Cloud Firewall integrates with ESA to automatically maintain a dynamic address book of back-to-origin IPs, eliminating manual IP whitelist management for your origin server.
Prerequisites
An Internet Border policy is configured in Cloud Firewall for your origin server.
Your origin server runs on an Alibaba Cloud service.
Origin server protection is enabled, and the Auto-enable latest back-to-origin IP list option is enabled.
How the ESA address book works
Reference the ESA address book (ESA Back-to-origin Address) in Cloud Firewall to protect your origin server. The ESA address book contains the IP addresses of ESA nodes. Add the ESA address book to an Internet Border policy, and Cloud Firewall filters traffic that does not originate from ESA nodes. When ESA back-to-origin IP addresses change, the address book updates automatically, eliminating manual maintenance of the IP whitelist for ESA nodes.
Reference the ESA address book
Log on to the Cloud Firewall console.
In the left-side navigation pane, choose .
On the Inbound tab, select an IP version (IPv4 by default), and then click Create Policy.

In the Create Inbound Policy panel, select the Create Policy tab. For Source Type, click address book.

Click the
icon and select Cloud Service Address Book.
Search for
ESA, locate ESA Back-to-origin Address in the results, and then click Select in the Actions column.
For Destination, enter your origin server IP address or CIDR block, such as
1.2.3.4/32.
Select a protocol type. If unsure, select ANY. In the Port field, enter your service port, and set Application to ANY.

Set Action to Allow, Priority to Highest, and Policy Validity Period to Always. Turn on the Status switch
, and then click OK.