---
格式版本: 2
标题: "ESA Unlocked: Origin Protection - Stop Attackers from Bypassing Your CDN"
原文链接: "https://www.alibabacloud.com/blog/esa-unlocked-origin-protection---stop-attackers-from-bypassing-your-cdn_603533"
发布日期: "2026-09-07"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:configured_publication_date_rule"
发布时间证据: "alibaba-cloud-news-publication-date html:original: Bryan, Zhang September 7, 2026"
发布时间校准原因: "信源发布日期识别规则直接确认发布时间"
发布时间校准置信度: "high"
发布时间候选数量: 2
发布时间严格候选数量: 2
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-09-08T00:15:34+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-09-08T00:12:59+08:00"
入库时间: "2026-09-07T16:18:11.987Z"
来源平台: "固定入口"
搜索渠道: "fixed_url"
搜索词: "https://www.alibabacloud.com/blog"
匹配关键词:
  - "performance"
  - "latency"
相关厂家:
  - "阿里"
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 27
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "正文主线是阿里云ESA CDN源站保护的配置教程，介绍POP IP白名单、负载均衡ACL、防火墙及安全组操作，与超节点或机架级AI基础设施无直接关系。来源为厂商官方博客且链接官方文档，正文完整，但未给出发布日期、正式新品发布或GA里程碑；固定知识库也无可确认的历史新增对照。新增内容主要是成熟功能的运维步骤与示例场景，没有可核验的新机架技术或商业部署，命中“教程与运维选型”硬否决项。"
AI质检模型: "gpt-5.6-sol"
AI质检时间: "2026-09-08T00:18:23+08:00"
AI主题相关性: 0
AI来源权威性: 11
AI新颖性: 2
AI技术细节: 4
AI商业部署信号: 1
AI完整性: 9
AI评分提示词版本: "v17-精简生产版"
AI评分提示词SHA256: "48fb9777f386026761b4873eaff30807694fb11e9b352d7c69bf2dfde750cc7d"
AI评分知识库版本: "knowledge_base_v1-20260819+runtime.86"
AI评分知识库SHA256: "16cb084764aab70def3967e3f9c4438de00331dbb25a3163c5d909a9cb960893"
AI评分知识库检索词: "[\"阿里\",\"https://www.alibabacloud.com/blog\",\"RAS\",\"NPU\",\"ESA\",\"CDN\",\"WAF\",\"DDoS\",\"IP\",\"US\",\"IPs\",\"DNS\"]"
AI评分知识库命中: "[{\"id\":\"july-correct-0001\",\"title\":\"全球首颗2nm GPU来了！苏姿丰甩出“最强AI机架”，CPU性能干翻英伟达 - 智东西\",\"sourceType\":\"labeled_article\",\"time\":\"2026-07\",\"matchedTerms\":[\"阿里\",\"RAS\",\"NPU\",\"CDN\",\"IP\",\"US\"],\"rank\":-9.994463898360298},{\"id\":\"july-correct-0010\",\"title\":\"Schneider Electric and AMD release first Helios platform reference design to accelerate AI Factory deployment\",\"sourceType\":\"labeled_article\",\"time\":\"2026-07\",\"matchedTerms\":[\"RAS\",\"CDN\",\"IP\",\"US\"],\"rank\":-7.067619959044608},{\"id\":\"july-correct-0088\",\"title\":\"StrataCL: Fabric-Native Communication Library for Production Supernodes - 智源社区论文\",\"sourceType\":\"labeled_article\",\"time\":\"2026-07\",\"matchedTerms\":[\"NPU\",\"IP\",\"US\"],\"rank\":-6.55584927109134},{\"id\":\"july-correct-0111\",\"title\":\"StrataCL: Fabric-Native Communication Library for Production Supernodes\",\"sourceType\":\"labeled_article\",\"time\":\"2026-07\",\"matchedTerms\":[\"NPU\",\"IP\",\"US\"],\"rank\":-6.0702755486288105},{\"id\":\"historical-jun-025\",\"title\":\"英伟达、谷歌与国产超节点的三种网络选择\",\"sourceType\":\"curated_item\",\"time\":\"2026-06\",\"matchedTerms\":[\"NPU\",\"US\"],\"rank\":-6.049319221996111}]"
AI摘要: "阿里云ESA推出Origin Protection，通过仅在负载均衡、云防火墙、安全组或主机防火墙放行ESA节点IP，杜绝攻击者用泄露的源站IP绕过CDN直接攻击源站。启用前提是多级缓存架构，Pro及以上套餐支持。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T21:44:23.786Z"
采集批次: "2026年9月8日0点08分30秒"
采集批次ID: "20260908-000830-962"
去重键: "https://www.alibabacloud.com/blog/esa-unlocked-origin-protection---stop-attackers-from-bypassing-your-cdn_603533"
---

