This topic describes how to configure and enable the Blocked Regions policy. This policy allows you to block requests to access Anti-DDoS Pro or Anti-DDoS Premium instances from IP addresses in specified regions. Anti-DDoS Pro or Anti-DDoS Premium instances that use the Enhanced function plan support this policy. After you enable this policy, requests to access Anti-DDoS Pro or Anti-DDoS Premium instances from the specified regions are dropped.
Prerequisites
Background information
The Blocked Regions policy blocks requests from specific regions in scrubbing centers. This policy drops blocked requests near the destination servers. Anti-DDoS Pro or Anti-DDoS Premium instances identify and filter requests based on the region of the source IP addresses. This policy cannot reduce the volume of attack traffic. Therefore, it is suitable for mitigating connection flood attacks.
Blocked Regions and Blocked Regions (Domain Names)
The Blocked Regions policy configured for Anti-DDoS Pro or Anti-DDoS Premium instances has a higher priority than the Blocked Regions (Domain Names) policy when both the policies are in effect.
For example, if you configure the Blocked Regions policy for an Anti-DDoS Pro or Anti-DDoS Premium instance to block requests from regions outside China, users outside China cannot access domain names associated with this instance even if the Blocked Regions (Domain Names) policy is configured to allow access from these regions. If you want to block regions outside China for some services, we recommend that you configure blocked regions for domain names rather than for Anti-DDoS Pro or Anti-DDoS Premium instances. For more information, see Configure a location blacklist for a domain name.