All Products
Search
Document Center

Anti-DDoS:Instance management

Last Updated:Jun 24, 2026

This topic describes how to manage your Anti-DDoS Proxy instances, including modifying burstable protection bandwidth, upgrading, and renewing them.

Overview

The following table describes the operations supported for Anti-DDoS Proxy (Chinese Mainland) and Anti-DDoS Proxy (Outside Chinese Mainland) instances.

Instance type

Supported operations

Description

Anti-DDoS Proxy (Chinese Mainland)

Modify burstable protection bandwidth

The burstable protection bandwidth determines the peak bandwidth of DDoS attacks that an Anti-DDoS Proxy (Chinese Mainland) instance can mitigate. For more information, see Billing for Anti-DDoS Proxy (Chinese Mainland).

Configure burstable clean bandwidth (for existing users only)

Burstable clean bandwidth is enabled by default, and there is no charge for enabling it. You are billed only when peak traffic exceeds the clean bandwidth specification. For more information, see Billing for burstable clean bandwidth.

Configure burstable QPS (for existing users only)

Burstable QPS is enabled by default, and there is no charge for enabling it. You are billed on a pay-as-you-go basis only when the peak QPS exceeds your purchased specification. For more information, see Billing for burstable QPS.

Upgrade an instance

If the specifications of your Anti-DDoS Proxy (Chinese Mainland) instance, such as the edition, number of protected domains, ports, or clean bandwidth, no longer meet your business needs, you can upgrade the instance in the Anti-DDoS Proxy console.

Renew an instance

To avoid service disruption when your Anti-DDoS Proxy (Chinese Mainland) instance expires, you can manually renew it or enable auto-renewal before its expiration date.

Purchase global advanced mitigation sessions

Supported only for Anti-DDoS Proxy (Chinese Mainland) instances that use the Advanced plan.

If the number of monthly advanced mitigations included with your Advanced plan is insufficient, you can purchase global advanced mitigation sessions. For more information, see Billing for global advanced mitigation sessions.

Manage instance tags

You can add custom tags to your Anti-DDoS Proxy (Chinese Mainland) instances to group and search for them based on purpose or attribute.

Anti-DDoS Proxy (Outside Chinese Mainland)

Configure burstable clean bandwidth (for existing users only)

Burstable clean bandwidth is enabled by default, and there is no charge for enabling it. You are billed only when peak traffic exceeds the clean bandwidth specification. For more information, see Billing for burstable clean bandwidth.

Configure burstable QPS (for existing users only)

Burstable QPS is enabled by default, and there is no charge for enabling it. You are billed on a pay-as-you-go basis only when the peak QPS exceeds your purchased specification. For more information, see Billing for burstable QPS.

Upgrade an instance

If the specifications of your Anti-DDoS Proxy (Outside Chinese Mainland) instance, such as the edition, number of protected domains, ports, or clean bandwidth, no longer meet your business needs, you can upgrade the instance in the Anti-DDoS Proxy console.

Renew an instance

To prevent service disruption after your Anti-DDoS Proxy (Outside Chinese Mainland) instance expires, you can manually renew it or enable auto-renewal before the expiration date.

Purchase global advanced mitigation sessions

This is supported only for Anti-DDoS Proxy (Outside Chinese Mainland) instances that use the Insurance, Sec-CMA, or Sec-CMA (Basic) plan.

If the number of monthly advanced mitigations included with your instance is insufficient, you can purchase global advanced mitigation sessions. For more information, see Billing for global advanced mitigation sessions.

Modify burstable protection bandwidth

An Anti-DDoS Proxy (Chinese Mainland) instance has a basic protection bandwidth and an optional burstable protection bandwidth. The burstable protection bandwidth must be greater than or equal to the basic protection bandwidth.

If burstable protection bandwidth is not configured, the basic protection bandwidth serves as the maximum mitigation limit. If configured, the burstable protection bandwidth becomes the maximum limit.

Note

You can increase the basic protection bandwidth only by upgrading the instance. The burstable protection bandwidth can be changed at any time in the Anti-DDoS Proxy console or during an upgrade.

  1. Log on to the Anti-DDoS Proxy console.

  2. In the left-side navigation pane, choose Assets > Instances.

  3. Find the instance you want to manage and, in the Instance Status column, click the edit icon image..png next to Protection Bandwidth:.

