Edge Security Acceleration (ESA) routes traffic to your origin server through its points of presence (POPs), which means your origin server receives requests from ESA POP IP addresses rather than individual visitor IPs. To protect your origin, configure Cloud Firewall to allow only traffic from these POP IPs and block all other sources.
Cloud Firewall provides a cloud service address book called ESA Back-to-origin Address that contains all current ESA POP IP addresses. When POP IPs change, the address book updates automatically, eliminating manual IP whitelist maintenance.
Prerequisites
Before you begin, make sure that you have:
An access control policy configured in Cloud Firewall for your origin server
An origin server deployed on an Alibaba Cloud service
Origin server protection enabled with the latest IP list auto-applied
Add the ESA address book to a Cloud Firewall policy
Log on to the Cloud Firewall console.
In the left navigation pane, choose Prevention Configuration > Access Control > Internet Border.
On the Inbound tab, select the IP version for the policy. IPv4 is selected by default. Click Create Policy.

In the Create Inbound Policy panel, select the Create Policy tab. For Source Type, select Address Book.

Click
and select Cloud Service Address Book. 
Search for
ESA, select ESA Back-to-origin Address from the results, and click Select in the Action column.
For Destination, enter the IP address or CIDR block of your origin server, such as
1.2.3.4/32.
For Protocol Type, select the protocol your service uses. If unsure, select ANY. For Port, enter your service port. For Application, select ANY.

Set Action to Allow, Priority to Highest, and Policy Validity Period to Always. Enable Status
, then click OK. 
Verify the policy
After creating the policy, confirm that it appears on the Inbound tab with the status enabled.