Blocking or Allowing Traffic From Specified IP Addresses Using a Blacklist and Whitelist
After connecting your services to an Advanced Anti-DDoS instance, you can add source IP addresses to the blacklist or whitelist to control access. The settings automatically apply to all traffic protected by the instance.
The access requests from blacklisted IP addresses will be blocked, and those from whitelisted IP addresses will be allowed.
Notes and Constraints
- A maximum of 500 IP addresses can be added to each of the blacklist and whitelist. Only one subnet segment can be configured at a time.
- IP addresses or ranges should be separated by commas (,) and must be unique. The number of IP addresses and ranges cannot exceed the remaining quota.
- In a blacklist rule, the IPv4 and IPv6 prefix length must be at least /8.
- In a whitelist rule, the IPv4 prefix length must be at least /16, and the IPv6 prefix length must be at least /64.
- IP addresses in the blacklist cannot be added to the whitelist.
Configuring a Blacklist and a Whitelist
- Log in to the AAD console.
- In the navigation pane on the left, choose Advanced Anti-DDoS > Protection Policies. The Protection Policies page is displayed.
- Select the instance for which you want to configure a blacklist or whitelist.
- Configure a blacklist and a whitelist.
- Configuring a blacklist
- In the Blacklist and Whitelist configuration area, click Create whitelist/blacklist rules.
- Select the IP Blacklist tab and click Add.
- In the displayed dialog box, enter the IP addresses or IP ranges to be blocked. Figure 1 Adding blacklisted IP addresses
- Click OK.
On the IP Blacklist page, click Delete in the Operation column or select the blacklisted IP addresses to be deleted and click Delete to delete IP addresses in batch. Deleted IP addresses will not be blocked.
- Configuring a whitelist
- Select the IP Whitelist tab and click Add.
- In the displayed dialog box, enter the IP addresses or IP ranges to be permitted. Figure 2 Adding whitelisted IP addresses
The whitelist rules of DDoS attack protection (Layer 4 protection) are automatically synchronized to the web CC protection (Layer 7 protection) configuration.
- Click OK.
On the IP Whitelist page, click Delete in the Operation column or select the whitelisted IP addresses to be deleted and click Delete to delete IP addresses in batch. After an IP address is deleted from the whitelist, the device will not directly permit traffic from this IP address.
- Configuring a blacklist
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot