Help Center/ Anti-DDoS Service/ Best Practices/ Best Practices of Cloud Native Anti-DDoS (CNAD) Advanced/ Enabling Cloud Native Anti-DDoS for Targeted IP Addresses
Updated on 2026-08-26 GMT+08:00

Enabling Cloud Native Anti-DDoS for Targeted IP Addresses

Scenarios

If the basic protection on Huawei Cloud is insufficient to mitigate high-volume DDoS attacks, you can enable Cloud Native Anti-DDoS (CNAD) Advanced to safeguard your workloads.

CNAD directly enhances defense capabilities for native cloud resources, including Elastic Cloud Servers (ECS), Elastic Load Balancers (ELB), Web Application Firewalls (WAF), and Elastic IP addresses (EIPs). CNAD Advanced specifically protects Huawei Cloud EIPs. Through simple configuration, its advanced mitigation policies bind directly to your cloud assets, improving service security and reliability.

Prerequisites

Resource and Cost Planning

Table 1 Resource and cost planning

Resource

Resource Description

Quantity

Cost Description

Elastic Cloud Server (ECS)

Bind an EIP.

1

For details about the ECS billing modes and pricing, see ECS Billing.

CNAD Advanced

Defend against DDoS attacks.

1

For details about the CNAD Advanced billing modes and pricing, see AAD Billing.

Step 1: Purchase a CNAD Instance

  1. Log in to the AAD console.
  2. In the upper right corner of the page, click Buy DDoS Mitigation.
  3. Set the purchase parameters as required, click Next, and complete the payment as prompted. The following uses the CNAD 2.0 instance type as an example.
    Table 2 Parameter description

    Parameter

    Example Value

    Description

    Instance Type

    Cloud Native Protection 2.0

    Type of the instance to be purchased. Choose an instance type as needed. Its value can be Cloud Native Protection 1.0 or Cloud Native Protection 2.0.

    Specifications

    Enterprise Edition

    Edition to be purchased. It can only be configured for Cloud Native Protection 2.0 instances.

    Region

    Chinese mainland

    • Chinese mainland: Applies to scenarios where business servers are deployed in the Chinese mainland (cross-region protection is supported). Only Dynamic BGP EIPs are supported.
    • Other: Applies to scenarios where backend servers are deployed in the Asia-Pacific region (currently supporting Hong Kong). Only Premium BGP EIPs are supported.

    Billing Mode for Public Network Lines

    Pay-per-use

    • Yearly/Monthly: Requires upfront payment for a specified subscription period. Charges are based on the allocated service bandwidth.
    • Pay-per-use: Billed daily based on the actual volume of scrubbed traffic.

    Service Bandwidth

    100 Mbit/s

    Service Bandwidth is the scrubbed, clean traffic routed to the origin server. It is recommended that the service bandwidth be greater than or equal to the egress bandwidth of the origin server. Otherwise, packet loss may occur or services may be affected.

    This parameter is displayed only when you select Yearly/Monthly for Billing Mode for Public Network Lines.

    Elastic Bandwidth

    Monthly 95th percentile billing

    Elastic service bandwidth is supported. When the service traffic exceeds the service bandwidth, the instance can be protected properly.

    Metering Rule

    Scrubbed traffic

    Scrubbed traffic represents legitimate user traffic that remains after malicious or volumetric attack traffic is stripped away by the scrubbing center.

    Protected IP Addresses

    50

    The Number of protected IP addresses specifies how many EIPs a single CNAD Advanced instance can safeguard. You are advised to evaluate this based on the total number of EIPs assigned to your cloud resources.

    The number of protected IP addresses ranges from 50 to 500.

    Instance Name

    CNAD-test

    Name of the instance to be purchased. This parameter is user-defined.

    It can contain a maximum of 32 characters. Only letters, numbers, underscores (_), and hyphens (-) are allowed.

    Enterprise Project

    -

    This parameter is displayed only when you use an enterprise account for purchase. Select a value based on the site requirements.

    Required Duration

    -

    Required duration. Select a value based on your needs.

    Quantity

    -

    Select the quantity based on your needs.

  4. After the payment is complete, return to the console and choose Cloud Native Anti-DDoS Advanced > Instances. The purchased instance is displayed in the list.

Step 2: Create a Protection Policy

CNAD Advanced supports multiple protection policies. The following uses a scrubbing policy as an example. For details about how to configure a protection policy, see Adding a Protection Policy.

  1. In the navigation pane on the left, choose Cloud Native Anti-DDoS Advanced > Protection Policies.
  2. Click Create Policy to create a policy.
    Table 3 Parameter description

    Parameter

    Example Value

    Description

    Policy Name

    Policy01

    Name of the protection policy. This parameter is user-defined.

    Instance

    Select the instance purchased in 3.

    Target instance to be protected by the protection policy.

  3. In the row containing the created policy, click Configure Policy. The Policy Content page is displayed.
  4. Under Basic Protection, click Set.
    Figure 1 Basic protection
  5. In the Basic Protection Settings dialog box that is displayed, set the traffic scrubbing threshold.
    Figure 2 Basic protection settings
    Table 4 Parameter description

    Parameter

    Example Value

    Description

    Traffic Scrubbing Level

    300 Mbit/s

    When DDoS traffic directed at an IP address exceeds the configured scrubbing threshold, CNAD Advanced automatically triggers traffic scrubbing to filter out malicious requests.

    You are advised to set this threshold as close as possible to your purchased bandwidth without exceeding it.

    Defense Mode

    Normal

    Traffic scrubbing is automatically triggered when incoming traffic reaches the specified threshold according to the selected mode.

    • Loose: Scrubbing is triggered when traffic reaches three times the scrubbing threshold.
    • Normal: Scrubbing is triggered when traffic reaches twice the scrubbing threshold.
    • Strict: Scrubbing is triggered as soon as traffic reaches the exact scrubbing threshold.
  6. Click OK.

Step 3: Add a Protected Object

  1. In the navigation pane on the left, choose Cloud Native Anti-DDoS Advanced > Instances.
  2. In the instance list, select the instance purchased in 3.
  3. Click Add Protected Objects. The Protected Objects page is displayed.
  4. Click Add Protected Object in the upper left corner.
    Table 5 Parameter description

    Parameter

    Description

    Instance Name

    Select the instance where you want to add protected objects.

    Policy

    Select the protection policy that you wish to apply to the protected objects.

    Addition Method

    • Batch Select: Search assets by type and select the desired items from the list.
    • Batch Import: Enter IP addresses. Use commas (,), semicolons (;), or spaces to separate multiple IP addresses; or put each IP address on a separate line.
  5. Click OK. Return to the Protected Objects page and check whether the added protected objects are displayed in the list.