All Products
Search
Document Center

Anti-DDoS:ConfigUdpReflect

Last Updated:Feb 25, 2026

Adds the filtering policies for UDP reflection attacks on an Anti-DDoS Pro or Anti-DDoS Premium instance to filter out the source ports of UDP traffic.

Operation description

You can call this operation to configure filtering policies to filter out UDP traffic from specific ports. This helps defend against UDP reflection attacks.

Limits

You can call this operation up to 10 times per second per account. If the number of the calls per second exceeds the limit, throttling is triggered. As a result, your business may be affected. We recommend that you take note of the limit when you call this operation.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

No authorization for this operation. If you encounter issues with this operation, contact technical support.

Request parameters

Parameter

Type

Required

Description

Example

InstanceId

string

Yes

The ID of the instance.

Note

You can call the DescribeInstanceIds operation to query the IDs of all instances.

ddoscoo-cn-i7m25564****

Config

string

Yes

The configuration of the filtering policy for UDP reflection attacks.

The value is a string that consists of a JSON struct. The JSON struct contains the following field:

  • UdpSports: the source ports of the UDP traffic that you want to block. This field is required and must be of the ARRAY type. Example: [17,19].

    We recommend that you block the following source ports of UDP traffic:

    • UDP 17: QOTD reflection attacks

    • UDP 19: CharGEN reflection attacks

    • UDP 69: TFTP reflection attacks

    • UDP 111: Portmap reflection attacks

    • UDP 123: NTP reflection attacks

    • UDP 137: NetBIOS reflection attacks

    • UDP 161: SNMPv2 reflection attacks

    • UDP 389: CLDAP reflection attacks

    • UDP 1194: OpenVPN reflection attacks

    • UDP 1900: SSDP reflection attacks

    • UDP 3389: RDP reflection attacks

    • UDP 11211: memcached reflection attacks

{\"UdpSports\":[17,19]}

RegionId

string

No

The region ID of the Anti-DDoS Proxy instance. Valid values:

  • cn-hangzhou: indicates an Anti-DDoS Proxy (Chinese Mainland) instance. This is the default value.

  • ap-southeast-1: indicates an Anti-DDoS Proxy (Outside Chinese Mainland) instance.

cn-hangzhou

All Alibaba Cloud API operations must include common request parameters. For more information about common request parameters, see Common parameters.

For more information about sample requests, see the "Examples" section of this topic.

Response elements

Element

Type

Description

Example

object

RequestId

string

The ID of the request.

9EC62E89-BD30-4FCD-9CB8-FA53865FF0D7

Examples

Success response

JSON format

{
  "RequestId": "9EC62E89-BD30-4FCD-9CB8-FA53865FF0D7"
}

Error codes

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.