You can manually deactivate blackhole filtering for an asset that is protected by an Anti-DDoS Origin paid edition and assigned a public IP address. This topic describes how to manually deactivate blackhole filtering.
Quota on deactivating blackhole filtering
If you use Anti-DDoS Origin Basic that is provided free of charge, the basic DDoS mitigation capability is used. After blackhole filtering is triggered, you cannot manually deactivate it. You can only wait for the blackhole filtering to be automatically deactivated.
Blackhole filtering can be automatically or manually deactivated.
Automatic: You can view the wait time for automatic deactivation of blackhole filtering on the Assets page of the Traffic Security console. If the time is acceptable, wait for blackhole filtering to deactivate automatically.
Manual: To deactivate blackhole filtering at the earliest opportunity, manually deactivate blackhole filtering.
The following table describes the deactivation methods that are supported by different editions.
The quota for manually deactivating blackhole filtering resets each month, regardless of whether you buy or renew an instance, as long as the instance is active.
For example, with the Anti-DDoS Origin 2.0 (Subscription) Inclusive Edition for Small and Medium Enterprises (SMEs), you have five deactivations per month. If you use all five by May 10 and renew on May 11, you still have 0 remaining for May.
Unused quota is cleared at the month's end.
Edition | Deactivation method | Quota on manual deactivation |
Anti-DDoS Origin Basic | Automatic | None |
Anti-DDoS Origin 1.0 (Subscription) Enterprise Edition |
| For each instance, the quota for deactivating blackhole filtering equals the number of IP Addresses purchased. If you increase the IP Addresses, the quota also increases, but it cannot exceed 200 per month. For example, if your Anti-DDoS Origin 2.0 (Subscription) Enterprise Edition instance can protect 50 IP Addresses, you have a quota of 50 deactivations per month. |
Anti-DDoS Origin 2.0 (Subscription) Enterprise Edition |
| |
Anti-DDoS Origin 2.0 (Subscription) Inclusive Edition for SMEs |
| 5 deactivations each instance per month |
Anti-DDoS Origin 2.0 (Pay-as-you-go) |
| 200 deactivations each instance per month |
Usage notes
If you manually deactivate blackhole filtering for the same asset, the interval between two deactivation operations must be at least 40 minutes.
If you manually deactivate blackhole filtering for an asset and another blackhole filtering is triggered for the asset, the asset continues to receive DDoS attacks. In this case, the interval between two deactivation operations must be at least 40 minutes.
If blackhole filtering is frequently triggered for your asset, the volume of the attacks exceeds the protection capability of your Anti-DDoS Origin instance. In this case, we recommend that you purchase an Anti-DDoS Pro or Anti-DDoS Premium instance to provide up to Tbit/s of protection.
Procedure
Log on to the Traffic Security console.
In the left-side navigation pane, choose .
In the top navigation bar, select the resource group to which the instances belong and the region in which the instances reside.
Anti-DDoS Origin 1.0 (Subscription) instances: Select the region in which the instance resides.
Anti-DDoS Origin 2.0 (Subscription) and Anti-DDoS Origin 2.0 (Pay-as-you-go) instances: Select All Regions.
On the Protected Objects page, find the instance that is in the Under blackhole state and click Deactivate Blackhole Filtering in the Actions column.
In the Deactivate Blackhole Filtering dialog box, view the remaining times that you can deactivate blackhole filtering for and click Confirm.
NoteBlackhole filtering is a risk management policy used by the backend servers of Alibaba Cloud. If your request to deactivate blackhole filtering fails, the quota on deactivating blackhole filtering for the day is not deducted.
Result
If blackhole filtering is deactivated, the value in the Status column of the protected IP address is changed from Under blackhole to Normal. If you fail to deactivate blackhole filtering, an error message appears. We recommend that you wait one minute and try again.