All Products
Search
Document Center

Anti-DDoS:IP protection policy

Last Updated:Sep 09, 2026

IP-specific mitigation policies filter malicious traffic during network-layer or transport-layer DDoS attacks without disrupting legitimate operations. Rules include AI-based intelligent protection, blacklists and whitelists, geo-blocking, port blocking, and packet fingerprint filtering. This topic describes how to create, modify, and manage IP-specific mitigation policies.

Limitations

  • Standard cloud assets support only IP-specific mitigation policies. Enhanced cloud assets support both IP-specific and port-specific mitigation policies. When both are configured, IP-specific policies take precedence.

  • A public IP address can be bound to only one IP-specific mitigation policy.

  • Custom mitigation policies are specific means by which Anti-DDoS Native intercepts traffic. Traffic intercepted by a custom mitigation policy is still counted toward attack traffic statistics.

Before you begin

  • To protect standard cloud assets: regardless of the Anti-DDoS Native edition (1.0, 2.0, or post-paid), add public IP addresses to the protected objects first.

  • To protect enhanced cloud assets: Anti-DDoS Native automatically adds purchased enhanced cloud assets to protected objects. No manual action is required.

Create an IP-specific mitigation policy

Step 1: Create basic information

  1. Go to the Mitigation Settings page of the Traffic Security console.

  2. Click Create Policy. In the dialog box that appears, enter a Policy Name, and then click OK.

  3. After the policy is created, click OK in the The policy is created. dialog box to go to the Create Rule page.

    Note

    You can also find the newly created policy on the policy list page and click Modify Mitigation Policy to go to the rule configuration panel.

Step 2: Configure mitigation rules

On the Create Rule page, configure the following mitigation rules.

Rule effectiveness notes

  • Priority of rule effectiveness:

    • Standard cloud assets: ICMP protocol blocking > Whitelist > Blacklist > Geo-blocking > Port blocking > Packet fingerprint filtering.

    • Enhanced cloud assets: ICMP protocol blocking > Whitelist > Blacklist > Geo-blocking > Port blocking > Packet fingerprint filtering > Reflection attack filtering > Rate Limit by Source IP.

  • Rule effectiveness duration: All rules take effect permanently except the blacklist, which requires a duration setting.

  • Rule effectiveness timing: Note that some rules take effect only during attacks.

    • Takes effect during attacks: The rule activates only when Anti-DDoS Native detects attack traffic and initiates traffic scrubbing. It does not take effect in a non-attack state.

    • Always in effect: The rule remains in effect regardless of the attack state.

Mitigation rule overview

Rule

Standard cloud assets

Enhanced cloud assets

Description

Intelligent Protection

Unsupported

Supported

The intelligent big data analysis engine automatically learns the baseline of business traffic and adaptively protects against DDoS attacks.

ICMP Blocking

Supported

Takes effect during attacks

Supported

Always in effect

Discards ICMP traffic during scrubbing to filter ICMP attacks and reduce server probing risk.

Blacklist and Whitelist

Supported

Takes effect during attacks

Supported

Always in effect

Configures filtering or allow rules based on source IP addresses. You can add up to 2,000 IP addresses to each blacklist and whitelist.

Location Blacklist

Supported

Takes effect during attacks

Supported

Always in effect

Blocks access requests based on geographic regions. You can block by region or country.

Port Blocking

Supported

Takes effect during attacks

Supported

Always in effect

Configures source or destination port filtering rules for UDP or TCP protocols. Supports up to 8 rules.

Source Rate Limiting

Unsupported

Supported

Always in effect

Rate-limits source IP addresses whose access frequency exceeds the threshold. Supports four dimensions: PPS, BPS, SYN PPS, and PS.

Reflection Attack Filtering

Unsupported

Supported

Always in effect

Applies only to UDP protocol traffic. Discards traffic from specified UDP reflection source ports. Supports default and custom rule types.

Fingerprint

Supported

Takes effect during attacks

Supported

Always in effect

Applies only to TCP and UDP packets. Identifies attack packets by matching header fields and data body content, and then filters, allows, or rate-limits traffic based on the match result. Both a visual mode and an expression mode are supported.

