All Products
Search
Document Center

Edge Security Acceleration:Automated origin server protection

Last Updated:Jun 17, 2026

Cloud Firewall integrates with ESA to automatically maintain a dynamic address book of back-to-origin IPs, eliminating manual IP whitelist management for your origin server.

Prerequisites

  • An Internet Border policy is configured in Cloud Firewall for your origin server.

  • Your origin server runs on an Alibaba Cloud service.

  • Origin server protection is enabled, and the Auto-enable latest back-to-origin IP list option is enabled.

How the ESA address book works

Reference the ESA address book (ESA Back-to-origin Address) in Cloud Firewall to protect your origin server. The ESA address book contains the IP addresses of ESA nodes. Add the ESA address book to an Internet Border policy, and Cloud Firewall filters traffic that does not originate from ESA nodes. When ESA back-to-origin IP addresses change, the address book updates automatically, eliminating manual maintenance of the IP whitelist for ESA nodes.

image

Reference the ESA address book

  1. Log on to the Cloud Firewall console.

  2. In the left-side navigation pane, choose Prevention Configuration > Access Control > Policy Configuration > Internet Border.

  3. On the Inbound tab, select an IP version (IPv4 by default), and then click Create Policy.image

  4. In the Create Inbound Policy panel, select the Create Policy tab. For Source Type, click address book.

    image

    1. Click the image icon and select Cloud Service Address Book.

      image

    2. Search for ESA, locate ESA Back-to-origin Address in the results, and then click Select in the Actions column.

      image

    3. For Destination, enter your origin server IP address or CIDR block, such as 1.2.3.4/32.

      image

    4. Select a protocol type. If unsure, select ANY. In the Port field, enter your service port, and set Application to ANY.

      image

    5. Set Action to Allow, Priority to Highest, and Policy Validity Period to Always. Turn on the Status switch image, and then click OK.

      image

Related topics