Alibaba Cloud provides Elastic IP addresses (EIPs) that are protected by Anti-DDoS Pro/Premium. These EIPs offer professional-grade, terabit-level DDoS protection, which makes them ideal for latency-sensitive applications that require high security, such as large-scale games and major live streaming events. This topic describes how to associate a Network Load Balancer (NLB) instance with an EIP that is protected by Anti-DDoS Pro/Premium to enable secure Internet access.
Anti-DDoS Pro/Premium EIPs
Alibaba Cloud offers EIPs with Anti-DDoS Pro/Premium, which you can purchase from the Elastic IP Address console. An EIP with Anti-DDoS Pro/Premium provides robust security without extra Anti-DDoS configurations or changes to your service IP addresses. For more information, see EIPs with Anti-DDoS Pro/Premium.
Limitations
The NLB instance and the EIP with Anti-DDoS Pro/Premium must be in the same region.
Limitations on EIPs with Anti-DDoS Pro/Premium
-
Only pay-as-you-go EIPs that use the BGP (Multi-ISP) line type support Anti-DDoS Pro/Premium.
-
If you create an EIP with Anti-DDoS Pro/Premium from an IP address pool, the IP address pool must also be of the Anti-DDoS Pro/Premium type.
-
The following regions support Anti-DDoS Pro/Premium:
Supported regions for EIPs
Area
Region
China
China (Beijing), China (Hangzhou), China (Shanghai), China (Hong Kong)
Asia Pacific
Philippines (Manila), Japan (Tokyo), Singapore, Malaysia (Kuala Lumpur), Indonesia (Jakarta)
Europe and the Americas
US (Virginia), US (Silicon Valley), Germany (Frankfurt), UK (London)
Supported regions for IP address pools
Area
Region
China
China (Hong Kong)
Asia Pacific
Philippines (Manila), Japan (Tokyo), Singapore, Malaysia (Kuala Lumpur), Indonesia (Jakarta)
Europe and the Americas
US (Virginia), US (Silicon Valley), Germany (Frankfurt), UK (London)
Limitations on associating an NLB instance with an EIP with Anti-DDoS Pro/Premium
Before you associate the EIP with an NLB instance, ensure that the EIP is not added to an Internet Shared Bandwidth instance. If you need to use an Internet Shared Bandwidth instance, you must first associate the EIP with the NLB instance and then add it to the Internet Shared Bandwidth instance in the NLB console. EIPs with Anti-DDoS Pro/Premium can be added only to BGP (Multi-ISP) Internet Shared Bandwidth instances.
Billing
After you associate an NLB instance with an EIP with Anti-DDoS Pro/Premium, the Anti-DDoS service charges you a protection fee.
|
Billable item |
Formula |
References |
|
Instance fee |
|
|
|
LCU fee |
|
|
|
Internet data transfer fee |
Internet data transfer fees are not charged for internal-facing NLB instances. These fees apply only to Internet-facing NLB instances. After an NLB instance is associated with an EIP with Anti-DDoS Pro/Premium, you are charged instance fees and data transfer fees for the EIP. For more information, see Pay-as-you-go. |
|
|
Protection fee |
After an NLB instance is associated with an EIP with Anti-DDoS Pro/Premium, you are charged a protection fee. For more information, see Billing of pay-as-you-go Anti-DDoS Origin. Warning
To purchase an EIP with Anti-DDoS Pro/Premium, you must activate the pay-as-you-go Anti-DDoS Origin service. This service is billed monthly and requires a minimum commitment of 30 days. You cannot disable the service within the first 30 days. |
|
Prerequisites
-
A Virtual Private Cloud (VPC) named VPC1 is created. For more information, see Create a VPC.
-
Two ECS instances, ECS01 and ECS02, are created in VPC1, each with a different Nginx service deployed.
-
To learn how to create an ECS instance, see Create an instance by using the wizard.
-
To learn how to deploy an Nginx service, see Manually deploy an LNMP stack on a CentOS 7 instance.
-
-
An NLB server group named RS01 is created, and ECS01 and ECS02 are added as backend servers. For more information, see Create a server group.
-
If you want to add the EIP to an Internet Shared Bandwidth instance, you must first create one. In this topic, a BGP (Multi-ISP) Internet Shared Bandwidth instance is used. For more information, see Create and manage an Internet Shared Bandwidth instance.
Procedure

