All Products
Search
Document Center

Global Accelerator:Instance diagnosis

Last Updated:Sep 09, 2026

If your Global Accelerator instance has an issue, you can use the instance diagnosis feature to troubleshoot it. This feature checks the configuration and operational status of your Global Accelerator instance and provides intelligent recommendations based on its findings. The diagnosis covers several categories: Configuration Diagnostics, Quota Limit Diagnostics, Certificate Diagnostics, Security Policy Diagnostics, Cost Diagnostics, and Service Access Diagnostics. You can also view the diagnostic history.

Prerequisites

  • The Global Accelerator instance that you want to diagnose is a standard instance. Instance diagnosis is supported only for standard Global Accelerator instances. It is not supported for basic Global Accelerator instances.

  • You must activate Network Intelligence Service (NIS). You can activate the service on the service activation page to start using it.

  • The first time you run a diagnosis, the system automatically creates a service-linked role named AliyunServiceRoleForNis to grant the necessary permissions. For more information, see Service-linked roles.

  • You have created the standard Global Accelerator instance that you want to diagnose. For details, see Create a standard GA instance.

Instance diagnosis

  1. Log on to the GA console.

  2. On the Instances page, find the Global Accelerator instance to diagnose and click Diagnose in the Monitor/Diagnostics column.

  3. In the Instance Diagnostics panel, view the diagnostic progress, a results summary, and detailed findings.

    • If issues are detected, the relevant diagnostic items appear in this panel. You can expand an item to view details.

    • In the Diagnostic Items area, select Show All Diagnostic Items. All diagnostic items supported by Global Accelerator are displayed. You can then expand each diagnostic item to view the diagnostic details.

    You can also click Go to the NIS console to view diagnostic records at the top of the Instance Diagnostics panel to go to the User Overview page of the Network Intelligence Service (NIS) console, where you can view more information about Global Accelerator instance diagnosis.

    Instance diagnosis mainly covers the configuration and running status of your Global Accelerator instance. A diagnostic result that shows correct configuration does not mean that link quality or origin server performance is free of issues. If you still experience high latency for cross-border access or slow origin server responses, use access logs together with MTR link probing for further troubleshooting.

Diagnostic items

The following table lists the diagnostic items available for a Global Accelerator instance.

Category

Item and description

Configuration Diagnostics

  • Check Instance Status: Checks if the operational status of the Global Accelerator instance is normal.

  • Configuration Integrity: Checks if the acceleration configuration is complete.

  • Configuration Correctness: Checks if the instance is configured correctly.

  • Access Control: Checks whether a whitelist or blacklist for access control is configured for the instance. For more information about access control, see Access control.

Quota Limit Diagnostics

This category assesses system resource utilization, identifies performance bottlenecks and risks, and helps you optimize and make timely adjustments. You can view the risk level based on the console prompts.

  • High Bandwidth Usage of Acceleration IP: Checks the inbound and outbound bandwidth utilization of the accelerated IP address.

  • Packet Loss Rate Due to Throttling on Acceleration IP: Checks for inbound and outbound packet loss.

  • High Bandwidth Usage of Endpoint Group: Checks the inbound and outbound public bandwidth utilization of the endpoint group.

  • Packet Loss Rate Due to Throttling on Endpoint Group: Checks for packet loss on the outbound public IP bandwidth of the endpoint group.

  • Bandwidth Usage Check for Inter-region Connection: Checks the bandwidth utilization of the inter-region connection.

  • Packet Loss Check for Inter-region Connection: Checks for inbound and outbound packet loss on the inter-region connection.

Certificate Diagnostics

Certification Expiration: Checks if the certificate for an HTTPS listener will expire within 60 days.

For more information about Global Accelerator certificates, see Associate and manage certificates.

Security Policy Diagnostics

  • Anti-DDoS Origin Basic Status: Indicates whether network activities for the accelerated IP address are protected against DDoS attacks, and whether the IP address is undergoing DDoS scrubbing or is in a black hole state.

  • Interception by Cloud Firewall: Check if network activities related to the accelerated IP address are blocked by Cloud Firewall.

  • Penalty for Security Control: Check whether the accelerated IP address is penalized by Alibaba Cloud Security for its network activities.

  • Suspension for Security Reasons: Checks if the accelerated IP address is locked for security risks.

Cost Diagnostics

  • Alerts for Overdue Payments: Checks for overdue payments on your Global Accelerator instance or bandwidth plan.

  • Alerts for Expiration: Checks if the instance will expire within 7 days.

Access Diagnostics

  • Health Check Status: Checks the health of endpoints. For more information about endpoint health checks, see Enable and manage health checks.

  • Access Errors: Checks if the backend service is returning timeouts or error codes.

  • Traffic Check: Uses access logs in the acceleration region to verify that traffic is reaching the Global Accelerator instance and to diagnose related access issues. For more information about access logs, see Use access logs.

Related documents

For more information about the instance diagnosis feature of Network Intelligence Service, see Use instance diagnosis.