將網站網域名稱新增至 Anti-DDoS Proxy 後,請將該網域名稱的 DNS 記錄指向 Anti-DDoS Proxy 產生的 CNAME 位址,即可啟用 DDoS 攻擊防護。本主題將引導您完成從快速整合到進階設定的完整流程,確保服務順利移轉。
開始之前
已購買 Anti-DDoS Proxy(中國內地)或 Anti-DDoS Proxy(非中國內地)執行個體。如需更多資訊,請參閱購買 Anti-DDoS Proxy 執行個體。
若您的網站服務已新增至 Anti-DDoS Proxy(中國內地)執行個體,則該網域名稱必須已完成 ICP 備案。如需更多資訊,請參閱ICP 備案。
說明新增至 Anti-DDoS Proxy(非中國內地)執行個體的網站不受 ICP 備案規範限制。
操作步驟
登入 Anti-DDoS Proxy 控制台的網站設定頁面。
在頂部導覽列中,選擇執行個體所在的地區。
Anti-DDoS Proxy(中國內地):選擇中國內地地區。
Anti-DDoS Proxy(非中國內地):選擇非中國內地地區。
在網站設定頁面,按一下新增網站。
說明您也可以按一下頁面底部的批次匯入,一次匯入多個網站設定。設定檔必須為 XML 格式。如需有關檔案格式的詳細資訊,請參閱其他作業。
輸入網站設定資訊,然後按一下下一步。
基本設定
功能方案:選擇要關聯的 Anti-DDoS Proxy 執行個體的功能方案。選項:標準版與增強版。
說明將滑鼠懸停在功能方案後的
圖示上,即可查看標準版與增強版功能方案的差異。如需更多資訊,請參閱標準版與增強版功能方案的差異。執行個體:選擇要關聯的 Anti-DDoS Proxy 執行個體。
重要一個網域名稱最多可關聯八個 Anti-DDoS Proxy 執行個體。這些執行個體必須使用相同的功能方案。
網站:輸入您要防護的網站網域名稱。您可以輸入精確比對的網域名稱,例如
www.example.com,或是萬用字元網域名稱,例如*.example.com。說明若同時存在萬用字元網域名稱(例如
*.aliyundoc.com)與精確比對網域名稱(例如www.aliyundoc.com)的設定,Anti-DDoS Proxy 會優先採用精確比對網域名稱(www.aliyundoc.com)的轉送規則與緩解策略。若您輸入的是根網域,則僅防護該根網域。二級網域及其他子網域不會受到防護。若要防護二級網域,請輸入該二級網域或萬用字元網域名稱。
您只能輸入網域名稱,不可輸入 IP 位址。
通訊協定類型:選擇網站支援的通訊協定。
HTTP / HTTPS:Web 服務的基礎通訊協定。
說明如需 HTTPS 設定的相關資訊,請參閱HTTPS 設定索引標籤中的說明。
Websocket / Websockets:即時通訊協定。若您選擇其中一種通訊協定,系統將自動選取 HTTP 或 HTTPS。
伺服器位址:設定 Anti-DDoS Proxy 進行回源時所使用的後端伺服器(源站)位址。
源站 IP 位址:輸入源站的公用 IP 位址。您可以輸入多個 IP 位址,並以逗號分隔。範例:
阿里雲上的源站:輸入源站 ECS 執行個體的公用 IP 位址。若在 ECS 執行個體前部署了 SLB 執行個體,請輸入該 SLB 執行個體的公用 IP 位址。
非阿里雲管理或其他雲端平台上的資料中心源站:執行
ping <網域名稱>命令以查詢該網域名稱解析到的公用 IP 位址,然後輸入該公用 IP 位址。
源站網域名稱:
適用情境:此選項適用於源站與 Anti-DDoS Proxy 之間還配置了其他代理服務的情境。範例:
若使用 WAF 作為前置代理,您可以輸入 WAF 執行個體的 CNAME。如需更多資訊,請參閱透過同時部署 Anti-DDoS Proxy 與 WAF 提升網站防護能力。
若您將源站網域名稱設定為 OSS Bucket 的預設公用存取點,則必須為該 Bucket 綁定自訂網域名稱。如需更多資訊,請參閱綁定自訂網域名稱。
限制:您最多可設定 10 個源站網域名稱。請以換行符號分隔。
伺服器連接埠:設定源站用於監聽網站服務的連接埠。
HTTP/Websocket:預設連接埠為 80。
HTTPS/Websockets:預設連接埠為 443。
自訂伺服器連接埠:
多個連接埠:您可以指定多個連接埠,並以逗號分隔。Anti-DDoS Proxy 執行個體所防護的所有網站服務之自訂連接埠總數不得超過 10 個。這包含不同通訊協定的自訂連接埠。
連接埠範圍(HTTP/HTTPS):80 至 65535
HTTPS 設定
若您選擇 HTTPS 進行加密驗證,請完成以下設定。
