All Products
Search
Document Center

Server Load Balancer:Use an Anti-DDoS Pro/Premium EIP with an NLB instance

Last Updated:May 12, 2026

Alibaba Cloud provides Elastic IP addresses (EIPs) that are protected by Anti-DDoS Pro/Premium. These EIPs offer professional-grade, terabit-level DDoS protection, which makes them ideal for latency-sensitive applications that require high security, such as large-scale games and major live streaming events. This topic describes how to associate a Network Load Balancer (NLB) instance with an EIP that is protected by Anti-DDoS Pro/Premium to enable secure Internet access.image..png

Anti-DDoS Pro/Premium EIPs

Alibaba Cloud offers EIPs with Anti-DDoS Pro/Premium, which you can purchase from the Elastic IP Address console. An EIP with Anti-DDoS Pro/Premium provides robust security without extra Anti-DDoS configurations or changes to your service IP addresses. For more information, see EIPs with Anti-DDoS Pro/Premium.

Limitations

The NLB instance and the EIP with Anti-DDoS Pro/Premium must be in the same region.

Limitations on EIPs with Anti-DDoS Pro/Premium

  • Only pay-as-you-go EIPs that use the BGP (Multi-ISP) line type support Anti-DDoS Pro/Premium.

  • If you create an EIP with Anti-DDoS Pro/Premium from an IP address pool, the IP address pool must also be of the Anti-DDoS Pro/Premium type.

  • The following regions support Anti-DDoS Pro/Premium:

    Supported regions for EIPs

    Area

    Region

    China

    China (Beijing), China (Hangzhou), China (Shanghai), China (Hong Kong)

    Asia Pacific

    Philippines (Manila), Japan (Tokyo), Singapore, Malaysia (Kuala Lumpur), Indonesia (Jakarta)

    Europe and the Americas

    US (Virginia), US (Silicon Valley), Germany (Frankfurt), UK (London)

    Supported regions for IP address pools

    Area

    Region

    China

    China (Hong Kong)

    Asia Pacific

    Philippines (Manila), Japan (Tokyo), Singapore, Malaysia (Kuala Lumpur), Indonesia (Jakarta)

    Europe and the Americas

    US (Virginia), US (Silicon Valley), Germany (Frankfurt), UK (London)

Limitations on associating an NLB instance with an EIP with Anti-DDoS Pro/Premium

Before you associate the EIP with an NLB instance, ensure that the EIP is not added to an Internet Shared Bandwidth instance. If you need to use an Internet Shared Bandwidth instance, you must first associate the EIP with the NLB instance and then add it to the Internet Shared Bandwidth instance in the NLB console. EIPs with Anti-DDoS Pro/Premium can be added only to BGP (Multi-ISP) Internet Shared Bandwidth instances.

Billing

After you associate an NLB instance with an EIP with Anti-DDoS Pro/Premium, the Anti-DDoS service charges you a protection fee.NLB绑定高防EIP

Billable item

Formula

References

Instance fee

Instance fee = Unit price (USD/hour) × Billing duration (hours)

Instance fee

LCU fee

LCU fee = max{LCUs for new connections, LCUs for concurrent connections, LCUs for processed data, LCUs for rule evaluations} × LCU unit price × Billing duration (hours)

Load Balancer Capacity Unit (LCU) fees

Internet data transfer fee

Internet data transfer fees are not charged for internal-facing NLB instances. These fees apply only to Internet-facing NLB instances. After an NLB instance is associated with an EIP with Anti-DDoS Pro/Premium, you are charged instance fees and data transfer fees for the EIP. For more information, see Pay-as-you-go.

Protection fee

After an NLB instance is associated with an EIP with Anti-DDoS Pro/Premium, you are charged a protection fee. For more information, see Billing of pay-as-you-go Anti-DDoS Origin.

Warning

To purchase an EIP with Anti-DDoS Pro/Premium, you must activate the pay-as-you-go Anti-DDoS Origin service. This service is billed monthly and requires a minimum commitment of 30 days. You cannot disable the service within the first 30 days.

Prerequisites

Procedure

配置流程

Step 1: Create an Anti-DDoS Pro/Premium EIP

To associate an NLB instance with an EIP with Anti-DDoS Pro/Premium, you must first purchase one in the Elastic IP Address console.

  1. Log on to the Elastic IP Addresses console.

  2. On the Elastic IP Addresses page, click Create EIP.

  3. On the EIP creation page, if this is your first time purchasing an EIP with Anti-DDoS Pro/Premium, click Anti-DDoS Origin (Pay-as-you-go) to activate the pay-as-you-go Anti-DDoS Origin service.

