All Products
Search
Document Center

Global Accelerator:Anti-DDoS Basic

Last Updated:Apr 01, 2026

Global Accelerator automatically enables Anti-DDoS Basic, free of charge, for all accelerated IP addresses and public IP addresses of endpoint groups. This built-in protection scrubs malicious traffic before it reaches your instance, providing up to 5 Gbps of DDoS mitigation with no configuration required.

How it works

All Internet traffic passes through the DDoS protection network before reaching your Global Accelerator instance. The network monitors traffic in real time. When it detects a DDoS attack or abnormal traffic volume, it redirects suspicious traffic to a scrubbing device. The device filters out malicious packets and forwards clean traffic to your instance without interrupting normal service. This process is called traffic scrubbing.

Traffic scrubbing is triggered when either of the following conditions is met:

  • Traffic matches the signature of a known attack model.

  • Traffic volume reaches the scrubbing threshold, which is set automatically based on the IP bandwidth.

Scrubbing methods include filtering attack messages, rate-limiting traffic, and rate-limiting packets. Anti-DDoS Basic uses two threshold types:

  • BPS scrubbing threshold: Triggered when inbound traffic (bits per second) exceeds the threshold.

  • PPS scrubbing threshold: Triggered when the number of inbound packets per second exceeds the threshold.

If inbound traffic exceeds the blackhole triggering threshold, all inbound traffic is blocked to protect the cluster. For details, see Alibaba Cloud blackhole filtering policy.

The blackhole triggering threshold and maximum mitigation capacity vary by region. For region-specific thresholds, see thresholds that trigger blackhole filtering in Anti-DDoS Basic. The actual threshold for your instance depends on the region and bandwidth configuration — the value shown on the Asset page is authoritative.

Scrubbing thresholds

Anti-DDoS Basic calculates the maximum scrubbing thresholds based on the IP bandwidth of each protected address.

Maximum BPS scrubbing threshold

IP bandwidth (Mbps)Maximum BPS scrubbing threshold (Mbps)
≤300450
>300Bandwidth of the accelerated IP address × 1.5

Maximum PPS scrubbing threshold

IP bandwidth (Mbps)Maximum PPS scrubbing threshold (pps)
≤100100,000
>100Bandwidth of the accelerated IP address × 1,000

How IP bandwidth is determined

  • Accelerated IP address: The bandwidth value allocated to the acceleration area.

  • Public IP address of an endpoint group: Depends on the billing method and bandwidth metering method.

Billing methodBandwidth metering methodIP bandwidth
SubscriptionPay-by-bandwidth (bound to a basic bandwidth plan)Peak bandwidth of the basic bandwidth plan
Pay-as-you-goPay-by-data-transfer (unified settlement by CDT)1200 Mbps

Example

For a standard Global Accelerator instance where the acceleration area allocates 100 Mbps to an accelerated IP address and the associated basic bandwidth plan has a peak bandwidth of 200 Mbps:

  • Accelerated IP address: BPS threshold = 450 Mbps, PPS threshold = 100,000 pps

  • Public IP address of the endpoint group: BPS threshold = 450 Mbps, PPS threshold = 200,000 pps

View mitigation thresholds

  1. Log on to the GA console.

  2. On the Instances page, click the instance ID.

    To view thresholds for a basic Global Accelerator instance, choose Basic Instance in the left navigation pane to open the basic instance list, then click the instance ID.
  3. View the thresholds for the accelerated IP address or the public IP address of the endpoint group.

    The DDoS protection icon is color-coded: Normal, Cleaning, or Black Hole Activated. Hover over the icon to see threshold details.

View thresholds for an accelerated IP address

On the instance details page, click the Acceleration Areas tab. Locate the accelerated IP address, then hover over the DDoS protection icon in the Accelerated IP Address or Security Protection column. The tooltip shows the BPS scrubbing threshold, PPS scrubbing threshold, and blackhole triggering threshold.

View thresholds for a public IP address of an endpoint group

This applies to standard Global Accelerator instances only.

  1. On the instance details page, click the Listeners tab, then click the listener ID associated with the endpoint group.

  2. On the listener details page, click the Endpoint Group tab. Locate the public IP address, then hover over the DDoS protection icon. The tooltip shows the BPS scrubbing threshold, PPS scrubbing threshold, and blackhole triggering threshold.

What's next

  • Adjust scrubbing thresholds: The default thresholds are set to the maximum for the IP bandwidth. If the BPS threshold is too high for effective protection, lower it. See Set scrubbing thresholds.

  • Upgrade DDoS protection: Anti-DDoS Basic covers common volumetric attacks. For advanced protection against more sophisticated threats, connect your GA instance to Anti-DDoS Origin or Anti-DDoS Pro/Premium. See Connect GA to Anti-DDoS Origin or Anti-DDoS Pro/Premium.