EIP supports Internet access over IPv4 connections. It is also integrated with Anti-DDoS services to enhance network security for resources.
Internet access control by using IPv4 gateways
IPv4 gateways can connect virtual private clouds (VPCs) to the Internet. An IPv4 gateway can enable a VPC to access the Internet by routing IPv4 traffic and translating private IP addresses to public IP addresses. When a VPC accesses the Internet by using an IPv4 gateway, IPv4 traffic flows through the IPv4 gateway.
Internet access control
If resources in a VPC are assigned an EIP, the sources can access the Internet regardless of route table configurations. To minimize security risks caused by direct Internet access, you can use IPv4 gateways and subnet routing to regulate access from VPCs to the Internet by granting or revoking Internet access permissions for subnets.
Routing policies for inbound traffic
You can use the subnet routing feature together with an IPv4 gateway to route inbound traffic to a virtual firewall, such as Cloud Firewall. This protects your Elastic Compute Service (ECS) instances against malicious requests.
DDoS mitigation
DDoS attacks are cyberattacks against targeted systems to make services unavailable to users. Alibaba Cloud Anti-DDoS Origin Basic provides up to 5 Gbps of bandwidth that is free of charge for DDoS mitigation. If your service requires a higher mitigation capacity, you can purchase Anti-DDoS (Enhanced) EIP.
Anti-DDoS Basic
By default, EIPs include Anti-DDoS Basic, which provides up to 5 Gbps of DDoS protection. Inbound internet traffic first passes through Alibaba Cloud Anti-DDoS Basic. When Anti-DDoS Basic detects traffic that matches a DDoS attack profile and exceeds the scrubbing threshold, Anti-DDoS Basic starts scrubbing, filters malicious packets, and forwards clean traffic to the EIP.
-
Scrubbing:
-
Scrubbing methods: filter attack packets, rate-limit traffic, and rate-limit packets.
-
Scrubbing trigger: Scrubbing begins when traffic matches the characteristics of a DDoS attack and its volume reaches the bits per second (BPS) or packets per second (PPS) scrubbing threshold. Anti-DDoS Basic automatically sets scrubbing thresholds based on the EIP's bandwidth.
-
BPS scrubbing threshold: If the EIP bandwidth is ≤ 300 Mbps, the threshold is 450 Mbps. If the EIP bandwidth is > 300 Mbps, the threshold is
EIP bandwidth value × 1.5Mbps. -
PPS scrubbing threshold: 100,000 pps for EIP bandwidths up to 100 Mbps. For bandwidths over 100 Mbps, the threshold is
EIP bandwidth value × 1000pps.
-
-
-
Blackhole routing: When DDoS attack traffic exceeds the EIP's blackhole threshold (the 5 Gbps capacity of Anti-DDoS Basic, specifically 5,200 Mbps), Alibaba Cloud applies blackhole routing to protect the cloud resource from further impact. This policy blocks all inbound traffic to the EIP, which can cause a complete service interruption. By default, the blackhole is automatically lifted after 2.5 hours. The actual duration may vary depending on the frequency of attacks on the EIP.
Anti-DDoS (Enhanced)
Alibaba Cloud provides EIPs protected by Anti-DDoS (Enhanced), which can mitigate DDoS attacks at the Tbps level.
You do not need to perform additional configurations for Anti-DDoS (Enhanced) or change your service IP addresses when you use EIPs protected by Anti-DDoS (Enhanced). EIPs protected by Anti-DDoS (Enhanced) are ideal for scenarios that require high security and low latency, such as large-scale gaming and important livestreaming activities.