設定憑證:若要啟用 HTTPS,您必須設定與網站網域名稱相符的 SSL 憑證。
設定TLS 安全性設定:
說明如需更多資訊,請參閱自訂伺服器 HTTPS 憑證的 TLS 安全性原則。
SSL 憑證的 TLS 版本:選擇國際標準 HTTPS 憑證支援的 TLS 版本。
TLS 1.0 及以上版本。此設定提供最佳相容性,但安全性較低。:支援 TLS 1.0、TLS 1.1 及 TLS 1.2。
TLS 1.1 及以上版本。此設定提供良好的相容性與中等安全性。:支援 TLS 1.1 及 TLS 1.2。
TLS 1.2 及以上版本。此設定提供良好的相容性與高安全性等級。:支援 TLS 1.2。
啟用 TLS 1.3 支援:支援 TLS 1.3。
SSL 憑證的加密套件:為國際標準 HTTPS 憑證選擇支援的加密套件,或選擇自訂加密套件。將指標懸停在加密套件選項的
圖示上,即可查看其包含的加密套件。
雙向驗證:
由阿里雲簽發:從需要預設 CA 憑證。下拉式清單中選擇預設 CA 憑證。此憑證由阿里雲的憑證管理服務(原 SSL 憑證)簽發。
非阿里雲簽發:
首先,將自行簽署的 CA 憑證上傳至憑證管理服務(原 SSL 憑證)。如需詳細指示,請參閱上傳憑證庫。
在需要預設 CA 憑證。下拉式清單中,選擇已上傳的自行簽署 CA 憑證。
啟用 OCSP Stapling:OCSP 全名為 Online Certificate Status Protocol(線上憑證狀態通訊協定)。它用於向簽發伺服器憑證的憑證授權單位(CA)查詢該憑證是否已被撤銷。在與伺服器進行 TLS 握手期間,用戶端必須同時取得憑證及其對應的 OCSP 回應。
重要OCSP 回應由 CA 進行數位簽署,無法偽造。啟用此功能不會帶來額外的安全風險。
停用(預設):用戶端在 TLS 握手期間向 CA 傳送 OCSP 查詢,以驗證憑證是否已被撤銷。此程序會阻斷連線,若網路狀況不佳,可能會導致頁面載入延遲。
啟用:Anti-DDoS Proxy 會執行 OCSP 查詢並將結果快取 3,600 秒。當用戶端向伺服器發起 TLS 握手請求時,Anti-DDoS Proxy 會將快取的 OCSP 回應連同憑證鏈傳送給用戶端。這可避免用戶端查詢造成的阻斷問題,並提升 HTTPS 效能。
SM 憑證:僅 Anti-DDoS Proxy(中國內地)執行個體支援上傳基於 SM 的 HTTPS 憑證。僅支援 SM2 演算法。
-
Allow Access Only from SM Certificate-based Clients: Off by default. Options:
-
On: Accepts only SM-certificate clients.
說明When enabled, TLS suites, mutual authentication, and OCSP stapling settings for international standard HTTPS certificates do not take effect.
-
Off: Accepts clients with either an SM or international standard certificate.
-
-
SM Certificate: Select an SM certificate from the list. Upload the certificate to Certificate Management Service first.
-
SM Cipher Suites for HTTPS Support: The following cipher suites are enabled by default (not configurable):
-
ECC-SM2-SM4-CBC-SM3
-
ECC-SM2-SM4-GCM-SM3
-
ECDHE-SM2-SM4-CBC-SM3
-
ECDHE-SM2-SM4-GCM-SM3
-
-
Advanced settings
Enable HTTPS Redirection: This setting is suitable for websites that support both HTTP and HTTPS. After you enable this setting, all HTTP requests are forcibly redirected to HTTPS requests on port 443 by default.
重要You can enable this setting only if you select both the HTTP and HTTPS protocols and do not select the Websocket protocol.
If you access a website over a non-standard HTTP port (other than 80) and enable force redirect to HTTPS, the access requests are redirected to HTTPS port 443 by default.
HTTP/2 Listener: If this switch is turned on, clients that use HTTP/2 can access Anti-DDoS Proxy. However, Anti-DDoS Proxy still uses HTTP/1.1 for origin fetch. The specifications of the HTTP/2 feature are as follows:
Basic specifications:
Idle timeout after a connection is closed (http2_idle_timeout): 120 s
Maximum number of requests per connection (http2_max_requests): 1,000
Maximum number of concurrent streams per connection (http2_max_concurrent_streams): 4
Maximum size of the entire request header list after HPACK decompression (http2_max_header_size): 256 K
Maximum size of an HPACK-compressed request header field (http2_max_field_size): 64 K
Configurable specifications: You can Upper Limit for HTTP/2 Streams, which is the maximum number of concurrent streams allowed between the client and Anti-DDoS Proxy.
Set Forward Connection Timeout: This is the idle timeout period for a persistent TCP connection established between a client and Anti-DDoS Proxy. It is the maximum wait time between two client requests.
說明If no new request is received within the specified period, Anti-DDoS Proxy closes the connection to release resources.
Enter the Forwarding Settings and click Next.
Back-to-Origin settings
Back-to-origin Scheduling Algorithm: If you configure multiple Origin IP Addresses or Origin Domain Names, you can change the load balancing algorithm or set weights for different servers to determine how traffic is distributed among the origin servers.
Method
Scenarios
Description
Round-robin (Default)
Scenarios that use multiple origin servers and require high load balancing performance.
All requests are distributed to all server addresses in turn. By default, all server addresses have the same weight. You can change the weights of servers. A larger weight indicates a higher probability of receiving requests.
IP hash
Scenarios that require session consistency. In extreme cases, load imbalance may occur.
Requests from the same client IP address are always directed to the same origin server to ensure session consistency. You can set weights for servers while using the IP hash algorithm. This lets you distribute traffic based on server processing capabilities and prioritize servers with better performance.
Least time
Services that are highly sensitive to access speed and response latency, such as games and online transactions.
The intelligent DNS parsing capability and the least time algorithm for origin fetch ensure the shortest latency for the entire link from the POP to the origin server.
Retry Back-to-origin Requests: The number of health check probes to check the availability of the origin server for domain forwarding. The default value is 3. The retry mechanism works as follows:
The back-to-origin retry feature is triggered only when service traffic accesses an edge zone. When the edge zone detects that the origin server of a domain name is unavailable, it retries the origin fetch.
If the origin server is still unreachable after the maximum number of retries, it enters a silence period. During this period, no traffic is forwarded to the origin server, and no probes are sent.
After the silence period ends, the back-to-origin retry feature is triggered again based on service traffic. If the retry is successful, the origin server is reactivated.
Traffic Marking:
Request Header Forwarding Configuration: Anti-DDoS Proxy supports request header forwarding. You can add or modify HTTP request headers when forwarding requests to your origin server. This helps identify and mark traffic that passes through Anti-DDoS Proxy.
Insert X-Client-IP to Get Originating IP Address: Passes the client’s original IP address.
Insert X-True-IP to Forward Client IP: Passes the IP address the client used to establish the connection.
Insert Web-Server-Type to Get Service Type: Usually added by the first proxy. Tells the backend server which frontend web server or proxy handled the request.
Insert WL-Proxy-Client-IP to Get Connection IP: Same function as X-Client-IP. A header specific to Oracle WebLogic Server.
X-Forwarded-Proto (Listener Protocol): The protocol used between the client and the first proxy.
Traffic marks
Default marks
說明JA3 Fingerprint, JA4 Fingerprint, Client TLS Fingerprint, and HTTP/2 Fingerprint require assistance from your account manager to configure.
If your service uses custom fields instead of default marks, see Custom Header below. After you configure it, your origin server parses this field from requests forwarded by Anti-DDoS Proxy. For parsing examples, see Get the true source IP address after configuring Anti-DDoS Proxy.
Originating Port: The header field name for the client’s originating port in the HTTP header. Typically recorded in the
X-Forwarded-ClientSrcPortfield.Originating IP Address: The header field name for the client’s originating IP address in the HTTP header. Typically recorded in the
X-Forwarded-Forfield.JA3 Fingerprint: The name of the HTTP header field that contains the MD5 hash of the client's JA3 fingerprint. The default field is
ssl_client_ja3_fingerprinting_md5.JA4 Fingerprint: The name of the HTTP header field that contains the MD5 hash of the client's JA4 fingerprint. The default field is
ssl_client_ja4_fingerprinting_md5.Client TLS Fingerprint: The name of the HTTP header field that contains the MD5 hash of the client's TLS fingerprint. The default field is
ssl_client_tls_fingerprinting_md5.HTTP/2 Fingerprint: The header field name for the MD5 hash value generated from the client HTTP/2.0 fingerprint in the HTTP header. Typically recorded in the
http2_client_fingerprint_md5field.
Custom Header: Add a custom HTTP header (including field name and value) to mark requests that pass through Anti-DDoS Proxy. When Anti-DDoS Proxy forwards website traffic, it adds the configured field value to requests sent to your origin server. This helps your backend service analyze and track traffic.
Naming restrictions: To avoid overwriting original request header fields, do not use the following reserved or common field names for your custom header:
Anti-DDoS Proxy default fields:
X-Forwarded-ClientSrcPort: Used by default to get the client port for Layer 7 engine access.X-Forwarded-ProxyPort: Used by default to get the listening port for Layer 7 engine access.X-Forwarded-For: Used by default to get the client IP address for Layer 7 engine access.ssl_client_ja3_fingerprinting_md5: Used by default to retrieve the MD5 hash of the client's JA3 fingerprint.ssl_client_ja4_fingerprinting_md5: Used by default to retrieve the MD5 hash of the client's JA4 fingerprint.ssl_client_tls_fingerprinting_md5: Used by default to retrieve the MD5 hash of the client's TLS fingerprint.http2_client_fingerprint_md5: Used by default to get the MD5 hash value of the client HTTP/2.0 fingerprint.
Standard HTTP fields: Such as host, user-agent, connection, and upgrade.
Common proxy fields: Such as x-real-ip, x-true-ip, x-client-ip, web-server-type, wl-proxy-client-ip, eagleeye-rpcid, eagleeye-traceid, x-forwarded-cluster, and x-forwarded-proto.
Quantity limit: You can add up to five custom header labels.
Configuration recommendations:
Use default marks first.
Verify the header field configuration in the staging environment before applying it to the production environment.
We recommend keeping field values to 100 characters or less to avoid affecting forwarding performance.
CNAME Reuse: Select whether to enable CNAME reuse. After you enable CNAME reuse, you can add multiple domain names that are hosted on the same server to Anti-DDoS Proxy by pointing their DNS records to the same Anti-DDoS Proxy CNAME. You do not need to add a separate website configuration for each domain name. For more information, see CNAME reuse.
重要This parameter is supported only by Anti-DDoS Proxy (Outside Chinese Mainland).
Other settings
Enable HTTP Redirection of Back-to-origin Requests: If your website does not support HTTPS for origin fetch, you must enable this setting. After you enable this setting, all HTTPS requests are sent to the origin server over HTTP, and all Websockets requests are sent over Websocket. The default origin port is 80.
說明If you access a website over a non-standard HTTPS port (other than 443) and enable HTTP for origin fetch, the access requests are redirected to HTTP port 80 of the origin server by default.
HTTP/2.0 Origin: After you enable HTTP/2.0 for back-to-origin requests, Anti-DDoS Proxy uses HTTP/2.0 to send requests to the origin.
警告To configure this feature, contact your account manager.
If your origin server does not support HTTP/2.0, do not configure this feature. Otherwise, your website becomes inaccessible.
Cookie Settings
Delivery Status: Enabled by default. Anti-DDoS Proxy inserts a cookie into the client, such as a browser, to differentiate clients or obtain client fingerprints. For more information, see Configure HTTP flood protection.
重要If you experience logon failures or session losses after you add your application to Anti-DDoS Proxy, you can try to disable this switch. Note that if you disable this switch, some HTTP flood protection features become ineffective.
Secure Attribute: Disabled by default. If you enable this attribute, the cookie is sent only over HTTPS connections, not HTTP connections. This helps protect the cookie from being stolen.
說明We recommend that you enable this attribute if your website service supports only HTTPS connections.
