Updated on 2026-07-06 GMT+08:00

Adding a Protected Object

After enabling CNAD, you need to add public IP addresses on Huawei Cloud as protected objects to enable protection for these public IP addresses.

Limitations and Constraints

  • The added protected objects (such as ECS, ELB, WAF, and EIP) must be in the same region as the region of the purchased CNAD instance.
  • Unlimited Protection Advanced Edition can protect only dedicated EIPs. Cloud Native Anti-DDoS 2.0 can protect both common and dedicated EIPs.
  • Cloud Native Anti-DDoS 2.0 outside the Chinese mainland can only protect premium BGP IP addresses 49.0.236.0/22, 49.0.234.0/23, and 49.0.233.0/24.

Prerequisites

A protection policy has been created. For details, see Adding a Protection Policy.

Adding Protected Objects to an Instance

  1. Log in to the AAD console.
  2. In the navigation tree on the left, choose Cloud Native Anti-DDoS Advanced > Protected Objects. The Protected Objects page is displayed.

    Figure 1 Protected objects

  3. Click Add Protected Object.
  4. On the Add Protected Objects page, add the IP addresses to be protected.

    Figure 2 Adding a Protected Object
    Table 1 Parameter description

    Parameter

    Description

    Instance Name

    Select the instance where you want to add protected objects.

    Protection Policy

    Select the protection policy that you wish to apply to the protected objects.

    Addition Method

    • Batch Select: Search for assets by asset type in the search bar, and select the desired assets to add.
    • Batch Import: Manually enter IP addresses. Use commas (,), semicolons (;), spaces, or line breaks to separate multiple IP addresses.

  5. Click OK.

Related Operations

  • After adding protected objects, you can regularly monitor their protection status and attack statistics. This allows you to promptly adjust protection policies to enhance service security. For details, see Viewing Details about a Protected Object.
  • You must select a protection policy for each protected object to enable CNAD Advanced DDoS mitigation. For details, see Selecting a Protection Policy for a Protected Object.
  • If you need to synchronize your EIP list with other security management systems or perform offline analysis, you can export the protected object data. For details, see Exporting Protected Objects.
  • If a protected object no longer requires CNAD Advanced protection, you can delete it from your CNAD Advanced instance. For details, see Deleting a Protected Object.