After you configure a UDP port forwarding rule, Anti-DDoS Proxy blocks common ports that are exploited in UDP reflection attacks. If the blocked ports conflict with your services or you want to block additional UDP ports, you can manually adjust the list of blocked ports.
Usage notes
-
This feature is available only on Anti-DDoS Proxy instances that use the Enhanced.
-
If no port forwarding rules are configured on the Port Config page, or only TCP forwarding rules are configured, Anti-DDoS Proxy drops all UDP traffic by default. You need to configure UDP Reflection Attack Mitigation only after you add a UDP port forwarding rule.
-
UDP Reflection Attack Mitigation applies at the instance level. The filtering policy applies to all UDP port forwarding rules on the instance.
-
By default, Anti-DDoS Proxy blocks all UDP ports listed in the One-click Filtering Policies. These ports include 17, 19, 69, 111, 123, 137, 161, 389, 1194, 1900, 3389, 3702, and 11211.
Effective period
The policy takes effect immediately after configuration and remains active indefinitely.
Prerequisites
-
You have purchased an Anti-DDoS Proxy instance that uses the Enhanced. For more information, see Purchase an Anti-DDoS Proxy instance.
-
You have added a UDP port forwarding rule on the Port Config page. For more information, see Configure port forwarding rules.
Procedure
Log on to the Anti-DDoS Proxy console.
In the top navigation bar, select the region of your instance.
Anti-DDoS Proxy (Chinese Mainland): Choose the Chinese Mainland region.
Anti-DDoS Proxy (Outside Chinese Mainland): Choose the Outside Chinese Mainland region.
In the left-side navigation pane, choose .
-
On the Protection for Infrastructure tab, select the Anti-DDoS Proxy instance that you want to manage from the list on the left.
You can use the instance ID or instance description to search for the instance.
-
In the UDP Reflection Attack Mitigation section, click Settings.
-
In the Configure Filtering Policies for UDP Reflection Attacks panel, specify the UDP source ports to filter, and then click OK.
-
One-click Filtering Policies: Lists common UDP reflection attack types and the source ports they use. Anti-DDoS Proxy blocks all ports in this list by default.
-
Custom Filtering Policy: Enter other UDP source ports to filter. Valid port numbers range from 0 to 65535. You can specify up to 20 ports, separated by commas (,).
Use this option for ports not covered by the One-click Filtering Policies. You cannot add ports already included in the one-click list.
-