After an ECS instance enters blackhole filtering, Alibaba Cloud discards all inbound traffic (making the public IP address inaccessible from the Internet) and blocks outbound traffic, preventing the instance from connecting to external networks (for example, API calls to WeChat or third-party services time out). This is expected behavior of the blackhole filtering mechanism and does not indicate a server-side fault. You can estimate the time when blackhole filtering is automatically deactivated and wait for it to expire. After blackhole filtering is automatically deactivated, the public IP address is automatically restored for both inbound and outbound traffic. You do not need to manually restart services or the instance. In urgent scenarios, you can change the public IP address of the ECS instance or migrate your workloads to another ECS instance to quickly restore your workloads. This topic describes how to quickly restore workloads of an ECS instance on which blackhole filtering is triggered.
After you change the public IP address of the ECS instance or migrate your workloads to another ECS instance, attackers can still obtain the new public IP address by pinging the domain name and re-launch attacks. To resolve the issue, purchase an Anti-DDoS Native or Anti-DDoS Proxy instance.
Estimated time for automatic blackhole release
If you have not purchased Anti-DDoS Native or Anti-DDoS Proxy, you must wait for blackhole filtering to be automatically deactivated. If you have purchased Anti-DDoS Native or Anti-DDoS Proxy, you can manually deactivate blackhole filtering for the ECS instance after you add your workloads to the instance for protection. For more information, see Deactivate blackhole filtering (Anti-DDoS Native) and Deactivate blackhole filtering (Anti-DDoS Proxy).
View the most recent time when the ECS instance was attacked.
Log on to the Traffic Security console. On the Event Center page, find the public IP address of the ECS instance and click Details to view the most recent time when the ECS instance was attacked.
NoteIf an asset receives multiple DDoS attacks, the duration of blackhole filtering is calculated after the last DDoS attack stops.
View the duration of blackhole filtering.
On the Assets page, view the duration of blackhole filtering. The duration indicates the total duration of blackhole filtering. The default duration is 2.5 hours. The actual duration varies based on the frequency of attacks on your asset, ranging from 30 minutes to 24 hours. In rare cases, the duration may be longer.
Estimate the time when blackhole filtering is automatically deactivated.
For example, the ECS instance was attacked at 12:30 and the duration of blackhole filtering is 150 minutes. In this case, blackhole filtering is expected to be deactivated at 15:00.
NoteThe estimated time is provided for reference only. If the ECS instance receives continuous DDoS attacks, the duration of blackhole filtering may be extended.
You can wait for blackhole filtering to be automatically deactivated. In urgent scenarios, you can use one of the following solutions to quickly restore your workloads.
After you change the public IP address of the ECS instance or migrate your workloads to another ECS instance, you must modify settings such as the DNS record and database connection based on your actual business requirements.
Solution 1: change the public IP address of the ECS instance
If you frequently change the public IP address of the ECS instance on which blackhole filtering is triggered, continuous attack traffic may cause risks to the cloud platform. In this case, your Alibaba Cloud account may be restricted and you cannot perform operations such as purchasing new instances.
Change the elastic IP address (EIP) of the ECS instance
-
(Optional) Apply for a new EIP.
For more information, see Apply for an EIP.
-
Disassociate the current EIP from the ECS instance.
For more information, see Disassociate an EIP from a cloud resource.
Important-
After you disassociate a pay-as-you-go EIP from a cloud resource, you are still charged an EIP configuration fee. To avoid unnecessary fees, release the EIP.
-
For information about EIP configuration fees, see Pay-as-you-go.
-
For information about how to release a pay-as-you-go EIP, see Release a pay-as-you-go EIP.
-
-
If you no longer require a subscription EIP after you disassociate the EIP from a cloud resource, you can unsubscribe from the EIP. For more information, see Rules for unsubscribing from resources.
-
-
Associate the new EIP with the ECS instance.
For more information, see Associate an EIP with an ECS instance.
Change the system-assigned public IP address of the ECS instance
Within 6 hours of instance creation
You can Change Public IP Address in the ECS console within 6 hours after the instance is created.
Prerequisites
-
The ECS instance is in the Stopped (
Stopped) state.NoteIf the ECS instance is a pay-as-you-go instance that is deployed in a VPC, you must stop the instance in standard mode. If you stop the instance in economical mode, you may be unable to change the static public IP address of the instance. For more information, see Economical mode.
-
You can change the static public IP address of an ECS instance up to three times within 6 hours after the instance is created.
NoteTo change the static public IP address of an ECS instance for the fourth time within 6 hours after the instance is created, perform the operations described in the More than 6 hours of instance creation section of this topic.
Procedure
Log in to the ECS console.
In the left-side navigation pane, choose .
In the upper-left corner of the page, select a region and resource group.
-
Find the ECS instance whose static public IP address you want to change. In the Actions column, choose .
-
In the Change Public IP Address message, confirm the information and click OK.
When the static public IP address of the instance is changed, a new static public IP address is displayed in the preceding message.
More than 6 hours of instance creation
You cannot directly change the static public IP address of an ECS instance more than 6 hours after the instance is created.
-
If the instance is not a subscription instance that uses the pay-by-bandwidth billing method for network usage, you can convert the static public IP address of the instance into an EIP.
For more information, see Convert the public IP address of an instance in a VPC to an EIP.
Important-
You cannot change the static public IP address of a subscription ECS instance within 24 hours before the instance expires.
-
For a subscription ECS instance that uses the pay-by-bandwidth billing method for network usage, you can change the billing method for network usage to Pay-by-traffic before you change the static public IP address of the instance. For information about how to change the billing method for network usage from pay-by-bandwidth to pay-by-traffic, see the Change from pay-by-bandwidth to pay-by-traffic section of the "Change the billing method for network usage of an ECS instance that uses a static public IP address" topic.
-
-
Disassociate the EIP from the ECS instance.
For more information, see Disassociate an EIP from a cloud resource.
Important-
After you disassociate a pay-as-you-go EIP from a cloud resource, you are still charged an EIP configuration fee. To prevent unnecessary fees, release the EIP.
-
For information about EIP configuration fees, see Pay-as-you-go.
-
For information about how to release a pay-as-you-go EIP, see Release a pay-as-you-go EIP.
-
-
If you no longer require a subscription EIP after you disassociate the EIP from a cloud resource, you can unsubscribe from the EIP. For more information, see Rules for unsubscribing from resources.
-
-
Change the public bandwidth of the ECS instance to a value greater than 1 Mbit/s to allow the system to assign a new public IP address to the instance.
For more information, see Modify the bandwidth configurations of subscription instances or Modify the bandwidth configurations of pay-as-you-go instances.
You can view the new static public IP address in the IP Address column on the instance list page. For more information, see the View the type of the public IP address section of this topic.
Solution 2: replacing business servers using ECS image cloning
Create a custom image for the ECS instance on which blackhole filtering is triggered. For more information, see Create custom image.
NoteWe recommend that you regularly create snapshots for your ECS instances during O&M. If you want to quickly restore your workloads, use a snapshot to create a custom image. For more information, see Create policy and Create a custom image from a snapshot.
Use the custom image to create an ECS instance that has the same configurations. For more information, see Create from custom image or shared image.
Solution 3: replacing business servers via SMC
Server Migration Center (SMC) is a server migration platform provided by Alibaba Cloud. Use SMC to migrate the ECS instance on which blackhole filtering is triggered to generate a custom image. Then, use the custom image to create another ECS instance.
Import the ECS instance on which blackhole filtering is triggered to SMC as a migration source. For more information, see Step 1: Import the information of a migration source.
Create a migration task to migrate system configurations and business data to a custom image. For more information, see Step 2: Create and start a migration task.
Use the custom image to create an ECS instance that has the same configurations. For more information, see Create from custom image or shared image.
Solution 4: logging into blackholed ECS instances to migrate business data
You cannot connect to an ECS instance on which blackhole filtering is triggered over the Internet. You can connect to the ECS instance by using Workbench, Session Manager, Virtual Network Computing (VNC), or another ECS instance that resides in the same virtual private cloud (VPC) as the ECS instance.
For more information about how to connect to an ECS instance by using Workbench, Session Manager, or VNC, see Connect to your instance. In this example, an ECS instance on which blackhole filtering is triggered is connected by using another ECS instance that resides in the same VPC as the ECS instance.
Usage notes
The two ECS instances must reside in the same region, same VPC, and belong to the same security group. The two ECS instances must be connected. For more information about security groups, see Overview.
Procedure
Log on to the ECS instance on which blackhole filtering is not triggered by using its private or public IP address.
Run a command or use a tool to connect to the ECS instance on which blackhole filtering is triggered by using its private IP address or public IP address.
The following table describes the common connection methods.
Operating system of the ECS instance on which blackhole filtering is triggered
Operating system of the ECS instance on which blackhole filtering is not triggered
Connection method
References
Windows
Windows
Use Microsoft Terminal Services Client (MSTSC).
Linux
Use rdesktop.
Linux
Windows
Use PuTTY.
Linux
Run an SSH command.
ssh root@<System-assigned public IP address or EIP of the instance>Migrate business data to the ECS instance on which blackhole filtering is not triggered.
FAQ
What do I do if blackhole filtering is triggered on my IP address and I cannot change the public IP address?
Blackhole filtering that is triggered by volumetric DDoS attacks cannot be manually deactivated. You must wait for the system to determine that the attack has stopped and then automatically deactivate blackhole filtering.
If your workloads are urgent but you cannot change the public IP address due to account restrictions or resource constraints, you must wait for blackhole filtering to be automatically deactivated. For information about how to estimate the deactivation time, see the "Estimate the time when blackhole filtering is automatically deactivated" section of this topic.
To prevent blackhole filtering from being triggered again, purchase Anti-DDoS Native (Enterprise) or Anti-DDoS Proxy based on your business requirements.
References
For more information about the Alibaba Cloud blackhole filtering policy, see Alibaba Cloud blackhole policy.
For more information about the blackhole filtering thresholds of cloud services, such as ECS, see View the thresholds that trigger blackhole filtering in Anti-DDoS Basic.
For more information about Anti-DDoS, see What is Anti-DDoS Native and What is Anti-DDoS Proxy.
> Network and Security Group > Change Public IP Address