SIP Protocol Protection

Supported

Takes effect during attacks

Supported

Always in effect

Designed for VoIP/voice communication services. Allows fragmented SIP protocol packets to pass through, and supports non-SIP protocol packet filtering, SIP client probing, and SIP source rate limiting.

Anti-DDoS Proxy Back-to-Origin Whitelisting

Unsupported

Supported

Adds the back-to-origin IP addresses of Anti-DDoS Proxy to the access control whitelist to prevent accidental blocking of business traffic.

Intelligent Protection

The intelligent big data analysis engine learns the baseline of business traffic and adaptively protects against network-layer and transport-layer DDoS attacks.

  • Applicable scenario: Always in effect for both standard and enhanced cloud assets.

  • Protection effect: Based on historical traffic data and expert experience algorithms, the protection levels are:

    Important

    After you create a policy template, this feature is enabled by default at the Normal. Optimal protection requires approximately 3 days of business traffic training.

    • Loose: Blocks IPs with obvious attack patterns. Some attacks may pass through, but false positives are low.

    • Normal: Blocks both obvious and suspected malicious IPs. Balances protection and false positives.

    • Strict: Maximum defense, but higher false positive rate.

  • Configuration method:

    1. On the rule configuration panel, find the Intelligent Protection section.

    2. In the Level section, select a protection level: Loose, Normal, or Strict.

ICMP Blocking

Discards ICMP traffic during scrubbing to filter ICMP attacks and reduce server probing risk.

  • Applicable scenario: Takes effect during attacks for standard cloud assets. Always in effect for enhanced cloud assets.

  • Protection effect:

    • When ICMP blocking is enabled, ping commands receive no responses.

      Warning

      Disable ICMP blocking before running network diagnostics. Otherwise, ping will not work.

    • ICMP blocking also applies to whitelisted IPs. ICMP traffic from whitelisted IPs is discarded.

  • Configuration method:

    1. On the rule configuration panel, find the ICMP Blocking section.

    2. In the Status section, turn on or off the switch. Enable this rule if your business does not use ICMP.

Blacklist and Whitelist

  • Applicable scenario: Takes effect during attacks for standard cloud assets. Always in effect for enhanced cloud assets.

  • Protection effect: Configures rules to directly discard or allow traffic from specified source IPs.

    Important

    If the traffic allowed by the whitelist is too large, the allowed traffic may still hit the default destination IP rate limiting policy of Anti-DDoS Native due to cloud asset specifications and cloud platform guarantees.

  • Configuration method:

    1. On the rule configuration panel, find the Blacklist and Whitelist section and click Settings.

    2. Select Blacklist or Whitelist, and complete the configuration as follows.

      Blacklist

      1. Set the timeout period (Blacklist only): You must set a timeout period when adding a blacklist. The setting applies to all IPs in the blacklist.

        1. On the Blacklist tab, click Validity Period Setting.

        2. In the Validity Period Setting section of the dialog box, set the timeout period based on your business needs. You can select Custom (5 to 43,200 minutes), Permanent, 30 minutes, or other time periods.

      2. Add IP addresses:

        1. Click Add. The Blacklist Configuration configuration dialog box appears.

        2. In the configuration dialog box, enter the blacklist IP addresses. Separate multiple addresses with spaces or line breaks.

          Note

          You can manually add up to 2,000 IP addresses to the blacklist.

      Whitelist

      1. Click Add. The Whitelist Configuration configuration dialog box appears.

      2. In the configuration dialog box, enter the whitelist IP addresses. Separate multiple addresses with spaces or line breaks.

        Note

        You can manually add up to 2,000 IP addresses to the whitelist.

Location Blacklist

Blocks access requests based on geographic regions.

  • Applicable scenario: Takes effect during attacks for standard cloud assets. Always in effect for enhanced cloud assets.

  • Protection effect: Traffic from blocked regions to the destination IP is discarded. Block by region or country.

  • Configuration method:

    1. On the rule configuration panel, find the Location Blacklist section.

    2. In the region selection list, select the regions or countries to block, and then click OK.

      Note

      Block all regions without legitimate business traffic.

Port Blocking

Configures source or destination port filtering rules for UDP or TCP protocols.

  • Applicable scenario: Takes effect during attacks for standard cloud assets. Always in effect for enhanced cloud assets.

  • Protection effect: Discards traffic from specified protocol ports. Use this to filter UDP reflection attacks.

  • Configuration suggestions:

    • If your assets use only TCP traffic, block all UDP source ports.

      Note

      Adjust the policy if you add UDP services later.

    • If your assets use UDP traffic, block common UDP reflection source ports: 1-52, 54-161, 389, 1900, and 11211.

  • Configuration method:

    1. On the rule configuration panel, click Settings in the Port Blocking section.

    2. On the Configure Source Port Blocking page, click Add Port.

    3. In the Add Port dialog box, complete the configuration as follows and click OK to save the rule.

      Note

      Supports up to 8 rules.

      • Protocol: Select the protocol type: TCP or UDP.

      • Source Port Range, Destination Port Range: Set the source port range and destination port range.

      • Action: Only Discard is supported.

Source Rate Limiting

Rate-limits source IP addresses whose access frequency exceeds the threshold.

  • Applicable scenario: Supported only by enhanced cloud assets. Always in effect.

  • Protection effect: Source IPs that exceed the threshold are blacklisted, and all their traffic is discarded.

  • Configuration method:

    1. On the rule configuration panel, click Settings in the Source Rate Limiting section.

    2. On the Configure Source Rate Limiting panel, turn on the rate limiting dimension switch (Source PPS, Source Bandwidth, PPS of Source SYN Packets, or Bandwidth of Source SYN Packets), and enter the rate limit threshold.

    3. (Optional) Enable the auto-add-to-blacklist feature: Select If a source IP address triggers rate limiting five times within 60 seconds, the IP address is added to the blacklist.. IPs that exceed the rate limit 5 times within 60 seconds are added to the blacklist.

Reflection Attack Filtering

  • Applicable scenario: Supported only by enhanced cloud assets. Always in effect.

  • Protection effect: Applies only to UDP traffic. Discards traffic from specified UDP reflection source ports.

  • Configuration method:

    1. On the rule configuration panel, click Settings in the Reflection Attack Filtering section.

    2. On the Configure Filtering Policies for UDP Reflection Attacks panel, select a filtering strategy. The following two strategies are supported:

      • One-click Filtering Policy: Lists common UDP reflection attack ports. Block all ports that your business does not use.

      • Custom Filtering Policy: Customize reflection source ports (up to 20). Ports cannot duplicate those in One-click Filtering Policy.

Fingerprint

  • Applicable scenario: Takes effect during attacks for standard cloud assets. Always in effect for enhanced cloud assets.

  • Protection effect: Forged attack packets typically share the same feature fields, such as a specific string or identical packet content. Fingerprint filtering identifies these packets by matching header fields and data body (payload) content, and then filters, allows, or rate-limits the traffic based on the match result. A single fingerprint rule can combine multiple match conditions, and can perform numeric operations on fields such as ports, packet length, IP addresses, TCP flags, and payload before comparing them.

    Note

    All fingerprint rules apply only to TCP and UDP packets.

  • Configuration method:

    1. On the rule configuration panel, click Settings in the Fingerprint section.

    2. On the Configure Fingerprint Rules panel, click Add Rule.

      A single protection policy supports a maximum of 8 fingerprint rules.

    3. On the Add Fingerprint Rule panel, select a rule mode.

      • Standard Mode: Select fields, numeric operations, and comparisons in a form, and combine multiple conditions with AND or OR. Suitable for common features, with no expression syntax to remember.

      • Expert Mode: Write the packet feature expression directly. Supports byte offset values, arithmetic and bitwise operations, and nesting. Suitable for complex feature scenarios.

      Important

      Rules created in the two modes are independent of each other and coexist in the same list. To keep the expression complete, the mode cannot be changed after a rule is created. To use a different mode, delete the rule and create it again.

    4. If you select Standard Mode, configure Rule Conditions as follows.

      • 1. Select Field: Select the packet field to match. For the supported fields and their valid values, see Supported fields and valid values in this topic.

      • 2. Numeric Operations: Optional. Perform an operation on the field value first, and then compare the result. The following operators are supported: & (bitwise AND), >> (right shift), +, and -. The operand can be a decimal or a 0x hexadecimal value. Address fields and version fields do not support numeric operations.

      • 3. Compare and Match: Select a comparison operator and enter a value. The following operators are supported: ==, !=, >, <, >=, <=, and in. The in operator performs a range match in the in [a, b] format, where both endpoints must be decimal values and a must not be greater than b.

      Click AND or OR to add more conditions. A single fingerprint rule supports a maximum of 10 Rule Conditions.

    5. If you select Expert Mode, enter an expression in the Packet Feature Expression field.

      • The expression uses Wireshark display filter syntax, for example tcp.srcport >= 80 and tcp.srcport <= 443 and ip.len > 1000. Auto-complete suggestions appear as you type a field name. You can also expand Syntax Reference and Examples and click a field in Fields and Values to insert it.

      • All fields in the expression must be supported fields, and the expression must contain at least one field.

      • Offsets written directly after a protocol name are not supported, such as udp[4:2] or ip[8]. Use the field form instead, such as udp.payload[4:2].

      • A single fingerprint rule supports a maximum of 20 subconditions.

    6. Configure Action, which is the action to perform on traffic after a feature match. Valid values: Pass, Discard, Rate Limit by Packet, Rate Limit by Flow, and Observe. If you select Rate Limit by Packet or Rate Limit by Flow, you must also set Bandwidth. Valid values: 1 to 100000.

    7. Optionally enter Remarks of up to 256 characters, and then click OK.

    Supported fields and valid values

    Standard Mode and Expert Mode use the same list of fields. In the following table, All refers to ==, !=, >, <, >=, <=, and in.

    Field category

    Field

    Supported comparison operators

    Valid values and description

    Port

    tcp.srcport, tcp.dstport, udp.srcport, udp.dstport

    All

    0 to 65535. Decimal or 0x hexadecimal values are supported.

    IP packet length

    ip.len

    All

    1 to 1500. Unit: bytes.

    Data body

    tcp.payload, udp.payload

    ==, !=, >, <, >=, and <=. The in operator is not supported.

    The [offset:bytes] range is required, where offset ranges from 0 to 1500 and bytes can only be 1, 2, or 4. The comparison value must be a 0x hexadecimal value of no more than 4 bytes, for example tcp.payload[0:4] == 0x12345678.

    IPv4 address

    ip.src, ip.dst, ip.addr

    == only

    Dotted decimal notation, with each octet ranging from 0 to 255. Leading zeros are not allowed. Numeric operations are not supported.

    IPv6 address

    ipv6.src, ipv6.dst

    == only

    Both the full format and the :: compressed format are supported. The IPv4-mapped format such as ::ffff:1.2.3.4 and the zone ID format such as fe80::1%eth0 are not supported. Numeric operations are not supported.

    TCP flag

    tcp.flags.fin, tcp.flags.syn, tcp.flags.rst, tcp.flags.psh, tcp.flags.ack, tcp.flags.urg, tcp.flags.ecn, tcp.flags.cwr

    == only

    Only the decimal value 0 or 1 is allowed. Hexadecimal values such as 0x1 and leading zeros such as 01 are not allowed.

    TCP sequence number

    tcp.seq, tcp.ack

    All

    0 to 4294967295.

    16-bit value

    tcp.window_size_value, tcp.checksum, tcp.urgent_pointer, udp.checksum, ip.id, ip.flags

    All

    0 to 65535. ip.flags is a 16-bit word. For details, see the syntax notes below.

    UDP packet length

    udp.length

    All

    8 to 65535. The UDP header is a fixed 8 bytes, so the minimum value is 8.

    Upper-layer protocol number

    ip.proto

    All

    0 to 255. Common values: 6 for TCP and 17 for UDP.

    Header length

    ip.hdr_len, tcp.hdr_len

    All

    20 to 60. Unit: bytes. For an exact == comparison, the value must be a multiple of 4, that is, 20, 24, 28, and so on up to 60.

    Protocol version

    ip.version, ipv6.version

    == only

    ip.version can only be 4, and ipv6.version can only be 6. Numeric operations are not supported.

    Syntax notes

    • Only the lowercase operators and and or can be used to join conditions, and they must be surrounded by spaces. (a)and(b) and the uppercase AND and OR cause a syntax error.

    • Only the lowercase 0x hexadecimal prefix is allowed. 0X1F is rejected.

    • The separator in a payload range is a colon, as in [offset:bytes], not a comma.

    • ip.flags is processed as a 16-bit word, which consists of the 3-bit IP flags and the 13-bit fragment offset. To match a specific flag, you must use the full literal value: write ip.flags == 0x4000 to match a set DF flag, and ip.flags == 0x2000 to match a set MF flag. ip.flags == 2 matches a fragment offset of 2 rather than the MF flag.

    • When a numeric operation is configured, the comparison value applies to the result of the operation instead of the original field value, so the valid values in the preceding table are no longer checked.

    • The total length of a single fingerprint rule cannot exceed 3000 characters.

SIP Protocol Protection

Designed for VoIP/voice communication services, SIP Protocol Protection allows fragmented SIP protocol packets to pass through. It also supports filtering non-SIP protocol packets, probing SIP client authenticity, and rate-limiting SIP traffic on demand.

Warning

Enable this feature only when your origin server actually hosts SIP/VoIP services. Otherwise, legitimate traffic may be inadvertently blocked.

  • Applicable scenario: Takes effect during attacks for standard cloud assets. Always in effect for enhanced cloud assets.

  • Protection effect:

    • Allows fragmented SIP protocol IP packets to pass through, preventing VoIP voice services from being interrupted due to false blocking of fragmented packets.

    • (Optional) Non-SIP Protocol Blocking: Directly drops non-SIP protocol packets within the configured SIP port range.

    • (Optional) SIP Client Probing: Actively probes clients using the SIP protocol and drops subsequent traffic from clients that do not respond or respond abnormally.

    • (Optional) SIP Source Rate Limiting: Enforces an upper rate limit on SIP packets from a single source IP address; traffic exceeding the limit is dropped.

  • Configuration method:

    1. On the rule configuration panel, find the SIP Protocol Protection section and click the card.

    2. In the SIP Protocol Protection panel that slides out from the right, turn on the Enable SIP Protocol Protection switch.

    3. Configure the following parameters, and then click OK.

      • SIP Port Range: Enter the SIP port used by your service. The default value is 5060. Supports single ports, multiple ports (comma-separated), or continuous ranges (hyphen-separated), and any combination thereof.

      • Defense mode: Select a protection level. The default is Normal. When you select Loose, Normal, or Strict, the system automatically fills in parameters based on the preset template and sets them to read-only. When you select Custom, the parameters below can be edited manually.

        Defense Mode

        Enabled Mitigation Capabilities

        Activation Threshold

        Scenarios

        Loose

        Non-SIP Protocol Blocking

        2,000 PPS

        Maximizes service availability. Suitable for voice services highly sensitive to false positives.

        Normal (default)

        Non-SIP Protocol Blocking, SIP Client Probing

        1,000 PPS

        Suitable for most VoIP services.

        Strict

        Non-SIP Protocol Blocking, SIP Client Probing, SIP Source Rate Limiting

        500 PPS + 10 Mbps; per-source rate limit: 1,000 PPS

        Suitable for scenarios under sustained SIP Flood attacks.

        Custom

        All parameters are manually configurable

        Custom

        Recommended for users with SIP protection experience.

      • Activation Threshold (editable only in Custom mode): The protection algorithm activates only when SIP traffic exceeds this threshold.

