Port mitigation policies protect Anti-DDoS (Enhanced) EIPs against TCP connection resource exhaustion attacks and application-layer flood attacks through fine-grained traffic feature monitoring and filtering.
What is a port mitigation policy
-
Definition and use: Port mitigation policies defend non-website services against TCP connection exhaustion attacks. You configure application-layer feature detection rules to identify and filter malicious traffic, protecting backend non-web applications such as game servers, databases, or custom TCP services. Use port mitigation policies when an IP mitigation policy cannot provide fine-grained session-level feature matching and filtering for traffic to specific ports.
-
Core capability: Session Feature Filtering. Accurately identifies normal and attack traffic based on session packet payload characteristics, and supports matching strategies based on application-layer protocols.
-
Comparison with IP mitigation policies:
-
Applicable products: IP mitigation policies apply to both Standard and Enhanced products. Port mitigation policies apply only to Enhanced products.
-
Protection granularity: IP mitigation policies operate at the IP level for broader coverage. Port mitigation policies operate at the port level for finer-grained control.
-
Priority: IP mitigation policy > Port mitigation policy.
-
Usage notes
-
You can attach only one port mitigation policy to each port.
-
This feature is in public preview. The usage policies during the preview period and the billing methods after official commercial release are subject to official announcements. To enable this feature, contact your account manager.
Prerequisites
You have configured ports of an Enhanced Anti-DDoS instance as protected objects. For more information, see Configure protected objects.
Procedure
-
Go to the Mitigation Settings page of the Traffic Security console.
-
Click Create Policy. Enter a Policy Name. Set Policy Type to Port-specific Mitigation Policy, and then click OK.
-
In the The policy is created. dialog box, click OK. You are redirected to the Create Rule page.
-
On the Create Rule page, click Create Rule. Configure mitigation rules for the policy template, and then click Next.
ImportantYou can add up to 10 mitigation rules per policy template. Each rule supports up to 10 match conditions.
-
Rule Name: Enter a custom name for the rule.
-
Match Conditions: Click Add Condition to configure match conditions for the policy.
-
Rule Type: Select String or Hexadecimal.
-
Match Range: Valid values for the start position and end position: 0 to 1499. The start position must be less than or equal to the end position..
-
Logical Operator: Only Yes and No are supported.
-
Term to Match:
-
If Rule Type is set to String: The match content can be up to 1,500 characters long. The value of (End Position − Start Position + 1) must be greater than or equal to the length of the match content.
-
If Rule Type is set to Hexadecimal: The match content must consist of hexadecimal characters. The string can be up to 3,000 characters long and must contain an even number of characters. The value of (End Position − Start Position + 1) must be greater than or equal to (Length of Match Content ÷ 2).
-
-
-
Action:
-
Monitor: Records hits but does not block requests.
-
Block: Drops the current request.
-
-
-
In the Protected Assets list, in the Objects to Select area, select a Protected Instance.
-
After you select the Asset IP Address to protect, select the specific ports to protect under the Port/Protocol area.
-
Review the settings, and then click Add.
Modify a port mitigation policy template
-
On the Mitigation Settings page, select Port-specific Mitigation Policy from the drop-down list. Find the target policy and click Modify Mitigation Policy in the Actions column.
-
On the Modify Mitigation Policy page, you can perform the following operations:
-
Create Rule: Click Create Rule above the list, configure the rule settings as described in the creation procedure, and then click OK.
-
Edit: Click Edit in the Actions column of the target rule, modify the rule settings as described in the creation procedure, and then click OK.
-
Delete: Click Delete in the Actions column of the target rule. In the confirmation dialog box, confirm the information, and then click Delete.
-
After you modify a policy template, the protected objects associated with it will use the modified policy. Proceed with caution.
Manage protected objects
-
On the Mitigation Settings page, select Port-specific Mitigation Policy from the drop-down list. Find the target policy and click Add Object for Protection in the Actions column.
-
On the View Applicable Object, you can perform the following operations:
-
Add Object for Protection:
-
Click Add Object for Protection above the list. In the Objects to Select area, select a mitigation instance.
-
In the IP list, select the IP address to protect. In the Port/Protocol area, select the ports to protect.
NoteA maximum of 50 protection objects can be selected.
-
Click Add.
-
-
Delete: Click Delete in the Actions column of the target object. In the confirmation dialog box, confirm the information, and then click OK.
-
Delete a port mitigation policy template
On the Mitigation Settings page, select Port-specific Mitigation Policy from the drop-down list. Find the target policy and click Delete in the Actions column.
You cannot delete a policy template that is associated with protected objects. To delete the template, first remove its association with the protected objects.