  4. In the Modify Burstable Clean Bandwidth dialog box, select a value for the burstable protection bandwidth and click OK.

    Note

    The maximum burstable protection bandwidth depends on the basic protection bandwidth of the instance. If the maximum available value does not meet your requirements, upgrade the instance to increase its basic protection bandwidth. For more information, see Instance upgrade.

Configure burstable clean bandwidth

If your service traffic fluctuates significantly or has short-term spikes, you can use burstable clean bandwidth to avoid frequent plan upgrades and downgrades.

Warning

Starting 10:00 (UTC+8) on March 6, 2026, the Monthly 95th percentile billing method is no longer available for new purchases. Manual adjustments to burstable clean bandwidth in the console — such as enabling, disabling, changing billing methods, or changing bandwidth specifications — are also no longer available. For details, see [Update] Adjustment to the Anti-DDoS Burstable Billing Feature on March 6, 2026.

  • Formula: Elastic Bandwidth Peak = min(Base Clean Bandwidth × 10, Elastic Bandwidth Upper Limit).

    Note

    The elastic peak represents the default upper limit of allocated elastic resources. When actual business usage exceeds the elastic peak, the product continues to provide service to the best of its ability, and you will incur elastic pay-as-you-go charges based on actual usage. However, packet loss may occur during the cluster scale-out period. We recommend that you promptly upgrade your guaranteed clean bandwidth.

  • Burstable bandwidth limit:

    • Anti-DDoS Proxy (Chinese Mainland): Profession (20,000 Mbps), Advanced (20,000 Mbps)

    • Anti-DDoS Proxy (Outside Chinese Mainland):Insurance(5,000 Mbps), Unlimited (5,000 Mbps), Sec-CMA 2.0 (2,000 Mbps), Chinese Mainland Acceleration (1,000 Mbps), Sec-CMA 1.0 (500 Mbps)

Procedure

  1. Log on to the Anti-DDoS Proxy console.

  2. In the top navigation bar, select the region of your instance.

    • Anti-DDoS Proxy (Chinese Mainland): Choose the Chinese Mainland region.

    • Anti-DDoS Proxy (Outside Chinese Mainland): Choose the Outside Chinese Mainland region.

  3. In the left-side navigation pane, choose Assets > Instances.

  4. Find the instance you want to manage and, in the Instance Specification column, click the edit icon 铅笔图标 next to Burstable Clean Bandwidth.

  5. In the Burstable Clean Bandwidth dialog box, configure the parameters and click OK.

    Actions

    Procedure

    Enable burstable clean bandwidth

    Turn on the Enable Burstable Clean Bandwidth switch, and set the Metering Method and Burstable Clean Bandwidth.

    Modify burstable clean bandwidth

    • Modify the Metering Method

      After the modification is complete, the Metering Method displays the mode that you selected, along with the message (The metering method is changed and the new metering method takes effect next month.). The modified metering method takes effect at 00:00 on the first day of the next month. You can modify the metering method up to three times per calendar month. The mode that takes effect in the next month is based on your last modification. You cannot switch the metering method on the last day of each calendar month.

    • Modify the Burstable Clean Bandwidth.

    Disable burstable clean bandwidth

    Turn off the Enable Burstable Clean Bandwidth switch. You can disable burstable clean bandwidth only once per month.

Configure burstable QPS

If your service QPS fluctuates frequently or has short-term spikes, you can use burstable QPS to avoid frequent plan upgrades and downgrades.

Warning

Starting from 10:00:00 UTC+8 on March 6, 2026, new customers can no longer enable the monthly 95th percentile billing mode for burstable QPS. You also cannot manually adjust burstable QPS settings in the console, including enabling or disabling the feature, changing the billing mode, or modifying the specification. For more information, see [Update] Announcement on changes to the burstable billing feature for Anti-DDoS on March 6, 2026.

  • Formula: Burstable QPS peak = min(Clean QPS × 3, Burstable QPS limit).

    Note

    The elastic peak is the upper limit for the elastic resources allocated by default. If your actual usage exceeds the elastic peak, the service is provided on a best-effort basis and you are charged for the elastic resources that you use on a pay-as-you-go basis. However, there is a risk of throttling. To ensure resource reservation beyond the burstable peak, upgrade the clean QPS in advance or contact your account manager for capacity expansion.

