Note:
Customers onboarded after September 10, 2026 are subject to the following instructions. If you are an existing Anti-DDoS Pro or Anti-DDoS Advanced customer, see historical documentation. DDoS protection is an automatic DDoS attack mitigation service provided by Tencent Cloud for various cloud resources. After your business is onboarded to Tencent Cloud, some products provide standard protection (free basic protection) by default, which helps protect your business against small-scale traffic-based attacks in daily operations and takes effect without additional configuration. When your business faces higher-intensity attack risks or requires more fine-grained traffic control beyond basic protection (such as allowlists and rate limiting policies), you can purchase a DDoS Defender plan to obtain greater protection capacity and customized protection policies.
Protected Resource Types and Protection Levels
Supported Protected Resource Types
DDoS protection supports the following protected resource types. The protection scope of DDoS protection varies based on the network deployment architecture characteristics of different protected resource types. Among them, cloud resources (CVM, CLB, EIP, WAF, LH) support only L3/4 DDoS protection. For EdgeOne resources, domains support L3/4 and L7 DDoS (CC) protection, while L4 proxy instances and broadcast network segments support only L3/4 DDoS protection.
|
Cloud Virtual Machine (CVM) | | Supported | Not supported |
Cloud Load Balancer (CLB) | | Supported | Not supported |
EIP | | Supported | Not supported |
WAF | - | Supported | Not supported |
Lighthouse (LH) | - | Supported | Not supported |
EdgeOne(EO) | | Supported | Supported |
EdgeOne(EO) | | Supported | Not supported |
EdgeOne(EO) | BGP Transit CIDRs | Supported | Not supported |
Protection Level
For a single protected resource, you can configure one of the following protection levels: Standard Protection, Advanced Protection, or Ultimate Protection. DDoS protection provides different protection capacities for protected resources at different protection levels. For details, see the descriptions of each protected resource type below.
|
Standard Protection | Provided by default free of charge with no activation conditions. | Resources with public network access capabilities on Tencent Cloud, such as CVM, CLB, EIP, WAF, LH, and EO |
Advanced Protection | Bind any DDoS Defender plan. | CVM, CLB, EIP (regular BGP IPs and static single-line IPs), WAF, LH, and EO (domains and L4 proxy instances) |
Ultimate Protection | Bind any DDoS Defender plan + any protection capability add-on(s). | EO domains and L4 proxy instances: can bind Chinese mainland protection-capacity add-on and Cross-regional protection-capacity add-on. EO BGP transit CIDRs: can bind Global (excluding Mainland China) protection-capacity add-on. Anti-DDoS EIP: can bind Chinese mainland protection-capacity add-on and Global (excluding Mainland China) protection-capacity add-on. |
Infrastructure Layer DDoS Protection (Standard Protection Level)
Infrastructure-layer DDoS protection corresponds to the Standard Protection level and is a free basic protection service provided by Tencent Cloud by default for cloud resources with public network access. This protection is always enabled and runs automatically, requiring no purchase or configuration. It takes effect immediately after resources are onboarded to Tencent Cloud and automatically mitigates common infrastructure-layer (L3/4) DDoS attacks such as UDP Flood and SYN Flood.
|
Tencent Cloud resources with public network access capabilities, such as CVM, CLB, EIP, WAF, and LH | L3/4 DDoS Protection protection of up to 2 Gbps1 |
EO resources (domains and L4 proxy instances) | EO provides default protection without committing resource capacity for DDoS Protection.2 |
Note:
Note 1
: Typically, DDoS Protection only mitigates traffic with attack characteristics and does not affect normal business traffic. In special cases (for example, when public network inbound traffic surges abnormally and may affect platform stability), the platform may take temporary measures (such as rate limiting or blocking) even if the traffic has no clear attack characteristics. Before taking such measures, the platform will notify you through the Message Center (via channels such as in-app messages, emails, and SMS). If you believe the traffic is normal business traffic, you can unblock it yourself through the unblocking center or contact us to request early unblocking.Note 2
: "Not committing resource capacity for DDoS Protection" means that EO will use limited resources to protect your business while ensuring infrastructure stability, and does not guarantee a minimum protection bandwidth or protection effect.Resource-Specific DDoS Protection (Advanced Protection and Ultimate Protection Levels)
Common Cloud Resources (CVM, CLB, EIP - Regular BGP IP address, EIP - Static Single-Line IP address, WAF, LH)
After you subscribe to a DDoS Defender plan, you can associate ordinary cloud resources (CVM, CLB, EIP - Regular BGP IP address, EIP - Static Single-line IP address, WAF, LH) with a protection instance at the Advanced Protection level. Protection capacity is provided based on the region where the resource resides. For details, see the following table:
|
Within the Chinese mainland | East China (Shanghai, Shanghai Finance, Nanjing) | Max 30 Gbps - 600 Gbps |
| North China (Beijing, Beijing Finance) | Max 120 Gbps - 480 Gbps |
| South China (Guangzhou) | Max 300 Gbps - 500 Gbps |
| Southwest China (Chongqing, Chengdu) | Max 15 Gbps - 350 Gbps |
| Northwest China (Xi'an) | Max 120 Gbps |
Global (excluding Chinese mainland) | - | Limited protection capability (potentially below 10 Gbps) |
Note:
DDoS protection provides best-effort protection for ordinary cloud resources at the Advanced Protection level (CVM, CLB, EIP - Regular BGP IP address, EIP - Static Single-line IP address, WAF, LH). Best-effort protection aims to successfully defend against every DDoS attack by integrating the capabilities of the current local cleansing centers to resist attacks with full effort. As Tencent Cloud's network capabilities continue to improve, best-effort protection also improves accordingly, without additional upgrade costs for you.