Step 1: Create an Anti-DDoS Pro/Premium EIP
To associate an NLB instance with an EIP with Anti-DDoS Pro/Premium, you must first purchase one in the Elastic IP Address console.
Log on to the Elastic IP Addresses console.
-
On the Elastic IP Addresses page, click Create EIP.
-
On the EIP creation page, if this is your first time purchasing an EIP with Anti-DDoS Pro/Premium, click Anti-DDoS Origin (Pay-as-you-go) to activate the pay-as-you-go Anti-DDoS Origin service.
WarningTo purchase an EIP with Anti-DDoS Pro/Premium, you must activate the pay-as-you-go Anti-DDoS Origin service. This service is billed monthly and requires a minimum commitment of 30 days. You cannot disable the service within the first 30 days.
After you activate the pay-as-you-go Anti-DDoS Origin service, you can log on to the Traffic Security console and go to or to view details about your activated Anti-DDoS Origin instance.
-
After you activate Anti-DDoS Origin, return to the EIP creation page. Configure the EIP parameters as described in the following table, and then click Buy Now and complete the payment.
This section describes only the parameters relevant to this topic. For information about other parameters, see Apply for a new EIP.
Parameter
Description
Billing Method
Select the billing method for the EIP. In this topic, Pay-as-you-go is selected.
Region
Select the region for the EIP.
Make sure that the EIP and the NLB instance are in the same region. In this topic, China (Hangzhou) is selected.
ISP
Select the line type for the EIP. In this topic, BGP (Multi-ISP) is selected.
Security Protection
Select the security protection level based on your business needs. In this topic, Anti-DDoS Pro/Premium is selected.
-
Default: provides basic DDoS protection of up to 5 Gbit/s.
-
Anti-DDoS Pro/Premium: provides professional-grade, terabit-level DDoS protection.
Billing Method for Data Transfer
Select the metering method for EIP data transfer. In this topic, Pay-By-Data-Transfer is selected.
Quantity
Specify the number of EIPs with Anti-DDoS Pro/Premium to purchase.
-
Step 2: Associate the EIP with an NLB instance
You can associate an NLB instance with an EIP with Anti-DDoS Pro/Premium when you create the instance or change its network type.
New NLB instance
When you create a new NLB instance, you can select an existing EIP with Anti-DDoS Pro/Premium to associate with it on the purchase page.
Log on to the NLB console.
-
In the top navigation bar, select the region where the NLB instance is to be deployed. In this topic, China (Hangzhou) is selected.
-
On the Instances page, click Create NLB.
-
On the NLB (Pay-As-You-Go) purchase page, configure the parameters, and then click Create Now and complete the payment.
This section describes only the parameters relevant to this topic. For more information, see Create an NLB instance.
-
Network Type: Select Public.
-
VPC: Select the previously created VPC1.
-
Zone: Select a zone and vSwitch, and assign the EIP with Anti-DDoS Pro/Premium that you created to the selected zone.
Note-
NLB supports multi-zone deployment. To ensure high availability, select at least two zones if the region supports them. NLB does not charge extra fees for using multiple zones.
-
If no vSwitch is available in the selected zone, follow the prompts on the page to create one.
-
An NLB instance can be associated with both an EIP with Anti-DDoS Pro/Premium and an EIP with default security protection. The default option, Automatically assign EIP, creates a pay-as-you-go, pay-by-traffic BGP (Multi-ISP) EIP with default security protection.
-
-
-
Configure a listener for the NLB instance. In this topic, a TCP listener is configured and associated with the server group RS01.
-
Return to the NLB Instances page. In the Actions column of the target instance, click Create Listener.
-
In the Configure Listener wizard, configure the listener parameters and click Next.
This section describes only some of the parameters. You can keep the default values for the other parameters. For more information, see Add a TCP listener.
-
Listener Protocol: Select a protocol based on your needs. In this topic, TCP is selected.
-
Listener Port: Set the port to 80.
-
-
In the Select Server Group wizard, select the RS01 server group that you created, and then click Next.
-
In the Configuration Review wizard, review the configurations and click Submit.
-
Existing internal NLB
If you have an existing internal-facing NLB instance, you can associate an EIP with Anti-DDoS Pro/Premium by changing the instance's network type and assigning the EIP to the NLB instance.
Log on to the NLB console.
-
In the top navigation bar, select the region where the instance is deployed. In this topic, China (Hangzhou) is selected.
-
On the Instances page, find the target internal-facing NLB instance and click its ID.
-
On the Instance Details tab, find the Basic Information section. To the right of IPv4 in the Network Type field, click Change Network Type.

