffic. Cross-border traffic blocking generally uses core routers on the carrier backbone network to discard traffic from specific regions close to the attack source.
Region support rules:
Public IP assets in the Chinese mainland: After cross-border traffic blocking is enabled, all traffic from outside the Chinese mainland is blocked.
Public IP assets outside the Chinese mainland: Cross-border traffic blocking is not supported.
Unblock mechanism: The traffic block is automatically lifted when the block duration ends. To lift the block early, manually disable the feature.
Quota and limits: The effective cross-border traffic blocking policy has a time limit and a monthly quota of 10 uses.
Check the attack analysis page in the Traffic Security console to determine whether all attack traffic originates from cross-border IPs. If so, enable cross-border traffic blocking for the public IP asset to avoid wasting your monthly quota.
Procedure
Log on to the Traffic Security console. In the left-side navigation pane, choose DDoS.
In the top navigation bar, select the resource group to which the instances belong and the region in which the instances reside.
Anti-DDoS Native 1.0 (Subscription) instances: Select the region in which the instance resides.
Anti-DDoS Native 2.0 (Subscription) and Anti-DDoS Native 2.0 (Pay-as-you-go) instances: Select All Regions.
In the left-side navigation pane, choose .
After selecting the target instance, locate the target IP and toggle the switch in the Cross-Border Traffic Blocking column. Set the block duration.
NoteThe block duration ranges from 30 minutes to 1 day, specified by the start time and end time. Once active, the duration cannot be modified. To change it, disable the active cross-border traffic blocking and re-enable it with a new duration.
View the configuration in the asset list. After the block duration ends, the traffic block is automatically canceled and the cross-border traffic blocking status changes to disabled.
View details of protected objects
Log on to the Traffic Security console. In the left-side navigation pane, choose DDoS.
In the top navigation bar, select the resource group to which the instances belong and the region in which the instances reside.
Anti-DDoS Native 1.0 (Subscription) instances: Select the region in which the instance resides.
Anti-DDoS Native 2.0 (Subscription) and Anti-DDoS Native 2.0 (Pay-as-you-go) instances: Select All Regions.
In the left-side navigation pane, choose .
On the Protected Objects page, select the instance you want to view. View the protection configuration details of the public IP assets under this instance.
IP assets and WAF assets
Item
Description
IP
The public IP asset bound to this instance.
Owner Account of Asset
Displayed when the current Alibaba Cloud account has multi-account management enabled, is a management account, and uses an Anti-DDoS Native 2.0 Anti-DDoS Native (Enterprise) instance. It indicates the Alibaba Cloud account to which the public IP asset belongs.
Traffic Scrubbing Threshold
The minimum access bandwidth that triggers traffic scrubbing, including traffic (Mbps) and packet rate (PPS). For more information, see Scrubbing threshold description for protected objects.
Asset Region
The region to which the public IP asset belongs.
Asset Type
The asset type of the public IP asset.
Status
The DDoS security status of the public IP asset.
Normal
Under blackhole: Click Actions in the Deactivate Blackhole Filtering column. In the Deactivate Blackhole Filtering dialog box, view the remaining blackhole deactivation times. After confirming the deactivation, click OK. View the blackhole event records. For details, see View blackhole event records.
Mitigation Policy
The protection policy template associated with the public IP asset.
If the value is Default, it indicates that the public IP asset uses the default protection capability of Anti-DDoS Native without a protection policy set. If it is a custom protection policy template, click the template to jump to the protection configuration page to view the template details.
Cross-Border Traffic Blocking
Whether cross-border traffic blocking is enabled.
Actions
Delete: Delete the protected object. This operation is supported only when the asset is in the blackhole state.
Deactivate Blackhole Filtering: This operation is supported only when the asset is in the blackhole state.
View Applied Policy: View the specific information of the protection policy that takes effect in real time for this public IP asset.
Anti-DDoS Advanced EIP
Item
Description
IP
Advanced EIP address.
Owner Account of Asset
Displayed when the current Alibaba Cloud account has multi-account management enabled and is a management account. It indicates the Alibaba Cloud account to which the Advanced EIP belongs.
Traffic Scrubbing Threshold
The minimum access bandwidth that triggers traffic scrubbing, including traffic (Mbps) and packet rate (PPS). For more information, see Scrubbing threshold description for protected objects.
Asset Region
The region to which the Advanced EIP belongs.
Asset Type
Anti-DDoS Advanced EIP (Advanced EIP).
Ports
The number of ports configured with port protection under the Advanced EIP. Click the icon to the left of the target IP to view which ports have protection policies configured.
