Blackholing
Understand the impact and response principles when an upstream network restricts a protected IP.
What Blackholing Means
When attack traffic threatens upstream network stability, a carrier or network service may restrict public access to the target IP. During this period, the service may remain unavailable through that protected IP even if the origin and origin rules are healthy.
How to Confirm It
- Review instance status, alerts, and attack trends.
- Test connectivity to the protected IP and the origin separately.
- Verify the origin protocol, port, and servers.
- Record the time, target IP, attack peak, and observed error.
- Use an available support channel to confirm whether upstream blackholing occurred and how recovery will proceed.
Response Principles
- Do not repeatedly change DNS or origin settings; this can obscure the difference between blackholing and a configuration fault.
- Do not expose a new origin IP before confirming that the attack has ended.
- Retain attack logs, monitoring data, and configuration history.
- Follow the operator's notice or current console guidance for recovery conditions and timing.
Conditions vary across networks and incidents. Do not schedule recovery based on historical thresholds or durations without current confirmation.
Reduce Recurrence Risk
- Confirm that protection-policy changes have been saved and deployed.
- Check whether DNS, historical records, or other services still expose the origin IP.
- Adjust access control and application-side rate limits based on attack characteristics.
- Prepare a tested rollback before changing production configuration.