## Stop Attacks at the Door, Not at the Edge

Most ESA users invest heavily in edge security: WAF rules, DDoS mitigation, bot management. These work well - as long as traffic actually passes through ESA.

The problem is that attackers do not always enter through the front door. If your origin's IP address is discoverable, an attacker can send traffic directly to it, bypassing every security control configured at the edge. Your WAF, DDoS protection, and bot rules become irrelevant because the malicious traffic never touches them.

This is not a theoretical risk. Origin IPs leak through DNS history archives, SSL certificate transparency logs, forgotten subdomains, and misconfigured email headers. Once exposed, the address is out there forever.

Most mature teams already protect their origin with an entry layer - an [Alibaba Cloud Server Load Balancer (SLB)](https://www.alibabacloud.com/product/server-load-balancer), a WAF appliance, or both. The load balancer handles traffic distribution and health checks; the WAF filters malicious requests; the origin pool sits behind a controlled boundary. But if that entry layer still accepts traffic from anywhere on the internet, you have moved the front door, not locked it. The attacker simply targets the load balancer or WAF IP instead of a backend server IP.

Origin Protection closes this gap. It ensures that your origin entry layer - whether that is an ALB, CLB, NLB, WAF endpoint, or host firewall - only accepts traffic from ESA's Points of Presence (POPs). Everything else is dropped before it reaches your application.

## How Origin IPs Get Exposed

You might assume your origin IP is private. In practice, it has probably been public at least once. Here are the most common leak paths:

| Leak Source | How It Happens | Why It Persists |
| --- | --- | --- |
| **DNS history services** | SecurityTrails, ViewDNS.info, and similar tools archive DNS records indefinitely. | If your domain ever pointed directly to your origin - even for a day during setup - the record is stored forever. |
| **SSL certificate transparency logs** | Certificate Authorities log every issued certificate publicly. | Attackers scrape these logs, extract domain names, and resolve them to find origin IPs. |
| **Forgotten subdomains** | `dev.example.com`, `staging.example.com`, or old microsites bypass ESA. | These subdomains often point directly to the origin and are never cleaned up. |
| **Email headers** | Application servers send mail directly from the origin. | SMTP headers can expose the origin IP if not routed through a third-party mail service. |

Once an attacker has the origin or load-balancer IP, they can send DDoS traffic directly, probe for vulnerabilities without triggering WAF rules, exploit origin weaknesses that ESA would have blocked, or cause outages while ESA dashboards report that everything is fine. The result is the same: your edge security investment is undermined by a single exposed address.

## How Origin Protection Works

Origin Protection is conceptually simple: **allow inbound traffic only from ESA's POP IP addresses. Drop everything else.**

1. When you enable Origin Protection, ESA provides a consolidated list of POP IP addresses (IPv4 and IPv6).
2. You add those addresses to the IP allowlist on your origin entry layer - load balancer ACL, Cloud Firewall, security group, or host firewall.
3. All non-ESA traffic is rejected before it reaches your application.

