Updated on 2026-08-26 GMT+08:00

Purchasing AAD Instances

AAD offers continuous protection to maintain service continuity during frequent DDoS attacks, particularly those with high traffic.

After purchasing the service, you need to perform only simple operations to gain robust protection capabilities. This service is suitable for servers deployed in the Chinese mainland and Asia Pacific regions.

  • After you purchase an AAD instance, refunds are not supported.
  • When an AAD instance is frozen, only the basic service connectivity is maintained, and no protection capacity is provided.
  • If an AAD instance has expired for 30 or more calendar days, AAD will stop forwarding service traffic and the instance will become invalid. If you do not need to use AAD anymore, switch your service traffic from AAD to the origin server 30 calendar days before the expiration date.

Limitations and Constraints

  • A new user can purchase up to 20 instances by default. (An old user can purchase up to 10 instances by default.) If the quota is insufficient, submit a service ticket to apply for a higher quota.
  • If your service servers are located in Chinese Mainland, you are advised to purchase AAD. To use AAD, ensure that all the domain names to be protected have obtained valid ICP licenses.
  • If your service servers are located outside Chinese Mainland, submit a service ticket for consultation.

Prerequisites

The account must have the permissions of the CAD Administrator and BSS Administrator roles.

Purchasing AAD Instances

The instance purchase varies depending on the protected region.

  1. Log in to the AAD console.
  2. In the upper right corner of the page, click Buy DDoS Mitigation.
  3. On the Buy DDoS Mitigation page, set Instance Type to AAD.
  4. Configure instance specifications, as shown in Table 1.

    Table 1 Parameters for purchasing an AAD instance

    Parameter

    Description

    Access Type

    • Website: Huawei Cloud uses intelligent algorithms to select the optimal access point for you and does not provide fixed high-defense IP addresses. This type is recommended for users using domain name access.
    • IP Access: provides only IP port protection and fixed high-defense IP addresses.

    Region

    • Chinese mainland: applies to scenarios where service servers are deployed in the Chinese mainland.
    • Other: applies to scenarios where service servers are deployed in the Asia Pacific region.

    If your service servers are deployed in other regions, submit a service ticket for consultation.

    Line

    • If Chinese mainland is selected, only BGP is supported.
    • If Other is selected, only AnyCast is supported.

    IP Type

    • To protect an IPv4 origin server, select IPv4.
    • To protect an IPv6 origin server, select IPv6.

    Only IPv4 addresses can be protected outside the Chinese mainland.

    Region

    Select a region near your resources.

    Basic Protection Bandwidth

    The basic protection bandwidth is the minimum bandwidth used to defend against attacks. If the peak attack traffic is less than or equal to the basic protection bandwidth, customers do not need to pay extra fees.

    To achieve enhanced protection, use the Elastic Protection Bandwidth parameter.

    Elastic Protection Bandwidth

    If you set this parameter to a value larger than the basic protection bandwidth, additional charges ensue when attack traffic exceeding the basic protection bandwidth is scrubbed.

    You can modify the elastic protection bandwidth as needed after you have purchased an AAD instance.

    NOTE:

    The elastic protection bandwidth must be greater than or equal to the basic protection bandwidth. If the two are set to the same value, the elastic protection bandwidth function does not take effect.

    Service Bandwidth

    Clean service bandwidth forwarded to the origin server from the AAD scrubbing center. The value ranges from 100 Mbit/s to 2000 Mbit/s.

    Collect statistics on the peak inbound and outbound traffic of all services to be connected to the AAD instance. The service bandwidth must be greater than both the peak inbound and outbound traffic.

    CAUTION:

    If the service bandwidth of your instance is lower than peak inbound or outbound traffic, packet loss may occur and your services may be affected. In this case, upgrade the service bandwidth in a timely manner. For details about upgrading specifications, see Modifying Instance Specifications.

    Assume that you have two services (service A and service B) to access AAD. The peak traffic of service A does not exceed 50 Mbit/s, and the peak traffic of service B does not exceed 70 Mbit/s. The total traffic does not exceed 120 Mbit/s. In this case, you only need to ensure that the maximum service bandwidth of the purchased instance is greater than 120 Mbit/s.

