FAQ
Does your ESA plan include free DDoS protection?
Yes. All ESA plans include basic DDoS protection (platform-level protection) by default, so you do not need to purchase it separately.
Basic DDoS protection mitigates DDoS attacks of up to 10 Gbps. This capacity is a reference value, not a guaranteed protection threshold. When an attack occurs, ESA performs best-effort mitigation on the edge nodes. If the attack keeps growing, acceleration quality may be affected. Basic DDoS protection does not include a commitment on how long it takes to eliminate the impact of an attack.
If your site faces a high risk of DDoS attacks or you want more reliable protection, contact us to upgrade to the Enterprise plan.
Are you charged for the traffic generated by DDoS attacks?
Whether you are charged depends on the type of DDoS protection that mitigates the attack traffic.
The following traffic is not billed and does not consume your plan quota:
L3/L4 attack traffic blocked by basic DDoS protection
HTTP requests blocked by deep learning and other protection mechanisms
If you purchase Best-effort DDoS protection, the attack traffic is counted as elastic protection bandwidth based on the protection specification that you purchased, and is billed on a pay-as-you-go basis.
Can you use DDoS protection with non-Alibaba Cloud servers?
Yes. DDoS protection in ESA supports any server that has a public IP address reachable over the public network routes of the Alibaba Cloud network.
Are the DDoS protection node IP addresses of your ESA Enterprise plan fixed?
No. The DDoS protection node IP addresses of the ESA Enterprise plan are not fixed. The system dynamically adjusts node scheduling based on the attack conditions. During an attack, traffic may be rerouted to a scrubbing center, so the protection node IP address may change. If your service depends on a fixed IP address, for example, for a firewall allowlist, take this behavior into account and adapt your configuration accordingly.
Can you bind multiple elastic IP addresses (EIPs) to ESA in rotation to avoid black holes?
No. ESA triggers black holes at the site level rather than at the EIP level, so switching EIPs cannot help you avoid black holes. For higher DDoS mitigation capability, upgrade to the Enterprise plan or purchase an additional DDoS protection instance.
After ESA enters a black hole, is DDoS protection on the EIP of your origin server still effective?
After ESA enters a black hole, all access traffic is dropped on the edge nodes and attack traffic does not reach the origin server. As a result, the DDoS protection configured on the EIP of the origin server is not triggered during this period.
After the black hole is lifted and traffic forwarding returns to normal, DDoS protection on the EIP of the origin server takes effect again. To improve DDoS mitigation capability and reduce how often black holes are triggered, upgrade to the Enterprise plan or purchase an additional DDoS protection instance.