All Products
Search
Document Center

Anti-DDoS:Configure custom mitigation policies

Last Updated:Jun 08, 2026

Anti-DDoS Native protects your public IP assets with a default mitigation policy. You can create custom policies to allow or deny traffic with specific characteristics, and refine them based on attack traffic patterns observed in mitigation logs or Attack Analysis.

Mitigation policy types

Anti-DDoS Native supports IP-specific and port-specific mitigation policies. When both are configured, IP-specific policies take priority.

Policy type

Applicable asset

Description

IP-specific mitigation policy

  • Assets of regular Alibaba Cloud services

    Note

    Web Application Firewall (WAF) assets do not support IP-specific mitigation policies.

  • Elastic IP addresses (EIPs) with Anti-DDoS (Enhanced) enabled

Mitigates volumetric DDoS attacks at the network and transport layers. Traffic matching a policy rule is processed based on the specified action.

Port-specific mitigation policy

EIPs with Anti-DDoS (Enhanced) enabled

Mitigates TCP flood attacks (application-layer flood attacks on non-website services) by allowing or discarding traffic with specific characteristics. Enables fine-grained application-layer traffic filtering.

Supported regions for mitigation policies

Mitigation policies are free but supported only in certain regions with limited functionality. If policies cannot meet your requirements, Contact us.

In the following table, √ indicates supported and × indicates not supported.

Asset type

Region

IP-specific mitigation policy

Port-specific mitigation policy

Asset of a regular Alibaba Cloud service

Chinese mainland

×

Regions outside the Chinese mainland

Supported regions: China (Hong Kong), US (Virginia), US (Silicon Valley), Germany (Frankfurt), UK (London), Japan (Tokyo), Singapore, Indonesia (Jakarta), and Malaysia (Kuala Lumpur)

×

EIP with Anti-DDoS (Enhanced) enabled

Chinese mainland

Supported only in the China (Hangzhou) region

Regions outside the Chinese mainland

Supported regions: China (Hong Kong), US (Virginia), US (Silicon Valley), Germany (Frankfurt), UK (London), Japan (Tokyo), Singapore, Indonesia (Jakarta), and Malaysia (Kuala Lumpur)

×

Asset that is added to an anti-DDoS diversion instance

Regions outside the Chinese mainland

×

×

References