    Elastic Bandwidth

    • Disabled
    • Daily 95th percentile billing (supported only outside the Chinese mainland): Traffic is averaged over 5-minute intervals throughout each calendar day. These 5-minute averages are sorted in descending order, the top 5% are discarded, and the highest remaining value is taken as the billing bandwidth.
    • Monthly 95th percentile billing: Traffic is averaged over 5-minute intervals throughout each calendar month. These 5-minute averages are sorted in descending order, the top 5% are discarded, and the highest remaining value is taken as the billing bandwidth.

    For details about elastic bandwidth billing, see How Is the Elastic Service Bandwidth Charged?

    Increase Elastic Bandwidth

    This parameter is available only if you enable elastic bandwidth billing.

    After you set this parameter, the actual available bandwidth is the current service bandwidth plus the value of Increase Elastic Bandwidth.

    Service QPS

    This parameter is available only when the access type is Website.

    The maximum number of requests an instance can handle without an attack.

    In the Chinese mainland, the default QPS is 3,000. You can purchase a higher QPS, up to 100,000. If you need a larger QPS, submit a service ticket.

    Protected Domain Names

    This parameter is available only when the access type is Website.

    By default, 50 objects are supported. You can pay for more. Up to 1000 objects are supported in the Chinese mainland.

    Forwarding Rules

    This parameter is available only when the access type is IP Access.

    By default, 50 objects are supported. You can pay for more. Up to 500 objects are supported in the Chinese mainland.

    Instance Name

    Name of the AAD instance.
    • The name can contain a maximum of 32 characters.
    • The name can contain only letters, numbers, underscores (_), and hyphens (-).

    Enterprise Project

    This parameter is only available if you have enabled the enterprise project function, or if your account is an enterprise account.

    To learn more, see Enabling Enterprise Center.

    NOTE:
    • Value default indicates the default enterprise project. Resources that are not allocated to any enterprise projects under your account are displayed in the default enterprise project.
    • The default option is available in the Enterprise Project drop-down list when you purchase AAD with a registered Huawei Cloud account.

    Required Duration

    Set the required duration.

    Auto Renewal

    • For monthly billing, your subscription will be renewed every month.
    • For yearly billing, your subscription will be renewed every year.

    Quantity

    Select the number of instances to be purchased. By default, a new user can purchase up to 20 instances. (An old user can purchase up to 10 instances by default.)

  5. (Optional) If IP Access is selected, read the note and select the check box under Note.
  6. Click Next.
  7. On the Details page, select the agreement and click Submit Order.
  8. Pay for the order on the payment page.
  1. Log in to the AAD console.
  2. In the upper right corner of the page, click Buy DDoS Mitigation.
  3. On the Buy AAD page, set Instance Type to Advanced Anti-DDoS.
  4. Configure AAD instance specifications, as shown in Table 2.

    Table 2 Parameter description

    Parameter

    Description

    Access Type

    • Website: Huawei Cloud uses intelligent algorithms to select the optimal access point for you and does not provide fixed high-defense IP addresses. This type is recommended for users using domain name access.
    • IP Access: provides only IP port protection and fixed high-defense IP addresses.

    Region

    • Chinese mainland: applies to scenarios where service servers are deployed in the Chinese mainland.
    • Other: applies to scenarios where service servers are deployed in the Asia Pacific region.

    If your service servers are deployed in other regions, submit a service ticket for consultation.

    Line

    Only Anycast is supported outside the Chinese mainland.

    IP Type

    Only IPv4 addresses can be protected outside the Chinese mainland.

    Protection Package

    • Basic protection: provides advanced protection twice a month for services with low DDoS attack risks. For details about how to purchase additional protection times, see Purchasing Protection Times.
    • Unlimited protection: provides advanced protection for unlimited times, which is suitable for defending against services with high DDoS attack risks.

    Service Bandwidth

    Clean service bandwidth forwarded to the origin server from the AAD scrubbing center. The value ranges from 100 Mbit/s to 2000 Mbit/s.

    Collect statistics on the peak inbound and outbound traffic of all services to be connected to the AAD instance. The service bandwidth must be greater than both the peak inbound and outbound traffic.