Even if an attacker discovers your origin or load-balancer IP, their traffic cannot get through. The only path to your origin is through ESA, where WAF, DDoS, bot management, and custom rules all apply.

## Before You Begin: Tiered Cache

> **Prerequisite**: Origin Protection requires a caching architecture with **at least two tiers**. If your Tiered Cache policy is set to **Edge Tiered Cache** (single tier), you cannot enable Origin Protection - ESA's back-to-origin traffic would come from too many POP IPs to whitelist effectively.

To fix this, hover over the **Configure** button and click **Modify** in the tooltip to jump to the Tiered Cache page:

On the Tiered Cache page, click **Configure**, select a multi-tier caching architecture (Regional, Smart, or Cache Reserve), and then you can enable Origin Protection:

## Step 1: Enable Origin Protection in the ESA Console

The core of Origin Protection happens in the ESA console - you turn the feature on and copy the POP IP list, then apply that list wherever your origin lives.

1. In the **ESA console**, select **Websites**. In the **Website** column, click the target website.
2. In the left-side navigation pane, choose **Security > Origin Protection**.
3. On the Origin Protection page, click **Configure**.  
	![esa_op_enable_configure](./assets/img-29beb48f.png)
4. Turn on the **Status** switch. In the dialog box, select **I understand the risks** and click **OK**.  
	![esa_op_enable_status](./assets/img-f895e095.png)
5. After it is enabled, ESA displays the **consolidated origin-fetch IP list**. Click the copy icon to grab all IPv4 and IPv6 CIDR blocks.
6. ![esa_op_ip_list](./assets/img-32985359.png)
7. Add the IP ranges to your origin's allowlist. The exact place depends on your architecture - pick one of the four options below.

> **Important**: If you stop using ESA, you must manually remove these rules from your origin firewall to prevent access disruptions.

## Step 2: Where to Enforce the Whitelist

There is no single "correct" place to apply the list. Enforce it at the outermost layer that only ESA talks to - everything behind it then inherits the protection.

| Enforcement Point | Best For | Maintenance | IP-List Updates |
| --- | --- | --- | --- |
| **Load Balancer ACL** (ALB / CLB / NLB) | Origins behind an Alibaba Cloud SLB | Low - configured in the LB console | Manual |
| **Cloud Firewall** | Multi-origin, hybrid, or regulated environments | Low - fully managed address book | **Automatic** |
| **ECS Security Group** | Origins running directly on ECS, no LB in front | Medium | Manual (update Prefix List) |
| **Host firewall** (iptables, firewalld) | On-premise or non-Alibaba Cloud origins | High | Manual (re-apply rules) |

### Option A: Load Balancer ACL (ALB / CLB / NLB)

If your origin already sits behind an Alibaba Cloud load balancer, the load balancer's access control list is the cleanest enforcement point - no deeper firewall changes.

1. In the **ALB console**, go to **Access Control**, select your region, and click **Create ACL**. Name it `esa-origin-pops` and add the ESA POP CIDR blocks as ACL entries.
2. Go to **Instances**, select your ALB, open the **Listener** tab, click **Enable** under **Access Control**, choose **Whitelist**, select the `esa-origin-pops` ACL, then **Save**.

Whitelist mode means the listener allows access only from IP addresses in the ACL and denies all other requests. The same pattern applies to **CLB** (access-control whitelist) and **NLB** (ACL association).

### Option B: Cloud Firewall (Automated)

ESA is integrated with Cloud Firewall. If your origins are all on Alibaba Cloud and you use Cloud Firewall, enable Origin Protection and then turn on the **Auto-apply Latest Origin Fetch IP List** switch - Cloud Firewall then updates the origin-fetch IP information automatically.

Then create an inbound rule in **Cloud Firewall > Access Control > Internet Border Firewall**:

- **Source**: Address Book → **Cloud Service IP Address Book → ESA Back-to-Origin Address**
- **Destination**: Your origin IP or CIDR
- **Protocol**: TCP (or ANY) · **Port**: 443 and/or 80 · **Action**: Allow · **Priority**: Highest

Add a second rule to **deny** all other inbound traffic to those ports. When ESA adds or removes POPs, the address book updates on its own - no manual edits.

### Option C: ECS Security Group (Detailed)

If your origin is an ECS instance, use Prefix Lists so you can whitelist both IPv4 and IPv6 ranges in one object.

1. Go to the **ECS console > Prefix lists** page.![esa_op_ecs_prefix_page](./assets/img-e903128d.png)
2. Switch to the region where your origin instance is located.![esa_op_ecs_region](./assets/img-09cdd1ba.png)
3. Click **Create prefix list** for IPv4: name it `list-esa-ipv4`, **Address family** = IPv4, **Max entries** = 200, then paste the IPv4 CIDR blocks from the ESA list under **Prefix list entries** and click **OK**.![esa_op_ecs_prefix_v4](./assets/img-86361700.png)
4. Repeat for IPv6: name it `list-esa-ipv6`, **Address family** = IPv6, **Max entries** = 200, paste the IPv6 blocks, click **OK**.
5. Go to **ECS console > Security groups > Create security group**. Select the VPC, delete the default rules, click **Add Manually**, and set the **Authorization object** to the two prefix lists you created for the service ports (e.g., 443).![esa_op_ecs_sg_rules](./assets/img-7861da8c.png)
6. Go to **ECS console > Instances**, click the target instance ID, open the **Security groups** tab, and click **Change security groups**.![esa_op_ecs_change_sg](./assets/img-93180035.png)
7. Select only the security group you just created, then click **OK**.

### Option D: Host Firewall (iptables / firewalld)

For on-premise or non-Alibaba Cloud origins, apply the whitelist directly on the host.

**iptables:**

```bash
# Allow ESA POPs (example - use your actual list)
iptables -A INPUT -p tcp -s 47.245.0.0/16 --dport 443 -j ACCEPT
iptables -A INPUT -p tcp -s 8.209.0.0/16 --dport 443 -j ACCEPT
# Add all other CIDR blocks...

# Drop everything else
iptables -A INPUT -p tcp --dport 443 -j DROP
```

**firewalld:**

```bash
firewall-cmd --permanent --new-ipset=esa-pops --type=hash:net
firewall-cmd --permanent --ipset=esa-pops --add-entry=47.245.0.0/16
firewall-cmd --permanent --ipset=esa-pops --add-entry=8.209.0.0/16
# Add all entries...

firewall-cmd --permanent --add-rich-rule='rule source ipset=esa-pops port=443 protocol=tcp accept'
firewall-cmd --permanent --add-rich-rule='rule port=443 protocol=tcp drop'
firewall-cmd --reload
```

> **Important**: Test firewall rules in a staging environment before applying them to production. A misconfigured DROP rule can take your origin offline.

## Update the Origin-Fetch IP List

When ESA POP addresses change, ESA notifies you by internal message or email. You must update your origin firewall or security group so ESA can keep reaching your origin.

1. In the **ESA console**, open the target website and go to **Security > Origin Protection**.
2. In the Origin Protection section, add all new IP address ranges to your origin allowlist, then click **Review**.![esa_op_update_review](./assets/img-50b2a7b7.png)
3. In the **Review Latest IP List** panel, click **I Have Applied and Confirm to Enable the Latest IP List**, then **OK**.

> **Note**: The new list takes effect only after you confirm it. Until then, ESA keeps using the previously confirmed list. Confirm Cloud Firewall's auto-apply is on if you want this handled without manual steps.

## Disable Origin Protection

To prevent service interruptions, **first remove the IP allowlist from your origin firewall, then disable Origin Protection** - not the other way around.

1. In the ESA console, open **Security > Origin Protection**, click **Configure**, and turn off the **Status** switch. Select **I understand the risks** and click **OK**.![esa_op_disable](./assets/img-23c573c6.png)
2. The status changes to **Disabled**.

