All Products
Search
Document Center

Anti-DDoS:Anti-DDoS plans

Last Updated:Nov 28, 2025

Anti-DDoS Pro and Anti-DDoS Premium (the Chinese mainland) provide free Anti-DDoS plans to eligible users. You can use these plans to offset pay-as-you-go burstable protection fees. This topic describes how to obtain and use Anti-DDoS plans.

Obtain an Anti-DDoS plan

You automatically receive an Anti-DDoS plan if you meet one of the following requirements:

  • You activate Anti-DDoS Pro or Anti-DDoS Premium (the Chinese mainland) for the first time.

  • You purchase or renew a subscription Anti-DDoS Pro or Anti-DDoS Premium (the Chinese mainland) instance.

Note

Anti-DDoS Pro and Anti-DDoS Premium (outside the Chinese mainland) does not support Anti-DDoS plans. For more information, contact your account manager.

Conditions for using an Anti-DDoS plan

Anti-DDoS plans can be used only to offset pay-as-you-go burstable protection fees.

  • If the inbound traffic is less than or equal to the basic protection bandwidth, no burstable protection fees are generated and your Anti-DDoS plan is not used.

  • If the inbound traffic is less than or equal to the sum of the basic protection bandwidth and the protection bandwidth of your Anti-DDoS plan, the plan can offset the burstable protection fees for that day.

  • If the inbound traffic is greater than the sum of the basic protection bandwidth and the protection bandwidth of your Anti-DDoS plan, the plan cannot be used to offset the fees.

Important
  • If burstable protection fees are generated but your Anti-DDoS plan cannot be used to offset them, your Anti-DDoS Pro or Anti-DDoS Premium instance is billed for the fees as usual.

  • If you experience multiple DDoS attacks in a day and the peak inbound traffic meets the conditions for using the plan, only one mitigation session is used to offset the burstable protection fees for that day.

Usage notes

  • Anti-DDoS plans do not increase your mitigation capabilities. They only offset the daily burstable protection fees for your Anti-DDoS Pro or Anti-DDoS Premium instance when the conditions are met. Your mitigation capability depends on your basic protection bandwidth and burstable protection bandwidth.

  • When all mitigation sessions of your Anti-DDoS plan are used, you can adjust the burstable protection bandwidth to be equal to the basic protection bandwidth to avoid unexpected burstable protection fees.

    Note

    If inbound traffic exceeds the basic protection bandwidth, blackhole filtering may be triggered and affect your services.

  • An Anti-DDoS plan can only offset burstable protection fees that are generated on or after the day you obtain the plan. The plan cannot be used for fees for which a bill has already been generated.

Recommendations for adjusting burstable protection bandwidth

You can manually adjust the burstable protection bandwidth to make effective use of your Anti-DDoS plan. You can set the burstable protection bandwidth to a maximum value equal to the basic protection bandwidth plus the Anti-DDoS plan specification. However, this setting is limited by the maximum configurable burstable protection bandwidth. For more information, see Modify the burstable protection bandwidth.

For example, assume that the basic protection bandwidth is 30 Gbps:

  • If the protection specification of your Anti-DDoS plan is 20 Gbps, you can set the burstable protection bandwidth to 50 Gbps (30 Gbps basic protection bandwidth + 20 Gbps Anti-DDoS plan specification).

  • If the protection specification of your Anti-DDoS plan is 300 Gbps, the sum of the basic protection bandwidth (30 Gbps) and the plan's protection specification (300 Gbps) is 330 Gbps. This value exceeds the maximum configurable burstable protection bandwidth of 300 Gbps. In this case, you must set the burstable protection bandwidth to 300 Gbps.

Actual elastic bandwidth

View Anti-DDoS plan details

An Anti-DDoS plan is automatically applied when the conditions for fee deduction are met. You can view the details and usage records of your Anti-DDoS plans in the Anti-DDoS Pro console. An Anti-DDoS plan is valid and can be used only if it has not expired and has one or more available mitigation sessions.

  1. Log on to the Anti-DDoS Proxy console.

  2. In the top navigation bar, select the Chinese Mainland region.

  3. In the left-side navigation pane, choose Assets > Anti-DDoS Plans.

  4. On the Anti-DDoS Plans page, you can view the details of your Anti-DDoS plans.

    Anti-DDoS plan_cn

    Item

    Description

    Specification

    The protection specification of the Anti-DDoS plan.

    In the figure, the protection specification is 100 Gbps. Assume your basic protection bandwidth is 30 Gbps:

    • If the inbound traffic is less than or equal to 130 Gbps (30 Gbps basic protection bandwidth + 100 Gbps Anti-DDoS plan specification), the plan can offset the pay-as-you-go fees for the day.

    • If the inbound traffic on that day is greater than 130 Gbps, the plan fails to offset the fees. In this case, if the conditions for generating pay-as-you-go burstable protection fees are met, you are billed for the fees as usual.

    Expiration Time

    The expiration date of the Anti-DDoS plan.

    Status

    The status of the Anti-DDoS plan.

    • Valid: The plan can be used.

    • Exhausted: The available mitigation sessions are used up.

    • Expired: The plan has expired and cannot be used.

    Available Protection

    The number of available mitigation sessions for the plan.

  5. (Optional) In the Actions column, click View Logs. You are redirected to the Operation Logs page to view the operation records of the Anti-DDoS plan. For more information, see Operation logs.

References

For more information about burstable protection bandwidth, see Billing of burstable protection bandwidth.