    Warning

    To purchase an EIP with Anti-DDoS Pro/Premium, you must activate the pay-as-you-go Anti-DDoS Origin service. This service is billed monthly and requires a minimum commitment of 30 days. You cannot disable the service within the first 30 days.

    After you activate the pay-as-you-go Anti-DDoS Origin service, you can log on to the Traffic Security console and go to Network Security > Anti-DDoS Native > Billing Management or Network Security > Anti-DDoS Native > Instance Management to view details about your activated Anti-DDoS Origin instance.

  4. After you activate Anti-DDoS Origin, return to the EIP creation page. Configure the EIP parameters as described in the following table, and then click Buy Now and complete the payment.

    This section describes only the parameters relevant to this topic. For information about other parameters, see Apply for a new EIP.

    Parameter

    Description

    Billing Method

    Select the billing method for the EIP. In this topic, Pay-as-you-go is selected.

    Region

    Select the region for the EIP.

    Make sure that the EIP and the NLB instance are in the same region. In this topic, China (Hangzhou) is selected.

    ISP

    Select the line type for the EIP. In this topic, BGP (Multi-ISP) is selected.

    Security Protection

    Select the security protection level based on your business needs. In this topic, Anti-DDoS Pro/Premium is selected.

    • Default: provides basic DDoS protection of up to 5 Gbit/s.

    • Anti-DDoS Pro/Premium: provides professional-grade, terabit-level DDoS protection.

    Billing Method for Data Transfer

    Select the metering method for EIP data transfer. In this topic, Pay-By-Data-Transfer is selected.

    Quantity

    Specify the number of EIPs with Anti-DDoS Pro/Premium to purchase.

Step 2: Associate the EIP with an NLB instance

You can associate an NLB instance with an EIP with Anti-DDoS Pro/Premium when you create the instance or change its network type.

New NLB instance

When you create a new NLB instance, you can select an existing EIP with Anti-DDoS Pro/Premium to associate with it on the purchase page.

  1. Log on to the NLB console.

  2. In the top navigation bar, select the region where the NLB instance is to be deployed. In this topic, China (Hangzhou) is selected.

  3. On the Instances page, click Create NLB.

  4. On the NLB (Pay-As-You-Go) purchase page, configure the parameters, and then click Create Now and complete the payment.

    This section describes only the parameters relevant to this topic. For more information, see Create an NLB instance.

    • Network Type: Select Public.

    • VPC: Select the previously created VPC1.

    • Zone: Select a zone and vSwitch, and assign the EIP with Anti-DDoS Pro/Premium that you created to the selected zone.

      Note
      • NLB supports multi-zone deployment. To ensure high availability, select at least two zones if the region supports them. NLB does not charge extra fees for using multiple zones.

      • If no vSwitch is available in the selected zone, follow the prompts on the page to create one.

      • An NLB instance can be associated with both an EIP with Anti-DDoS Pro/Premium and an EIP with default security protection. The default option, Automatically assign EIP, creates a pay-as-you-go, pay-by-traffic BGP (Multi-ISP) EIP with default security protection.

  5. Configure a listener for the NLB instance. In this topic, a TCP listener is configured and associated with the server group RS01.

    1. Return to the NLB Instances page. In the Actions column of the target instance, click Create Listener.

    2. In the Configure Listener wizard, configure the listener parameters and click Next.

      This section describes only some of the parameters. You can keep the default values for the other parameters. For more information, see Add a TCP listener.

      • Listener Protocol: Select a protocol based on your needs. In this topic, TCP is selected.

      • Listener Port: Set the port to 80.

    3. In the Select Server Group wizard, select the RS01 server group that you created, and then click Next.

    4. In the Configuration Review wizard, review the configurations and click Submit.

Existing internal NLB

If you have an existing internal-facing NLB instance, you can associate an EIP with Anti-DDoS Pro/Premium by changing the instance's network type and assigning the EIP to the NLB instance.

  1. Log on to the NLB console.

  2. In the top navigation bar, select the region where the instance is deployed. In this topic, China (Hangzhou) is selected.

  3. On the Instances page, find the target internal-facing NLB instance and click its ID.

  4. On the Instance Details tab, find the Basic Information section. To the right of IPv4 in the Network Type field, click Change Network Type.

    私网NLB变更网络类型

  5. In the Change Network Type dialog box, set IP Address Type to EIP. From the Assign EIP drop-down list, select the EIP with Anti-DDoS Pro/Premium that you created in Step 1: Create an Anti-DDoS Pro/Premium EIP, and then click OK.

    An NLB instance can be associated with both an EIP with Anti-DDoS Pro/Premium and an EIP with default security protection. If you select Purchase EIP, a pay-as-you-go, pay-by-traffic BGP (Multi-ISP) EIP with default security protection is created.

Existing public NLB

If your Internet-facing NLB instance is associated with a default security protection EIP, and you need to associate the NLB instance with an Anti-DDoS Pro/Premium EIP, perform the following steps:

  1. Change the network type of the Internet-facing NLB instance to internal-facing.

  2. Change the network type back to Internet-facing and assign the EIP with Anti-DDoS Pro/Premium to the NLB instance.

Note

When you create an Internet-facing NLB instance, selecting the default Automatically assign EIP option associates the instance with a pay-as-you-go, pay-by-traffic BGP (Multi-ISP) EIP with default security protection.

公网ALB实例绑定高防EIP

Step 1: Change the NLB instance network type to internal-facing

  1. On the Instances page, find the target Internet-facing NLB instance and click its ID.

  2. On the Instance Details tab, find the Basic Information section. To the right of IPv4 in the Instance Details field, click Change Network Type.

    公网变更网络类型

  3. In the Change Network Type dialog box, review the impacts of the change and click OK.

    The change takes about one minute to take effect. The conversion is successful when the Network Type on the Instance Details tab changes to Private.

Step 2: Change the NLB instance network type back to Internet-facing

  1. On the Instances page, find the target internal-facing NLB instance and click its ID.

  2. On the Instance Details tab, find the Basic Information section. To the right of IPv4 in the Network Type field, click Change Network Type.

    私网NLB变更网络类型

  3. In the Change Network Type dialog box, set IP Address Type to EIP. From the Assign EIP drop-down list, select the EIP with Anti-DDoS Pro/Premium that you created in Step 1: Create an Anti-DDoS Pro/Premium EIP, and then click OK.

    An NLB instance can be associated with both an EIP with Anti-DDoS Pro/Premium and an EIP with default security protection. If you select Purchase EIP, a pay-as-you-go, pay-by-traffic BGP (Multi-ISP) EIP with default security protection is created.

(Optional) Step 3: Add the EIP to a shared bandwidth instance

If an NLB instance deployed across two zones is not added to an Internet Shared Bandwidth instance, its default public bandwidth is 400 Mbit/s. To obtain a higher bandwidth, you can add the EIP to an Internet Shared Bandwidth instance.

  1. On the NLB Instances page, find the target instance. You can use either of the following methods to add it to an Internet Shared Bandwidth instance:

    • In the Actions column, click the 更多操作.png icon and select >Associate with EIP Bandwidth Plan. Alternatively, click Associate in the EIP Bandwidth Plan column.

    • Click the target instance ID. On the Instance Details tab, find the Billing Information section and click Associate with EIP Bandwidth Plan.

  2. In the Associate with EIP Bandwidth Plan dialog box, select the target Internet Shared Bandwidth instance and click OK.

Step 4: Configure DNS resolution

NLB allows you to map a custom domain name to the public service domain of an NLB instance by using a CNAME record. This simplifies access to your network resources.

  1. In the left-side navigation pane, choose NLB > Instances.

  2. In the top navigation bar, select the region where the NLB instance is deployed. In this topic, China (Hangzhou) is selected.

  3. Perform the following steps to create a CNAME record:

    Note

    If your domain name is not registered by using Alibaba Cloud Domains, you must add your domain name to Alibaba Cloud DNS before you can configure a DNS record. For more information, see Manage domain names. If your domain name is registered by using Alibaba Cloud Domains, skip this step.

    1. Log on to the Alibaba Cloud DNS console.

    2. On the Authoritative DNS Resolution page, find your domain name and click DNS Settings in the Actions column.

    3. On the DNS Settings tab of the domain name details page, click Add DNS Record.

    4. In the Add Record panel, configure the parameters and click OK. The following table describes the parameters.

      Parameter

      Description

      Record Type

      Select CNAME from the drop-down list.

      Hostname

      The prefix of the domain name. In this example, @ is entered.

      Note

      If the domain name is a root domain name, enter @.

      DNS Query Source

      Select Default.

      Record Value

      Enter the CNAME, which is the domain name of the NLB instance.

      TTL Period

      Specify a time-to-live (TTL) value for the CNAME record to be cached on the DNS server. In this example, the default value is used.

Step 5: Test the connection

This topic uses an NLB instance with a TCP listener and the NLB server group RS01 as an example. For more information about other listeners, see the following topics:

After configuring DNS resolution for the NLB instance, open a browser and enter the domain name you configured in Step 4: Configure DNS resolution to test if the NLB instance is accessible from the Internet through the EIP with Anti-DDoS Pro/Premium.

Requests are forwarded to the two ECS servers.访问测试图1访问测试图2