This topic describes how to view the DDoS mitigation information about assets that belong to your Alibaba Cloud account and how to improve the DDoS mitigation capability of an asset. The assets are assigned public IP addresses.
Procedure
Log on to the Traffic Security console.
In the left-side navigation pane, click Assets.
On the Assets page, view the description of DDoS attack mitigation or DDoS mitigation information about each asset.
In the Description of DDoS Attack Mitigation section, you can perform the following operations:
Click Default Basic Protection Threshold to view default thresholds at which Anti-DDoS Origin Basic automatically triggers blackhole filtering in each region.
Click Blackhole Filtering to view the blackhole filtering policy of Alibaba Cloud.
Click Anti-DDoS Origin to go to the Handle Now panel. You can purchase Anti-DDoS Origin instances based on your business requirements.
You can perform the following steps to view the DDoS mitigation information about each asset:
Click the tab based on the type of assets that you want to view. For example, you can click ECS.
In the asset list, view the DDoS mitigation information about each asset.
Parameter
Description
IP
The public IP address of an asset.
You can click the public IP address of an asset to go to view the traffic trends of the asset.
IP Status
The security status of an asset.
Normal.
Cleaning. You can cancel traffic scrubbing. For more information, see Cancel traffic cleaning.
Black Hole Activated. You can view the blackhole filtering events. For more information, see View information about blackhole filtering events.
Mitigation Capabilities
The mitigation capability of an asset. The capability indicates the maximum bandwidth of DDoS attacks that can be mitigated.
If the bandwidth that is consumed by DDoS attacks exceeds the mitigation capability of the asset, blackhole filtering is triggered for the asset. For more information about how to improve the mitigation capability of an asset, see Step 4.
Traffic Scrubbing Threshold
The minimum bandwidth that must be reached before traffic scrubbing is triggered. The bandwidth is measured in Mbit/s and packets per second (PPS). For more information, see Configure a traffic scrubbing threshold.
Improve the mitigation capability of an asset.
If the mitigation capability of Anti-DDoS Origin Basic cannot meet your business requirements, you can use Anti-DDoS Origin of a paid edition, Anti-DDoS Pro, or Anti-DDoS Premium based on your business scenarios. For more information, see the Scenario-specific anti-DDoS solutions section of this topic.
Use an Anti-DDoS Origin of a paid edition to protect an asset
The following procedure describes how to use an Anti-DDoS Origin of a paid edition to protect an Elastic Compute Service ( ECS) instance. You can use this example as a reference for other types of assets.
Select the public IP address of the ECS instance for which you want to protect on the ECS tab and click Enable Anti-DDoS Origin.
In the Anti-DDoS Origin Instances of Paid Editions panel, find the required instance and click Add in the Actions column. In the message that appears, click OK.
NoteIf no Anti-DDoS Origin instances of paid editions exist, go to the buy page to purchase an instance. For more information, see Purchase an Anti-DDoS Origin instance of a paid edition.
Use Anti-DDoS Pro or Anti-DDoS Premium
In the left-side navigation pane, click Network Security. Then, click Anti-DDoS Proxy (Chinese Mainland) or Anti-DDoS Proxy (Outside Chinese Mainland) to go to the related console. For information about the configurations of Anti-DDoS Pro or Anti-DDoS Premium, see Protect website services.