Configure New Connection Timeout Period: The time that Anti-DDoS Proxy waits to establish a connection to the origin server.
說明If a connection is not established within this period, the attempt is considered a failure.
Configure Read Connection Timeout Period: The maximum time that Anti-DDoS Proxy waits for a response from the origin server after it establishes a connection and sends a read request.
Configure Write Connection Timeout Period: The time that Anti-DDoS Proxy waits after sending data and before the origin server starts processing it.
說明If Anti-DDoS Proxy fails to send all data to the origin server or the origin server does not start processing the data within this period, the attempt is considered a failure.
Back-to-origin Persistent Connections: A TCP connection between a cache server and an origin server remains active for a period instead of closing after each request. This can waste resources. Enable Back-to-origin Persistent Connections to reduce connection establishment time and resource consumption, and to improve request processing efficiency and speed.
Requests Reusing Persistent Connections: The number of HTTP requests that can be sent over a single TCP connection from Anti-DDoS Proxy to the origin server. This reduces latency and resource consumption caused by frequent connection establishment and termination.
說明We recommend that you set this value to be less than or equal to the number of requests per persistent connection configured on the backend origin server, such as a WAF or SLB instance. This prevents service inaccessibility caused by connection termination.
Timeout Period of Idle Persistent Connections: The maximum time that an idle persistent TCP connection from Anti-DDoS Proxy to the origin server can remain open in the connection pool of Anti-DDoS Proxy. If no new request is received within this period, the connection is closed to release system resources.
說明We recommend that you set this value to be less than or equal to the timeout period configured on the backend origin server, such as a WAF or SLB instance. This prevents service inaccessibility caused by connection termination.
Verify and go-live
After you complete the website configuration, follow this checklist to perform validation and go live. This helps prevent service interruptions.
Core steps (Required)
Allow back-to-origin IP addresses: In the security policies of your origin server, such as a firewall or security group, add the back-to-origin IP address ranges of Anti-DDoS Proxy to the whitelist. This prevents traffic that is forwarded from Anti-DDoS Proxy to your origin from being mistakenly blocked. For more information, see Add the back-to-origin IP addresses of Anti-DDoS Proxy to a whitelist.
Verify the configuration locally: Before you change your DNS records, modify the local
hostsfile to verify that the forwarding configuration works as expected. This helps prevent service interruptions. For more information, see Verify forwarding settings on a local machine.Switch DNS resolution: After the local verification is successful, change the DNS record of your website domain name to the CNAME provided by Anti-DDoS Proxy. This action switches your service traffic to Anti-DDoS Proxy for protection. For more information, see Use a CNAME or IP address to resolve a domain name to Anti-DDoS Proxy.
Optional steps
Change the origin IP address: If your origin server is an Alibaba Cloud ECS instance and its IP address is exposed, we recommend that you change the public IP address of the ECS instance. This prevents attackers from bypassing Anti-DDoS Proxy to attack your origin server. For more information, see Static public IP address.
Configure DDoS mitigation policies: In addition to the default mitigation policies of Anti-DDoS Proxy (Anti-DDoS Global Mitigation Policy, Intelligent Protection, and Frequency Control), you can enable more protection features on the Protection for Website Services tab as needed. For more information, see Protection for Website Services.
重要Enabling HTTP flood protection policies may insert a cookie into the client. For more information, see Cookie insertion.
Configure CloudMonitor alerts: Configure alert rules for common service metrics of Anti-DDoS Proxy, such as traffic and connections, and attack events, such as blackhole filtering and scrubbing events. This lets you receive timely alerts for anomalous activity and respond quickly. For more information, see CloudMonitor alerts.
Configure the log analysis service: Enable the log analysis service to collect and store website access logs for 180 days by default. This is useful for business analysis and meeting classified protection compliance requirements. For more information, see Quickly use the log analysis feature.
Quotas and limits
A domain name can be associated with a maximum of eight Anti-DDoS Proxy instances.
The total number of custom ports (other than 80 or 443) for all website configurations under an Anti-DDoS Proxy instance cannot exceed 10.
You can add a maximum of five custom header labels.
References
ICP filing
ICP filing check and handling: Anti-DDoS Proxy (Chinese Mainland) periodically checks the ICP filing status of protected domain names. If an ICP filing becomes invalid, Anti-DDoS Proxy (Chinese Mainland) stops forwarding traffic for the related services and displays a "The domain name has not completed ICP filing. Please update the filing status." message on the Website Config page.
Dual ICP filing requirement: If the origin server is an Alibaba Cloud product, it must meet the ICP filing requirements of both Anti-DDoS Proxy and the origin product. Otherwise, back-to-origin traffic forwarding will be affected. For more information, see the official documentation of each cloud product or contact technical support. For example, if the origin server is an ECS instance, you must obtain an ICP filing for the ECS instance. For more information, see ICP filing check for servers and ICP filing process.
Service recovery: If you receive a notification that your ICP filing is invalid, update your filing information immediately to resume the service.
Delete a website configuration
If a website configuration is no longer needed, you can delete it as follows:
Restore the DNS record: Change the DNS record of the domain name so that it no longer points to the IP address of the Anti-DDoS Proxy instance, the Anti-DDoS Proxy CNAME, or the Sec-Traffic Manager CNAME.
警告If you delete the website configuration before you restore the DNS record, your service may be interrupted.
Delete the website configuration
Manually delete: On the Website Config page, find the target configuration and click Delete in the Actions column. For more information, see Delete a website configuration.
Automatically delete: One month after the last Anti-DDoS Proxy instance under your account is released, the system automatically deletes all domain name and port forwarding configurations of Anti-DDoS Proxy under the account.
FAQ
Why do I get a 502 or 504 error when I access my website after I complete the configuration?
This error usually occurs because the origin fetch fails. Check the following items in order:
Check the origin server firewall/security group: Confirm that you have added the back-to-origin IP address ranges of Anti-DDoS Proxy to the whitelist.
Check the "Enable HTTP for Origin Fetch" configuration: If your origin server supports only HTTP (listening on port 80), but you have configured HTTPS in Anti-DDoS Proxy without enabling "Enable HTTP for Origin Fetch", the origin fetch will fail.
Check the origin server status: Confirm that the Origin IP Address is correct and that the origin server itself is running properly.
Why does my browser report a certificate error after I enable HTTPS?
Check the following items:
Certificate-domain name mismatch: Make sure the certificate covers the domain name you added, including the
wwwand root domains. For example, a certificate forwww.example.comcannot be used forexample.comunless it is a wildcard or multi-domain certificate.Incomplete certificate chain: When you upload a certificate, make sure to upload the complete certificate chain (server certificate plus intermediate CA certificate).
Expired certificate: Check if the uploaded certificate is still valid.
How can I confirm that my website traffic is passing through Anti-DDoS Proxy?
DNS query: In the command line, run
ping <your domain name>ordig <your domain name>. Check if the resolved address is the CNAME of the Anti-DDoS Proxy instance or the IP address it points to.Console reports: On the reports page of the Anti-DDoS Proxy console, check if there is inbound traffic data.
Origin server logs: Check the web access logs of your origin server to confirm that the source IP addresses of requests belong to the back-to-origin IP address ranges of Anti-DDoS Proxy.
My application logs record only the IP address of Anti-DDoS Proxy. How can I get the real visitor IP address?
This is expected. As a proxy, Anti-DDoS Proxy uses its back-to-origin IP addresses to access your origin server. To get the real visitor IP address, you need to configure your web server (such as Nginx or Apache) to extract the IP address from the
X-Forwarded-Forrequest header. For more information, see Obtain the real IP addresses of clients after you configure an Anti-DDoS Proxy instance.How do I verify the mitigation effectiveness of Anti-DDoS Proxy?
Note that you cannot manually trigger blackhole filtering on your server for testing purposes. Blackhole filtering is automatically triggered when the system detects a volumetric DDoS attack that exceeds the mitigation threshold. To verify the scrubbing and forwarding effectiveness of Anti-DDoS Proxy:
Use a test service: Connect a test service, instead of your production service, to Anti-DDoS Proxy to avoid impact on production traffic.
Simulate DDoS traffic: Use a stress testing tool to simulate DDoS traffic and observe the scrubbing and forwarding behavior of Anti-DDoS Proxy.
Check console reports: On the reports page of the Anti-DDoS Proxy console, check the mitigation data and scrubbing results.
Check origin server logs: Check the web access logs of your origin server and confirm that the source IP addresses of requests belong to the back-to-origin IP address ranges of Anti-DDoS Proxy.