    CAUTION:

    If the service bandwidth of your instance is lower than peak inbound or outbound traffic, packet loss may occur and your services may be affected. In this case, upgrade the service bandwidth in a timely manner. For details about upgrading specifications, see Modifying Instance Specifications.

    Assume that you need to connect two services (service A and service B) to Advanced Anti-DDoS. The peak traffic of service A does not exceed 50 Mbit/s, and that of service B does not exceed 70 Mbit/s. The total service traffic does not exceed 120 Mbit/s. In this case, you only need to ensure that the maximum service bandwidth of the purchased instance is greater than 120 Mbit/s.

    Elastic Bandwidth

    • Disabled
    • Daily 95th percentile billing (supported only outside the Chinese mainland): Traffic is averaged over 5-minute intervals throughout each calendar day. These 5-minute averages are sorted in descending order, the top 5% are discarded, and the highest remaining value is taken as the billing bandwidth.
    • Monthly 95th percentile billing: Traffic is averaged over 5-minute intervals throughout each calendar month. These 5-minute averages are sorted in descending order, the top 5% are discarded, and the highest remaining value is taken as the billing bandwidth.

    For details about elastic bandwidth billing, see How Is the Elastic Service Bandwidth Charged?

    Increase Elastic Bandwidth

    This parameter is available only if you enable elastic bandwidth billing.

    After you set this parameter, the actual available bandwidth is the current service bandwidth plus the value of Increase Elastic Bandwidth.

    Service QPS

    This parameter is available only when the access type is Website.

    The maximum number of requests an instance can handle without an attack.

    By default, 1,000 QPS is provided outside the Chinese mainland. You can pay to increase the QPS. Up to 100,000 QPS supported. If you need a larger QPS, submit a service ticket.

    Protected Domain Names

    This parameter is available only when the access type is Website.

    By default, 50 objects are supported. You can pay for more. Up to 200 objects are supported in the Chinese mainland.

    Forwarding Rules

    This parameter is available only when the access type is IP Access.

    By default, 5 objects are supported. You can pay for more. Up to 200 objects are supported in the Chinese mainland.

    Instance Name

    Name of the AAD instance.
    • The name can contain a maximum of 32 characters.
    • The name can contain only letters, numbers, underscores (_), and hyphens (-).

    Enterprise Project

    This parameter is only available if you have enabled the enterprise project function, or if your account is an enterprise account.

    To learn more, see Enabling Enterprise Center.

    NOTE:
    • Value default indicates the default enterprise project. Resources that are not allocated to any enterprise projects under your account are displayed in the default enterprise project.
    • The default option is available in the Enterprise Project drop-down list when you purchase AAD with a registered Huawei Cloud account.

    Required Duration

    Set the required duration.

    Auto Renewal

    • For monthly billing, your subscription will be renewed every month.
    • For yearly billing, your subscription will be renewed every year.

    Quantity

    Select the number of instances to be purchased. By default, a new user can purchase up to 20 instances. (An old user can purchase up to 10 instances by default.)

  5. (Optional) If IP Access is selected, read the note and select the check box under Note.
  6. Click Next.
  7. On the Details page, select the agreement and click Submit Order.

    For regions outside the Chinese mainland, the payment can be made only after the order is approved.

  8. Pay for the order on the payment page.

Connecting to Advanced Anti-DDoS

After purchasing an Advanced Anti-DDoS instance, you need to connect your services to the instance for protection to take effect. You can choose to connect your services by domain name or IP address.

  • Domain name connection: If your services use domain names licensed by ICP, you can connect the domain names to Advanced Anti-DDoS.
  • IP address connection: If your service does not have a domain name and is exposed directly through an EIP, you can configure forwarding rules to connect the service to Advanced Anti-DDoS.

Billing

An Advanced Anti-DDoS instance is billed based on its billing items. For details, see Advanced Anti-DDoS billing.

Unsubscription

When you purchase a yearly/monthly resource, such as a yearly/monthly Anti-DDoS instance, you make a one-time upfront payment. By default, the billing automatically stops when the purchased subscription expires. For details, see Stopping Billing.