-
In the Change Network Type dialog box, set IP Address Type to EIP. From the Assign EIP drop-down list, select the EIP with Anti-DDoS Pro/Premium that you created in Step 1: Create an Anti-DDoS Pro/Premium EIP, and then click OK.
An NLB instance can be associated with both an EIP with Anti-DDoS Pro/Premium and an EIP with default security protection. If you select Purchase EIP, a pay-as-you-go, pay-by-traffic BGP (Multi-ISP) EIP with default security protection is created.
Existing public NLB
If your Internet-facing NLB instance is associated with a default security protection EIP, and you need to associate the NLB instance with an Anti-DDoS Pro/Premium EIP, perform the following steps:
-
Change the network type of the Internet-facing NLB instance to internal-facing.
-
Change the network type back to Internet-facing and assign the EIP with Anti-DDoS Pro/Premium to the NLB instance.
When you create an Internet-facing NLB instance, selecting the default Automatically assign EIP option associates the instance with a pay-as-you-go, pay-by-traffic BGP (Multi-ISP) EIP with default security protection.

Step 1: Change the NLB instance network type to internal-facing
-
On the Instances page, find the target Internet-facing NLB instance and click its ID.
-
On the Instance Details tab, find the Basic Information section. To the right of IPv4 in the Instance Details field, click Change Network Type.

-
In the Change Network Type dialog box, review the impacts of the change and click OK.
The change takes about one minute to take effect. The conversion is successful when the Network Type on the Instance Details tab changes to Private.
Step 2: Change the NLB instance network type back to Internet-facing
-
On the Instances page, find the target internal-facing NLB instance and click its ID.
-
On the Instance Details tab, find the Basic Information section. To the right of IPv4 in the Network Type field, click Change Network Type.

-
In the Change Network Type dialog box, set IP Address Type to EIP. From the Assign EIP drop-down list, select the EIP with Anti-DDoS Pro/Premium that you created in Step 1: Create an Anti-DDoS Pro/Premium EIP, and then click OK.
An NLB instance can be associated with both an EIP with Anti-DDoS Pro/Premium and an EIP with default security protection. If you select Purchase EIP, a pay-as-you-go, pay-by-traffic BGP (Multi-ISP) EIP with default security protection is created.
(Optional) Step 3: Add the EIP to a shared bandwidth instance
If an NLB instance deployed across two zones is not added to an Internet Shared Bandwidth instance, its default public bandwidth is 400 Mbit/s. To obtain a higher bandwidth, you can add the EIP to an Internet Shared Bandwidth instance.
-
On the NLB Instances page, find the target instance. You can use either of the following methods to add it to an Internet Shared Bandwidth instance:
-
In the Actions column, click the
icon and select >Associate with EIP Bandwidth Plan. Alternatively, click Associate in the EIP Bandwidth Plan column. -
Click the target instance ID. On the Instance Details tab, find the Billing Information section and click Associate with EIP Bandwidth Plan.
-
-
In the Associate with EIP Bandwidth Plan dialog box, select the target Internet Shared Bandwidth instance and click OK.
Step 4: Configure DNS resolution
NLB allows you to map a custom domain name to the public service domain of an NLB instance by using a CNAME record. This simplifies access to your network resources.
-
In the left-side navigation pane, choose .
-
In the top navigation bar, select the region where the NLB instance is deployed. In this topic, China (Hangzhou) is selected.
Perform the following steps to create a CNAME record:
NoteIf your domain name is not registered by using Alibaba Cloud Domains, you must add your domain name to Alibaba Cloud DNS before you can configure a DNS record. For more information, see Manage domain names. If your domain name is registered by using Alibaba Cloud Domains, skip this step.
Log on to the Alibaba Cloud DNS console.
On the Authoritative DNS Resolution page, find your domain name and click DNS Settings in the Actions column.
On the DNS Settings tab of the domain name details page, click Add DNS Record.
In the Add Record panel, configure the parameters and click OK. The following table describes the parameters.
Parameter
Description
Record Type
Select CNAME from the drop-down list.
Hostname
The prefix of the domain name. In this example, @ is entered.
NoteIf the domain name is a root domain name, enter @.
DNS Query Source
Select Default.
Record Value
Enter the CNAME, which is the domain name of the NLB instance.
TTL Period
Specify a time-to-live (TTL) value for the CNAME record to be cached on the DNS server. In this example, the default value is used.
Step 5: Test the connection
This topic uses an NLB instance with a TCP listener and the NLB server group RS01 as an example. For more information about other listeners, see the following topics:
After configuring DNS resolution for the NLB instance, open a browser and enter the domain name you configured in Step 4: Configure DNS resolution to test if the NLB instance is accessible from the Internet through the EIP with Anti-DDoS Pro/Premium.
Requests are forwarded to the two ECS servers.
