Updated on 2026-08-26 GMT+08:00

Protection Policy Overview

CNAD Advanced provides diverse protection policies. After purchasing an instance, you can select a protection policy as needed or add a protection policy to implement DDoS protection.

If the protection policy is incorrectly configured, attacks may fail to be defended against or traffic may be incorrectly scrubbed. Exercise caution when performing this operation.

Limitations and Constraints

You can add a maximum of 10 protection policies. If you need to increase the quota, submit a service ticket.

Protection Policy Overview

  • Time when a protection policy takes effect:
    • Effective during attacks: The policy takes effect only when CNAD detects attack traffic and starts cleaning the traffic. The policy remains inactive during normal traffic conditions.
    • Always effective: The policy remains active permanently across all traffic states.
  • Rule validity period: Once configured, the rule stays in effect permanently.
Table 1 Protection policies

Protection Policy

Section

Standard Cloud Product

Anti-DDoS Service Dedicated EIP

Description

Example Configuration

Basic protection

Configuring a Basic Protection Policy to Intercept Attack Traffic

Always effective

Always effective

Configure a basic protection policy for protected objects. If the DDoS attack bandwidth for an IP address surpasses the configured scrubbing threshold, CNAD is activated to scrub the attack traffic, ensuring service availability.

Configure the parameters based on service requirements:

  • Traffic Scrubbing Level: 100 Mbit/s
  • Defense Mode: Normal

IP address blacklist or whitelist

Blocking or Permitting Traffic From Specified IP Addresses Using a Blacklist and Whitelist

Effective during attacks

Always effective

You can configure an access control list to control access to your IP addresses.

You can add a blacklist or whitelist as needed.

  • Blacklist: 1.1.x.x
  • Whitelist: 2.2.x.x

Fingerprint filtering

Setting a Traffic Handling Policy Based on Fingerprint Features

Effective during attacks

Always effective

You can configure fingerprint filtering protection rules to match the content at a specified location within a data packet. Based on the matching result, you can set actions such as discarding, allowing, or rate limiting.

Configure the parameters based on service requirements:

  • Protocol: UDP
  • Action: Allow

Port blocking

Blocking Traffic to a Specified Port

Effective during attacks

Always effective

If a destination port is unnecessary for access, you can set up a port blocking policy to block traffic from reaching the port, thereby minimizing DDoS attack risks.

Configure the parameters based on service requirements:

  • Rule Name: port1
  • Protocol: TCP
  • Port Type: Destination Port
  • Start Port - End port: 235 - 260
  • Action: Discard

Protocol rate limit

Limiting Traffic of a Specified Protocol

Effective during attacks

Always effective

You can block inbound traffic targeting your protected resources by protocol type. You can choose to block UDP, TCP, or ICMP traffic.

Configure the parameters based on service requirements:

  • UDP: Protective Action: Close
  • TCP: Protective Action: Limit rate
  • ICMP: Protective Action: Block
  • Other: Protective Action: Close

Watermarking

Using Watermarks to Defend Against CC Attacks

Effective during attacks

Always effective

CNAD supports the sharing of watermark algorithms and keys with the service end. All packets sent by the client are embedded with watermarks, which can effectively defend against layer-4 CC attacks.

Configure the parameters based on service requirements:

  • Watermark Name: test
  • Protocol: UDP
  • x,y
  • Port Range: 300 - 500

Advanced protection

Using Advanced Protection Policies to Restrict Abnormal Connections

Effective during attacks

Always effective

If an origin server IP address frequently sends a high volume of abnormal connection packets within a short period, you can set up an advanced protection policy to blacklist the origin server IP address for a certain period. Access from it can be restored once the blacklist period ends.

Configure parameters as required: Abnormal Connection Defense

  • Defense Mode: TCP Null Connection Defense
    • Packets per Connection/Period (s): 1/5
    • Abnormal Connections/Period (s): 3/5
  • Defense Threshold:
    • Connection threshold (connections): 500
    • Connection rate threshold (connections/second): 1000

Geo-blocking

Blocking Traffic From Specified Locations

Effective during attacks

Always effective

CNAD can block traffic from specified geographic regions. Once the policy is in effect, access traffic from the designated region will be discarded.

Configure the parameters based on service requirements:

  • Blocking Scope: One-click blocking
  • Region: Outside the Chinese mainland

Attack Filtering

Filtering Attacks Based on One-Click Rate Limiting Rules

Effective during attacks

Always effective

Provides common one-click rate limiting rules, such as UDP destination port rate limiting and DNS traffic rate limiting.

Configure the parameters based on service requirements:

Rules: SYN-ACK rate limiting and DNS rate limiting