Key Concepts
Protection Instance
A DDoS protection instance is an independent resource in the console. It includes a protected IP, status, plan, specifications, validity period, policies, and origin configuration.
Protected IP
A protected IP is the public address used to route service traffic through the protection service. Do not continue exposing the origin IP after onboarding, or attackers may bypass the protected IP.
Origin
An origin is the server that runs your application. It must listen on the protocol and port configured in the origin rule and permit forwarding traffic from the protection service.
Origin Rule
An origin rule defines how traffic is forwarded from the protected IP. Fields vary by protocol and may include a proxy port, origin servers, domain, scheduling policy, and Proxy Protocol.
Protection Policy
A protection policy defines how instance traffic is handled. Templates provide preset configurations; access control manages allowlist, blocklist, filter, and location rules.
Traffic Metrics
The console may show:
- Peak received traffic: Highest incoming traffic in the selected period.
- Peak dropped traffic: Highest dropped traffic in the selected period.
- Peak received packet rate: Highest incoming packet rate in the selected period.
- Peak dropped packet rate: Highest dropped packet rate in the selected period.
Use the units and time range shown on the page.
Protection and Elastic Bandwidth
A plan may contain baseline protection bandwidth, elastic bandwidth, or other limits. Do not infer definitions, limits, or charges from field names alone; refer to the plan, order, and final bill.
Blackholing
Blackholing generally means that an upstream network restricts public access to a target IP to contain an attack. Thresholds, duration, and recovery procedures depend on the operator's notice or support confirmation.
