Enabling Cloud Native Anti-DDoS for Targeted IP Addresses
Scenarios
If the basic protection on Huawei Cloud is insufficient to mitigate high-volume DDoS attacks, you can enable Cloud Native Anti-DDoS (CNAD) Advanced to safeguard your workloads.
CNAD directly enhances defense capabilities for native cloud resources, including Elastic Cloud Servers (ECS), Elastic Load Balancers (ELB), Web Application Firewalls (WAF), and Elastic IP addresses (EIPs). CNAD Advanced specifically protects Huawei Cloud EIPs. Through simple configuration, its advanced mitigation policies bind directly to your cloud assets, improving service security and reliability.
Prerequisites
- Ensure your account has a sufficient balance to prevent resource purchase failures.
- Ensure your account has been granted the required permissions. For details, see Creating a User and Granting the CNAD Access Permission.
- Create an ECS. For details, see section Purchasing an ECS.
- Purchase an EIP. For details, see Obtaining an EIP.
Resource and Cost Planning
| Resource | Resource Description | Quantity | Cost Description |
|---|---|---|---|
| Elastic Cloud Server (ECS) | Bind an EIP. | 1 | For details about the ECS billing modes and pricing, see ECS Billing. |
| CNAD Advanced | Defend against DDoS attacks. | 1 | For details about the CNAD Advanced billing modes and pricing, see AAD Billing. |
Step 1: Purchase a CNAD Instance
- Log in to the AAD console.
- In the upper right corner of the page, click Buy DDoS Mitigation.
- Set the purchase parameters as required, click Next, and complete the payment as prompted. The following uses the CNAD 2.0 instance type as an example.
Table 2 Parameter description Parameter
Example Value
Description
Instance Type
Cloud Native Protection 2.0
Type of the instance to be purchased. Choose an instance type as needed. Its value can be Cloud Native Protection 1.0 or Cloud Native Protection 2.0.
Specifications
Enterprise Edition
Edition to be purchased. It can only be configured for Cloud Native Protection 2.0 instances.
Region
Chinese mainland
- Chinese mainland: Applies to scenarios where business servers are deployed in the Chinese mainland (cross-region protection is supported). Only Dynamic BGP EIPs are supported.
- Other: Applies to scenarios where backend servers are deployed in the Asia-Pacific region (currently supporting Hong Kong). Only Premium BGP EIPs are supported.
Billing Mode for Public Network Lines
Pay-per-use
- Yearly/Monthly: Requires upfront payment for a specified subscription period. Charges are based on the allocated service bandwidth.
- Pay-per-use: Billed daily based on the actual volume of scrubbed traffic.
Service Bandwidth
100 Mbit/s
Service Bandwidth is the scrubbed, clean traffic routed to the origin server. It is recommended that the service bandwidth be greater than or equal to the egress bandwidth of the origin server. Otherwise, packet loss may occur or services may be affected.
This parameter is displayed only when you select Yearly/Monthly for Billing Mode for Public Network Lines.
Elastic Bandwidth
Monthly 95th percentile billing
Elastic service bandwidth is supported. When the service traffic exceeds the service bandwidth, the instance can be protected properly.
Metering Rule
Scrubbed traffic
Scrubbed traffic represents legitimate user traffic that remains after malicious or volumetric attack traffic is stripped away by the scrubbing center.
Protected IP Addresses
50
The Number of protected IP addresses specifies how many EIPs a single CNAD Advanced instance can safeguard. You are advised to evaluate this based on the total number of EIPs assigned to your cloud resources.
The number of protected IP addresses ranges from 50 to 500.
Instance Name
CNAD-test
Name of the instance to be purchased. This parameter is user-defined.
It can contain a maximum of 32 characters. Only letters, numbers, underscores (_), and hyphens (-) are allowed.
Enterprise Project
-
This parameter is displayed only when you use an enterprise account for purchase. Select a value based on the site requirements.
Required Duration
-
Required duration. Select a value based on your needs.
Quantity
-
Select the quantity based on your needs.
- After the payment is complete, return to the console and choose Cloud Native Anti-DDoS Advanced > Instances. The purchased instance is displayed in the list.
Step 2: Create a Protection Policy
CNAD Advanced supports multiple protection policies. The following uses a scrubbing policy as an example. For details about how to configure a protection policy, see Adding a Protection Policy.
- In the navigation pane on the left, choose Cloud Native Anti-DDoS Advanced > Protection Policies.
- Click Create Policy to create a policy.
Table 3 Parameter description Parameter
Example Value
Description
Policy Name
Policy01
Name of the protection policy. This parameter is user-defined.
Instance
Select the instance purchased in 3.
Target instance to be protected by the protection policy.
- In the row containing the created policy, click Configure Policy. The Policy Content page is displayed.
- Under Basic Protection, click Set. Figure 1 Basic protection
- In the Basic Protection Settings dialog box that is displayed, set the traffic scrubbing threshold. Figure 2 Basic protection settings
Table 4 Parameter description Parameter
Example Value
Description
Traffic Scrubbing Level
300 Mbit/s
When DDoS traffic directed at an IP address exceeds the configured scrubbing threshold, CNAD Advanced automatically triggers traffic scrubbing to filter out malicious requests.
You are advised to set this threshold as close as possible to your purchased bandwidth without exceeding it.
Defense Mode
Normal
Traffic scrubbing is automatically triggered when incoming traffic reaches the specified threshold according to the selected mode.
- Loose: Scrubbing is triggered when traffic reaches three times the scrubbing threshold.
- Normal: Scrubbing is triggered when traffic reaches twice the scrubbing threshold.
- Strict: Scrubbing is triggered as soon as traffic reaches the exact scrubbing threshold.
- Click OK.
Step 3: Add a Protected Object
- In the navigation pane on the left, choose Cloud Native Anti-DDoS Advanced > Instances.
- In the instance list, select the instance purchased in 3.
- Click Add Protected Objects. The Protected Objects page is displayed.
- Click Add Protected Object in the upper left corner.
Table 5 Parameter description Parameter
Description
Instance Name
Select the instance where you want to add protected objects.
Policy
Select the protection policy that you wish to apply to the protected objects.
Addition Method
- Batch Select: Search assets by type and select the desired items from the list.
- Batch Import: Enter IP addresses. Use commas (,), semicolons (;), or spaces to separate multiple IP addresses; or put each IP address on a separate line.
- Click OK. Return to the Protected Objects page and check whether the added protected objects are displayed in the list.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot