Block requests from specific geographic locations for a website protected by Anti-DDoS Proxy. After you enable the Location Blacklist (Domain Names) feature and select locations, Anti-DDoS Proxy blocks all requests from IP addresses in those locations.
Use cases
Use this feature in either of the following situations:
Restrict by service region: Your website is intended for users in specific locations only. Add all other locations to the blacklist to prevent access from outside your service region.
Block attack sources: Your website is receiving DDoS attacks from a specific location. Add that location to the blacklist to stop those requests.
Both situations use the same configuration steps — the difference is which locations you select.
Usage notes
Websites only. This feature applies only to website services. For non-website services, configure traffic blocking on the Protection for Infrastructure tab instead. See Configure the near-origin traffic diversion feature and Configure the location blacklist feature. The near-origin traffic diversion feature is available for Anti-DDoS Proxy (Chinese Mainland) only.
One domain name at a time. Configure the location blacklist separately for each domain name. Bulk configuration across multiple domain names is not supported.
Filters requests, not traffic volume. This feature drops requests based on the originating IP address location. It does not reduce the volume of incoming attack traffic.
Prerequisites
Before you begin, ensure that you have:
Configure the location blacklist for a domain name
Log on to the Anti-DDoS Proxy console.
In the top navigation bar, select the region of your instance:
Anti-DDoS Proxy (Chinese Mainland): Select Chinese Mainland.
Anti-DDoS Proxy (Outside Chinese Mainland): Select Outside Chinese Mainland.
In the left-side navigation pane, choose Mitigation Settings > General Policies.
On the General Policies page, click the Protection for Website Services tab, then select a domain name from the list on the left.
In the Location Blacklist (Domain Names) section, click Settings.
In the Configure Location Blacklist panel, select the locations to block, then click OK.
Back in the Location Blacklist (Domain Names) section, turn on Status to apply the configuration.
Result
The configuration takes effect immediately on all Anti-DDoS Proxy instances associated with the domain name.