  • Burstable QPS limit:

    • The Chinese mainland:

      • IPv4 Anti-DDoS Proxy instance: maximum burstable QPS is 300,000.

      • IPv6 Anti-DDoS Proxy instance: maximum burstable QPS is 100,000.

    • Outside the Chinese mainland: maximum burstable QPS is 150,000.

QPS specifications and corresponding connection limits

Each QPS tier has corresponding connection limits. If burstable QPS is enabled, the burstable tier's limits apply.

QPS

New connections

Concurrent connections

0 < QPS ≤ 5,000

5,000

100,000

5,000 < QPS ≤ 10,000

10,000

200,000

10,000 < QPS ≤ 30,000

30,000

500,000

30,000 < QPS ≤ 50,000

50,000

1,000,000

50,000 < QPS ≤ 100,000

80,000

1,500,000

100,000 < QPS ≤ 150,000

100,000

2,000,000

150,000 < QPS ≤ 200,000

Note

Supported only by Anti-DDoS Proxy (Chinese Mainland).

150,000

3,000,000

200,000 < QPS ≤ 300,000

Note

Supported only by Anti-DDoS Proxy (Chinese Mainland).

200,000

4,000,000

Procedure

  1. Log on to the Anti-DDoS Proxy console.

  2. In the top navigation bar, select the region of your instance.

    • Anti-DDoS Proxy (Chinese Mainland): Choose the Chinese Mainland region.

    • Anti-DDoS Proxy (Outside Chinese Mainland): Choose the Outside Chinese Mainland region.

  3. In the left-side navigation pane, choose Assets > Instances.

  4. Find the instance that you want to manage. In the Instance Specification column, click the edit icon 铅笔图标 next to Burstable QPS.

  5. In the Burstable QPS dialog box, configure the parameters and click OK.

    Actions

    Procedure

    Enable burstable QPS

    Turn on the Enable Burstable QPS switch and set the Metering Method. The Burstable QPS Specifications parameter is not configurable.

    Modify burstable QPS

    You can only modify the Metering Method.

    After you make a change, the new metering method is selected and a message appears: (The metering method is changed and the new metering method takes effect next month.). The new metering method takes effect at 00:00 on the first day of the next month. You cannot switch the metering method on the last day of a calendar month.

    Disable burstable QPS

    Turn off the Enable Burstable QPS switch. You can disable burstable QPS only once per month.

Instance upgrade

Upgrading an Anti-DDoS Proxy instance increases its specifications. You must pay the price difference for the remaining subscription period.

Important

Anti-DDoS Proxy instances can only be upgraded. Downgrading an instance to a lower specification, including reverting to its original plan, is not supported.

Procedure

  1. Log on to the Anti-DDoS Proxy console.

  2. In the top navigation bar, select the region of your instance.

    • Anti-DDoS Proxy (Chinese Mainland): Choose the Chinese Mainland region.

    • Anti-DDoS Proxy (Outside Chinese Mainland): Choose the Outside Chinese Mainland region.

  3. In the left-side navigation pane, choose Assets > Instances.

  4. Find the instance that you want to upgrade and click Upgrade in the Actions column.

  5. On the Upgrade page, select the new instance specifications as needed, read and agree to the Terms of Service, and then click Buy Now to complete the payment.

Instance renewal

You can manually renew your Anti-DDoS Proxy instance to prevent it from being released. To avoid service interruptions from a forgotten renewal, you can also enable auto-renewal, which allows Alibaba Cloud to automatically renew the instance before it expires.

Manual renewal

You can manually renew an Anti-DDoS Proxy instance at any time before it is released. Manual renewal is not supported for instances that have already been released.

We recommend renewing your instance within the following time frames:

  • For an Anti-DDoS Proxy (Chinese Mainland) instance, renew no later than 7 calendar days after the expiration date to avoid affecting traffic forwarding.

  • For an Anti-DDoS Proxy (Outside Chinese Mainland) instance, renew no later than 30 calendar days after the expiration date to avoid affecting traffic forwarding.

  1. Log on to the Anti-DDoS Proxy console.

  2. In the top navigation bar, select the region of your instance.

    • Anti-DDoS Proxy (Chinese Mainland): Choose the Chinese Mainland region.

