CNAD Basic (Anti-DDoS) |
Anti-DDoS monitors the service traffic from the Internet to public IP addresses and detects attack traffic in real time. It then scrubs attack traffic based on user-configured defense policies without interrupting services. It also generates monitoring reports that provide visibility into the network traffic security. |
You can use this service to protect your public IPv4 and IPv6 addresses on Huawei Cloud against the DDoS attacks if you have only general security requirements. |
Anti-DDoS provides a 2 Gbit/s DDoS mitigation capacity for free, and its maximum mitigation capacity can reach 5 Gbit/s (depending on the available bandwidth of Huawei Cloud). 2 Gbit/s is the traffic peak, that is, the maximum traffic that Anti-DDoS can defend against. |
CNAD Advanced (including CNAD standard, platinum, unlimited protection advanced, and unlimited protection basic editions) |
CNAD Advanced provides higher DDoS protection capability for cloud services, such as Elastic Cloud Server (ECS), Elastic Load Balance (ELB), Web Application Firewall (WAF), and Elastic IP (EIP), on Huawei Cloud. CNAD Advanced defends against the DDoS attacks targeting the IP addresses on Huawei Cloud and provides higher protection capabilities for cloud services. With few clicks on the console, you can enjoy always-on DDoS mitigation. |
CNAD Advanced is used to protect your Huawei Cloud services (with public IP addresses assigned to) from DDoS attacks, meeting your requirements for immense protection capability and high network quality. CNAD Advanced can be used for the following scenarios:
|
- CNAD Advanced standard
20G
- CNAD unlimited protection basic edition
Shared protection for not less than 20 Gbit/s of traffic
- CNAD unlimited protection advanced edition
Unlimited protection can be shared among them, with up to 1.5 Tbit/s protection capability. Dedicated EIPs and service bandwidth are billed separately.
|
AAD |
AAD works as a proxy and uses AAD IP addresses to forward requests to origin servers. All public network traffic is diverted to the AAD IP address so that the origin server is hidden from the public. This protects origin servers from DDoS attacks. |
If your service servers and main customers are in the Chinese Mainland, the access of your customers outside the Chinese Mainland may be affected by network quality. HUAWEI CLOUD, non-HUAWEI CLOUD, and IDC hosts can be protected.
NOTICE:
- AAD does not support domain names that have no ICP licenses. To use AAD to protect website services, ensure that the website domain name has an ICP license.
- AAD provides IPv4 protection by default.
- If you want to use IPv6 protection, use CNAD Advanced.
|
One high-defense IP address is able to defend against 1 Tbit/s network-, and application-layer DDoS attacks. The AAD service offers more than 5 Tbit/s of defense capability.
- 5 Tbit/s of defense capability is the overall defense capability of the AAD equipment room.
- 1 Tbit/s of defense capability refers to the maximum protection capability of a single high-defense IP address.
|
AAD International |
If your service servers are deployed outside the Chinese Mainland and your main users are outside the Chinese Mainland, AAD international is suitable for you. |
If your service server is deployed outside the Chinese Mainland but your main service users are in the Chinese Mainland, there might be an average of about 300ms delay for users in the Chinese Mainland.
NOTE:
If you want to use AAD international edition, we recommended that you can use AAD for your servers and customers outside the Chinese Mainland only.
|
Over 5 Tbit/s AAD defense capability, supporting unlimited AnyCast defense. |