      • Non-SIP Protocol Blocking (editable only in Custom mode): When enabled, identifies and directly drops non-SIP protocol packets within the configured SIP port range. This is especially effective when ports are abused for reflection attacks or illegal payloads.

      • SIP Client Probing (editable only in Custom mode): When enabled, actively probes clients using the SIP protocol. Subsequent traffic from clients that do not respond or respond abnormally is dropped, effectively identifying spoofed sources or reflection bots.

      • SIP Source Rate Limiting (editable only in Custom mode): When enabled, enforces an upper rate limit on SIP packets from a single source IP address. Traffic exceeding the limit is dropped. You must specify a per-source rate limit value. Recommended when a large-volume SIP Flood attack has been confirmed.

Anti-DDoS Proxy Back-to-Origin Address Whitelisting

Adds Anti-DDoS Proxy back-to-origin IP addresses to the access control whitelist. Supported only by enhanced cloud assets. When protecting enhanced cloud assets, traffic is forwarded back to the origin through the Anti-DDoS Proxy scrubbing center. Enable this to prevent accidental blocking of legitimate business traffic.

Configuration method:

  1. On the rule configuration panel, find the Add Back-to-origin CIDR Blocks of Anti-DDoS Proxy to Whitelist section.

  2. Turn on or off the switch. Strongly recommended for enhanced cloud assets.

Step 3: Select protected objects

After configuring the mitigation rules, click Next to go to the protected objects selection page.

  1. In the Objects to Select section of the Protected Assets page, select the protected objects (public IP addresses) to which you want to apply this policy.

  2. Click Add. After the mitigation policy is created, click Back. On the Mitigation Settings page, you can view the newly created policy.

Note

A public IP address can be bound to only one IP-specific mitigation policy. If an IP is already bound to another policy, the original policy no longer applies to that IP after you bind a new one.

Modify an IP-specific mitigation policy

  1. On the Mitigation Settings page, locate the target policy and click Modify Mitigation Policy in the Actions column.

  2. In the Modify Mitigation Policy panel that slides out from the right, modify mitigation rules based on your business needs. Each rule follows the same configuration described in the "Create an IP-specific mitigation policy" section.

  3. After making modifications, click OK at the bottom of the panel to save your changes.

Warning

Modified policies take effect immediately for all associated protected objects. Proceed with caution.

Manage protected objects

  1. On the Mitigation Settings page, locate the target policy and click Add Object for Protection in the Actions column.

  2. On the View Applicable Object page, perform the following operations:

    • Add Object for Protection:

      Note

      A public IP address can be bound to only one IP-specific mitigation policy. If an IP is already bound to another policy, the original policy no longer applies to that IP after you bind a new one.

      1. Click Add Object for Protection above the list.

      2. In the Objects to Select section of the Protected Assets page, select the protected objects (public IP addresses) to which you want to apply this policy.

      3. Click Add at the bottom.

    • Delete: Click Delete in the Actions column for the target IP.

    • Delete: Select multiple target IPs and click Delete below the list.

  3. After saving the changes, return to the policy list page and verify that the Add Object for Protection column for the target policy displays the updated number of protected objects.

Delete an IP-specific mitigation policy

  1. On the Mitigation Settings page, locate the target policy and click Delete in the Actions column.

  2. In the confirmation dialog box that appears, confirm the policy name and click Delete.

Important

You cannot delete a policy associated with protected objects. Remove all associated protected objects first.

Configuration examples

Configure IP-specific mitigation policies for standard cloud assets under large-volume network-layer or transport-layer attacks based on your traffic characteristics.

Configuration item

Description

ICMP Blocking

Block ICMP traffic if your business does not use ICMP.

Blacklist and Whitelist

During attacks, add suspicious source IPs to the blacklist from the Attack Analysis page (up to 2,000 IPs). View attack event analysis.

Location Blacklist

Block all regions without business traffic. For example, if your business serves only Chinese mainland, block all other regions.

Port Blocking

Block all UDP ports if your business does not use UDP.

Fingerprint

Analyze attack traffic and configure fingerprint filtering based on attack features.