If DDoS attacks on your business affect the infrastructure of Tencent Cloud's DDoS protection mitigation centers, Tencent Cloud reserves the right to suppress traffic. Traffic suppression may have a certain impact on your business. For example, business access traffic may be rate-limited or even blocked.
Anti-DDoS EIP
After you subscribe to a DDoS Defender plan and a Chinese mainland protection-capacity add-on or a Global (excluding Mainland China) protection-capacity add-on, you can associate an Anti-DDoS EIP with a protection instance at the Ultimate Protection level to obtain the corresponding DDoS protection capacity.
|
Within the Chinese mainland | Beijing, Guangzhou, Shanghai | Max 600 Gbps - 1 Tbps |
Global (excluding Chinese mainland) | Hong Kong (China), Singapore, Silicon Valley, Frankfurt, Tokyo, Virginia, Sao Paulo, Jakarta, Seoul, Riyadh | Up to Tbps-level protection (best-effort protection with Anycast joint defense) |
EO Domains and L4 Proxy Instances
After you subscribe to a DDoS Defender plan, you can associate an EO domain or a L4 proxy instance with a protection instance at the Advanced Protection level. If you also subscribe to a Chinese mainland protection-capacity add-on, you can associate an EO domain or a L4 proxy instance with a protection instance at the Ultimate Protection level to obtain higher DDoS protection capacity.
|
|
|
|
|
L3/4 DDoS Protection Capacity | Within the Chinese mainland | Can provide committed protection against DDoS attacks up to 200 Gbps | Scaled to provide committed protection against DDoS attacks up to 1 Tbps |
| Global (excluding Chinese mainland) | Highly elastic protection based on the Anycast architecture4 |
|
L7 DDoS Protection Capacity | Within the Chinese mainland | Can provide committed protection against DDoS attacks up to 300,000 QPS. | Scaled to provide committed protection against DDoS attacks up to 600,000 QPS. |
| Global (excluding Chinese mainland) | Highly elastic protection based on the Anycast architecture |
|
Note:
Note 1: By default, automated mitigation is performed only on attack traffic exceeding 100 Mbps. (Attack traffic is calculated based on traffic statistics from a single region. The threshold is for reference only, and the actual protection prevails.)
Note 2: The actual protection capacity of DDoS protection is dynamically adjusted based on the actual infrastructure capacity and resource allocation. When the scale of a DDoS attack exceeds the protection capacity of EdgeOne infrastructure, EdgeOne will take mitigation measures including but not limited to traffic scheduling, traffic rate limiting, and access blocking to ensure infrastructure stability.
Note 3
: The protection region of DDoS protection is consistent with the acceleration region of the EO site or L4 proxy instance.Note 4
: "Highly elastic protection based on the Anycast architecture" means that EO will provide protection based on the Anycast architecture by using DDoS traffic mitigation centers in regions worldwide (excluding the Chinese mainland). The maximum protection capacity can reach over 10 Tbps. For details on the latest protection bandwidth capacity, see the product introduction page.EO Broadcast Network Segments
After you subscribe to a DDoS Defender plan and a Global (excluding Mainland China) protection-capacity add-on, you can associate an EO Anycast network segment with a protection instance at the Ultimate Protection level to obtain the corresponding DDoS protection capacity.
|
Within the Chinese mainland | Not applicable |
Global (excluding Chinese mainland) | Tbps-level maximum |