Protection Policy Overview
CNAD Advanced provides diverse protection policies. After purchasing an instance, you can select a protection policy as needed or add a protection policy to implement DDoS protection.
If the protection policy is incorrectly configured, attacks may fail to be defended against or traffic may be incorrectly scrubbed. Exercise caution when performing this operation.
Limitations and Constraints
You can add a maximum of 10 protection policies. If you need to increase the quota, submit a service ticket.
Protection Policy Overview
- Time when a protection policy takes effect:
- Effective during attacks: The policy takes effect only when CNAD detects attack traffic and starts cleaning the traffic. The policy remains inactive during normal traffic conditions.
- Always effective: The policy remains active permanently across all traffic states.
- Rule validity period: Once configured, the rule stays in effect permanently.
| Protection Policy | Section | Standard Cloud Product | Anti-DDoS Service Dedicated EIP | Description | Example Configuration |
|---|---|---|---|---|---|
| Basic protection | Configuring a Basic Protection Policy to Intercept Attack Traffic | Always effective | Always effective | Configure a basic protection policy for protected objects. If the DDoS attack bandwidth for an IP address surpasses the configured scrubbing threshold, CNAD is activated to scrub the attack traffic, ensuring service availability. | Configure the parameters based on service requirements:
|
| IP address blacklist or whitelist | Blocking or Permitting Traffic From Specified IP Addresses Using a Blacklist and Whitelist | Effective during attacks | Always effective | You can configure an access control list to control access to your IP addresses. | You can add a blacklist or whitelist as needed.
|
| Fingerprint filtering | Setting a Traffic Handling Policy Based on Fingerprint Features | Effective during attacks | Always effective | You can configure fingerprint filtering protection rules to match the content at a specified location within a data packet. Based on the matching result, you can set actions such as discarding, allowing, or rate limiting. | Configure the parameters based on service requirements:
|
| Port blocking | Effective during attacks | Always effective | If a destination port is unnecessary for access, you can set up a port blocking policy to block traffic from reaching the port, thereby minimizing DDoS attack risks. | Configure the parameters based on service requirements:
| |
| Protocol rate limit | Effective during attacks | Always effective | You can block inbound traffic targeting your protected resources by protocol type. You can choose to block UDP, TCP, or ICMP traffic. | Configure the parameters based on service requirements:
| |
| Watermarking | Effective during attacks | Always effective | CNAD supports the sharing of watermark algorithms and keys with the service end. All packets sent by the client are embedded with watermarks, which can effectively defend against layer-4 CC attacks. | Configure the parameters based on service requirements:
| |
| Advanced protection | Using Advanced Protection Policies to Restrict Abnormal Connections | Effective during attacks | Always effective | If an origin server IP address frequently sends a high volume of abnormal connection packets within a short period, you can set up an advanced protection policy to blacklist the origin server IP address for a certain period. Access from it can be restored once the blacklist period ends. | Configure parameters as required: Abnormal Connection Defense
|
| Geo-blocking | Effective during attacks | Always effective | CNAD can block traffic from specified geographic regions. Once the policy is in effect, access traffic from the designated region will be discarded. | Configure the parameters based on service requirements:
| |
| Attack Filtering | Effective during attacks | Always effective | Provides common one-click rate limiting rules, such as UDP destination port rate limiting and DNS traffic rate limiting. | Configure the parameters based on service requirements: Rules: SYN-ACK rate limiting and DNS rate limiting |
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot