tencent cloud

Documentação Anti-DDoS

DDoS Protection Capacity Description

Baixar
Modo Foco
Tamanho da Fonte
Última atualização: 2026-09-16 11:43:21
Traduzido por IA
Note:
Customers onboarded after September 10, 2026 are subject to the following instructions. If you are an existing Anti-DDoS Pro or Anti-DDoS Advanced customer, see historical documentation.
DDoS protection is an automatic DDoS attack mitigation service provided by Tencent Cloud for various cloud resources. After your business is onboarded to Tencent Cloud, some products provide standard protection (free basic protection) by default, which helps protect your business against small-scale traffic-based attacks in daily operations and takes effect without additional configuration. When your business faces higher-intensity attack risks or requires more fine-grained traffic control beyond basic protection (such as allowlists and rate limiting policies), you can purchase a DDoS Defender plan to obtain greater protection capacity and customized protection policies.

Protected Resource Types and Protection Levels

Supported Protected Resource Types

DDoS protection supports the following protected resource types. The protection scope of DDoS protection varies based on the network deployment architecture characteristics of different protected resource types. Among them, cloud resources (CVM, CLB, EIP, WAF, LH) support only L3/4 DDoS protection. For EdgeOne resources, domains support L3/4 and L7 DDoS (CC) protection, while L4 proxy instances and broadcast network segments support only L3/4 DDoS protection.
Protection Resource Type
Sub-resource Type
L3/4 DDoS protection
L7 DDoS protection (CC Protection)
Cloud Virtual Machine (CVM)
CVM with regular public IP addresses assigned
Supported
Not supported
Cloud Load Balancer (CLB)
Supported
Not supported
EIP
Supported
Not supported
WAF
-
Supported
Not supported
Lighthouse (LH)
-
Supported
Not supported
EdgeOne(EO)
Supported
Supported
EdgeOne(EO)
Supported
Not supported
EdgeOne(EO)
BGP Transit CIDRs
Supported
Not supported

Protection Level

For a single protected resource, you can configure one of the following protection levels: Standard Protection, Advanced Protection, or Ultimate Protection. DDoS protection provides different protection capacities for protected resources at different protection levels. For details, see the descriptions of each protected resource type below.
Protection Level
Activation Requirement
Applicable Protected Resource Type
Standard Protection
Provided by default free of charge with no activation conditions.
Resources with public network access capabilities on Tencent Cloud, such as CVM, CLB, EIP, WAF, LH, and EO
Advanced Protection
Bind any DDoS Defender plan.
CVM, CLB, EIP (regular BGP IPs and static single-line IPs), WAF, LH, and EO (domains and L4 proxy instances)
Ultimate Protection
Bind any DDoS Defender plan + any protection capability add-on(s).
EO domains and L4 proxy instances: can bind Chinese mainland protection-capacity add-on and Cross-regional protection-capacity add-on.
EO BGP transit CIDRs: can bind Global (excluding Mainland China) protection-capacity add-on.
Anti-DDoS EIP: can bind Chinese mainland protection-capacity add-on and Global (excluding Mainland China) protection-capacity add-on.

Infrastructure Layer DDoS Protection (Standard Protection Level)

Infrastructure-layer DDoS protection corresponds to the Standard Protection level and is a free basic protection service provided by Tencent Cloud by default for cloud resources with public network access. This protection is always enabled and runs automatically, requiring no purchase or configuration. It takes effect immediately after resources are onboarded to Tencent Cloud and automatically mitigates common infrastructure-layer (L3/4) DDoS attacks such as UDP Flood and SYN Flood.
Protection Resource Type
Standard Protection Capability
Tencent Cloud resources with public network access capabilities, such as CVM, CLB, EIP, WAF, and LH
L3/4 DDoS Protection protection of up to 2 Gbps1
EO resources (domains and L4 proxy instances)
EO provides default protection without committing resource capacity for DDoS Protection.2
Note:
Note 1
: Typically, DDoS Protection only mitigates traffic with attack characteristics and does not affect normal business traffic. In special cases (for example, when public network inbound traffic surges abnormally and may affect platform stability), the platform may take temporary measures (such as rate limiting or blocking) even if the traffic has no clear attack characteristics. Before taking such measures, the platform will notify you through the Message Center (via channels such as in-app messages, emails, and SMS). If you believe the traffic is normal business traffic, you can unblock it yourself through the unblocking center or contact us to request early unblocking.
Note 2
: "Not committing resource capacity for DDoS Protection" means that EO will use limited resources to protect your business while ensuring infrastructure stability, and does not guarantee a minimum protection bandwidth or protection effect.

Resource-Specific DDoS Protection (Advanced Protection and Ultimate Protection Levels)

Common Cloud Resources (CVM, CLB, EIP - Regular BGP IP address, EIP - Static Single-Line IP address, WAF, LH)

After you subscribe to a DDoS Defender plan, you can associate ordinary cloud resources (CVM, CLB, EIP - Regular BGP IP address, EIP - Static Single-line IP address, WAF, LH) with a protection instance at the Advanced Protection level. Protection capacity is provided based on the region where the resource resides. For details, see the following table:
Region
Protection Capability
Within the Chinese mainland
East China (Shanghai, Shanghai Finance, Nanjing)
Max 30 Gbps - 600 Gbps
North China (Beijing, Beijing Finance)
Max 120 Gbps - 480 Gbps
South China (Guangzhou)
Max 300 Gbps - 500 Gbps
Southwest China (Chongqing, Chengdu)
Max 15 Gbps - 350 Gbps
Northwest China (Xi'an)
Max 120 Gbps
Global (excluding Chinese mainland)
-
Limited protection capability (potentially below 10 Gbps)
Note:
DDoS protection provides best-effort protection for ordinary cloud resources at the Advanced Protection level (CVM, CLB, EIP - Regular BGP IP address, EIP - Static Single-line IP address, WAF, LH). Best-effort protection aims to successfully defend against every DDoS attack by integrating the capabilities of the current local cleansing centers to resist attacks with full effort. As Tencent Cloud's network capabilities continue to improve, best-effort protection also improves accordingly, without additional upgrade costs for you.
If DDoS attacks on your business affect the infrastructure of Tencent Cloud's DDoS protection mitigation centers, Tencent Cloud reserves the right to suppress traffic. Traffic suppression may have a certain impact on your business. For example, business access traffic may be rate-limited or even blocked.

Anti-DDoS EIP

After you subscribe to a DDoS Defender plan and a Chinese mainland protection-capacity add-on or a Global (excluding Mainland China) protection-capacity add-on, you can associate an Anti-DDoS EIP with a protection instance at the Ultimate Protection level to obtain the corresponding DDoS protection capacity.
Region
Protection Capability
Within the Chinese mainland
Beijing, Guangzhou, Shanghai
Max 600 Gbps - 1 Tbps
Global (excluding Chinese mainland)
Hong Kong (China), Singapore, Silicon Valley, Frankfurt, Tokyo, Virginia, Sao Paulo, Jakarta, Seoul, Riyadh
Up to Tbps-level protection (best-effort protection with Anycast joint defense)

EO Domains and L4 Proxy Instances

After you subscribe to a DDoS Defender plan, you can associate an EO domain or a L4 proxy instance with a protection instance at the Advanced Protection level. If you also subscribe to a Chinese mainland protection-capacity add-on, you can associate an EO domain or a L4 proxy instance with a protection instance at the Ultimate Protection level to obtain higher DDoS protection capacity.
Protected Area3
When Binding the Essential/Premium Plan
(Protection Level = Advanced Protection)
When Binding the Essential/Premium Plan + Mainland China Protection Capacity Add-on
(Protection Level = Ultimate Protection)
L3/4 DDoS Protection Capacity
Within the Chinese mainland
Can provide committed protection against DDoS attacks up to 200 Gbps
Scaled to provide committed protection against DDoS attacks up to 1 Tbps
Global (excluding Chinese mainland)
Highly elastic protection based on the Anycast architecture4
L7 DDoS Protection Capacity
Within the Chinese mainland
Can provide committed protection against DDoS attacks up to 300,000 QPS.
Scaled to provide committed protection against DDoS attacks up to 600,000 QPS.
Global (excluding Chinese mainland)
Highly elastic protection based on the Anycast architecture
Note:
Note 1: By default, automated mitigation is performed only on attack traffic exceeding 100 Mbps. (Attack traffic is calculated based on traffic statistics from a single region. The threshold is for reference only, and the actual protection prevails.)
Note 2: The actual protection capacity of DDoS protection is dynamically adjusted based on the actual infrastructure capacity and resource allocation. When the scale of a DDoS attack exceeds the protection capacity of EdgeOne infrastructure, EdgeOne will take mitigation measures including but not limited to traffic scheduling, traffic rate limiting, and access blocking to ensure infrastructure stability.
Note 3
: The protection region of DDoS protection is consistent with the acceleration region of the EO site or L4 proxy instance.
Note 4
: "Highly elastic protection based on the Anycast architecture" means that EO will provide protection based on the Anycast architecture by using DDoS traffic mitigation centers in regions worldwide (excluding the Chinese mainland). The maximum protection capacity can reach over 10 Tbps. For details on the latest protection bandwidth capacity, see the product introduction page.

EO Broadcast Network Segments

After you subscribe to a DDoS Defender plan and a Global (excluding Mainland China) protection-capacity add-on, you can associate an EO Anycast network segment with a protection instance at the Ultimate Protection level to obtain the corresponding DDoS protection capacity.
Region
Protection Capability
Within the Chinese mainland
Not applicable
Global (excluding Chinese mainland)
Tbps-level maximum

Ajuda e Suporte

Esta página foi útil?

comentários