    • Anti-DDoS Proxy (Outside Chinese Mainland): Choose the Outside Chinese Mainland region.

  3. In the left-side navigation pane, choose Assets > Instances.

  4. Find the instance that you want to renew and click Renew in the Actions column.

  5. On the Renew page, set the Subscription duration. Read and select the Terms of Service, and then click Buy Now to complete the payment.

Enable auto-renewal

You can enable auto-renewal for your Anti-DDoS Proxy instance, but you must do so at least two calendar days before it expires. If the instance expires the next day, you must renew it manually.

  1. Log on to the Anti-DDoS Proxy console.

  2. In the top navigation bar, choose Expenses > Renewal Management.

  3. On the Manual tab, find the desired Anti-DDoS Proxy instance and click Enable Auto Renewal in the Actions column.

  4. In the Enable Auto Renewal dialog box, select a Unified Auto Renewal Cycle and click Enable Auto Renewal.

After you enable auto-renewal, you can view the renewal settings on the Auto tab. Alibaba Cloud will deduct the required fee from your account 9 calendar days before the instance expires. If you no longer need auto-renewal, you can disable it for the instance on the Auto tab.

Purchase global advanced mitigation sessions

Once purchased, global advanced mitigation sessions are automatically used to defend against DDoS attacks that exceed your instance's monthly limit, which prevents service disruptions.

  • To purchase global advanced mitigation sessions for the Advanced plan, log on to the Anti-DDoS Proxy (Chinese Mainland) console.

  • To purchase global advanced mitigation sessions for the Insurance plan or Sec-CMA plan, log on to the Anti-DDoS Proxy (Outside Chinese Mainland) console.

The following steps describe how to purchase global advanced mitigation sessions for an Anti-DDoS Proxy (Outside Chinese Mainland) instance with an Insurance plan or Sec-CMA plan.

  1. Log on to the Anti-DDoS Proxy console.

  2. In the top navigation bar, select the region of your instance.

    • Anti-DDoS Proxy (Chinese Mainland): Choose the Chinese Mainland region.

    • Anti-DDoS Proxy (Outside Chinese Mainland): Choose the Outside Chinese Mainland region.

  3. In the left-side navigation pane, choose Assets > Instances.

  4. In the upper-right corner of the Instances page, click Purchase.

  5. On the Global Advanced Mitigation (Anti-DDoS Pro and Anti-DDoS Premium) purchase page, set Applicable Service to Anti-DDoS Proxy (Outside Chinese Mainland) Insurance or Anti-DDoS Proxy (Outside Chinese Mainland) Sec-CMA, and select the desired number of Quantity.

  6. Click Buy Now and complete the payment.

  7. Verify the purchase: After the purchase is complete, you can confirm it in one of the following ways:

    • In the upper-right corner of the instance list, view the number of available mitigation sessions for your Insurance and Sec-CMA plans.

    • Click Details to view detailed information about the global advanced mitigation sessions, such as activation time, expiration time, and usage.

Instance tag management

A tag is a key-value pair that you can add to an instance. Tags help you categorize and search for instances.

  1. Log on to the Anti-DDoS Proxy console.

  2. In the left-side navigation pane, choose Assets > Instances.

  3. On the Instances page, you can perform the following operations.

    Actions

    Procedure

    Add a tag to an instance

    1. On the Instances page, find the target instance and click the edit icon 编辑标签 in the Tag column.

    2. In the Edit Tag dialog box, add or edit tags for the instance and click OK. You can use either of the following methods:

      • Select Tag: Select a tag key and tag value from the list of existing tags.

      • Add Tag: Set a new Tag Key and Tag Value, and click OK.

    Note

    An instance can have a maximum of 20 tags. For a single instance, each tag key must be unique. If you add a tag with an existing key, the new value overwrites the old one.

    Search for an instance by tag

    On the Instances page, select a tag key and tag value from the filter box.

    Remove a tag

    You can only remove tags from one instance at a time; batch removal is not supported.

    1. On the Instances page, find the target instance and click the edit icon 编辑标签 in the Tag column.

    2. In the Edit Tag dialog box, click the remove icon 删除 next to the tag that you want to remove, and then click OK.

    Note

    When a tag is removed from an instance, the system automatically deletes the tag if it is no longer associated with any other resources.

References