Status
The DDoS security status of the Advanced EIP.
Normal
Under blackhole: Click Actions in the Deactivate Blackhole Filtering column. In the Deactivate Blackhole Filtering dialog box, view the remaining blackhole deactivation times. After confirming the deactivation, click OK. View the blackhole event records. For details, see View blackhole event records.
Mitigation Policy
The protection policy template associated with the Advanced EIP.
If the value is Default, it indicates that the Advanced EIP uses the default protection capability of Anti-DDoS Native without a protection policy set. If it is a custom protection policy template, click the template to jump to the protection configuration page to view the template details.
Cross-Border Traffic Blocking
Whether cross-border traffic blocking is enabled.
Actions
Add Port: Add a specified port. This operation is supported only when the Advanced EIP is in the blackhole state.
Deactivate Blackhole Filtering: This operation is supported only when the Advanced EIP is in the blackhole state.
View Applied Policy: View the protection policy details of the Advanced EIP.
Delete a protected object
On the Protected Objects page, select the target instance.
In the asset list, locate the target public IP asset or Advanced EIP and click Delete in the Actions column.
In the Delete Protected Object dialog box, review the warning and click OK.
Batch reassign assets
Log on to the Traffic Security console. In the left-side navigation pane, choose DDoS.
In the upper-left corner of the top navigation bar, select the resource group of the instance and select All Regions as the region.
In the left-side navigation pane, choose .
Navigate to the corresponding asset tab, such as Advanced EIP, and click Batch Reassign Assets below the list.
In the dialog box, select the target Anti-DDoS Native instance and click OK.
WarningThe entire batch migration fails if any of the following conditions occur. Partial migration is not supported:
Asset region mismatch: The destination instance does not support the region of the assets to be migrated (for example, Chinese mainland assets being migrated to an instance that supports only assets from regions outside the Chinese mainland).
Insufficient capacity: The number of assets to be migrated exceeds the protected IP limit of the destination instance.
Under attack: IPs in a scrubbing state cannot switch binding instances.
What's next
FAQ
Are Advanced EIPs automatically added as protected objects?
Yes. After you purchase an Advanced EIP, it is automatically added as a protected object. No manual configuration is required. For details, see Automatic addition rules.
Can I enable cross-border traffic blocking for Advanced EIPs?
Yes. As a protected object, an Advanced EIP can enable the feature when under cross-border DDoS attacks to block traffic from outside the Chinese mainland. The cross-border traffic blocking policy has a monthly quota of 10 uses. Use it only when under attack.
How does the Advanced EIP lifecycle relate to the Anti-DDoS Native instance?
The lifecycle of Advanced EIPs is aligned with Anti-DDoS Native 2.0 (Enterprise) instances. When an Advanced EIP is released, the asset is automatically removed from the Anti-DDoS Native instance. When an Anti-DDoS Native instance expires and is released, the associated Advanced EIP is also automatically released. For details, see Lifecycle of Advanced EIPs.
What do I do if the IP capacity is full?
Increase the protected IP capacity of your Anti-DDoS Native instance, or purchase a new instance. For related operations, see Instance management and Pricing.
How do I switch an asset from a member account to the management account?
A public IP asset can be protected by only one instance. Delete the protected object under the member account first, then add it under the management account.
What do I do if I receive the error "The IP address does not belong to you"?
Troubleshoot by following these steps:
Verify that the IP address you entered is correct.
Check the region of the cloud product that corresponds to the protected IP, and confirm it matches the region of the Anti-DDoS Native instance.
If the protected IP is a WAF IP, check the region of the WAF instance and confirm that Anti-DDoS Native supports that region. For supported regions, see What is Anti-DDoS Native.
If the protected IP type is IPv6, check whether public bandwidth is enabled. For how to enable IPv6 public bandwidth for ECS, see IPv6 communication.
What should I do if an Advanced EIP fails to be added?
If an Advanced EIP fails to be added as a protected object, check the following common causes and solutions:
SLR not authorized: The Advanced EIP feature requires SLR authorization. Go to the Instance Management page and complete the authorization as prompted.
Region mismatch: The Advanced EIP region does not match the Anti-DDoS Native instance region. Upgrade the instance to include the region of the Advanced EIP.
Insufficient capacity: The IP capacity of the instance is full. Upgrade the instance to increase the IP capacity.
Edition mismatch: The current instance edition does not support this feature. Upgrade to Anti-DDoS Native 2.0 (Enterprise).
Instance expired: The instance has expired. Renew the instance.
Instance released: The instance has been released. Purchase a new instance.
STS check error: A service-side error occurred. Try again later or contact technical support.