## Things to Watch Out For

### Functions and Pages Use Pre-Convergence IPs

The IP list from Origin Protection consists of **converged node IPs**, but `fetch()` calls from ESA Functions and Pages actually use **pre-convergence node IPs**. If a site called by `fetch()` does not have Origin Protection enabled, the real origin-pull IP of that `fetch()` is not in the converged list.

> **Heads-up**: If your Functions call a site that also sits behind ESA, enable Origin Protection on that target site. If it is not on ESA, add the Functions egress IP ranges to the origin allowlist.

### Too Many IP Ranges? Use Back-to-Origin Convergence

If Origin Protection returns more IP ranges than your origin can configure, ask your sales representative to enable **back-to-origin convergence** (Enterprise plan only). This further reduces the number of back-to-origin ranges.

> **Note**: Fewer ranges means fewer back-to-origin POPs, which can reduce access quality. Enable this feature with caution.

### Always Clean Up Before Leaving ESA

If you move traffic off ESA - for example, by pointing DNS directly to your origin - update or remove the allowlist **before** disabling ESA. If the entry layer still only accepts ESA POPs but ESA no longer proxies traffic, legitimate requests get dropped.

## Real-World Scenarios

### Finance: Compliance-Driven Origin Lockdown

A regional bank uses ESA to protect its online banking platform. Its PCI DSS framework requires that all inbound traffic to cardholder data environments be logged and filtered. Before Origin Protection, auditors flagged a gap: the origin remained accessible from untrusted networks. By whitelisting only ESA POPs at the load balancer, the bank demonstrated that 100% of inbound traffic was pre-filtered by ESA's security stack, and the audit finding closed immediately.

### Gaming: DDoS Last Line of Defense

A mobile gaming company runs its servers behind ESA and is a frequent DDoS target. During one attack, the attackers found the origin IP through a forgotten staging subdomain and sent a 50Gbps flood directly to the game server, bypassing ESA entirely. After implementing Origin Protection, a repeat attack hit the whitelist and was dropped instantly - the servers never saw it. ESA stops attacks at the edge; the whitelist catches anything aimed at the door.

### SaaS: Multi-Tenant Isolation

A B2B SaaS platform serves hundreds of customers from shared origin infrastructure, using ESA's WAF to enforce tenant-specific policies via the `Host` header. If an attacker finds the origin IP, they can craft the right header and reach any tenant directly. Origin Protection forces all traffic through ESA's policy engine, so tenant isolation cannot be circumvented at the origin.

## Plan Availability

| Plan | Origin Protection |
| --- | --- |
| Entrance (USD 0/month) | Not supported |
| Pro (USD 15/month) | Supported |
| Premium (USD 249/month) | Supported |
| Enterprise (custom) | Supported |

The Entrance plan does not include this feature, since POP IP whitelisting requires the multi-tier cache architecture that Pro and above provide.

## What's Next?

With Origin Protection configured, your origin is only accessible through ESA.

But what if your users are in mainland China and your origin is in the US or Europe? You then face a compliance puzzle (data residency) and a performance puzzle (cross-border latency). Cross-border acceleration solves both, and it is the topic of the next article in this series.

---

**Resources**:

- [Origin Protection Documentation (official console steps)](https://www.alibabacloud.com/help/en/edge-security-acceleration/esa/user-guide/origin-protection)
- [ESA Product Page](https://www.alibabacloud.com/product/edge-security-acceleration)
- [ALB Access Control (ACL)](https://www.alibabacloud.com/help/en/slb/application-load-balancer/network-acls)
- [ESA Address Book in Cloud Firewall](https://www.alibabacloud.com/help/en/edge-security-acceleration/esa/user-guide/reference-esa-address-book-in-cloud-firewall)

6. ![esa_op_ip_list](./assets/img-32985359.png)

1. Go to the **ECS console > Prefix lists** page.![esa_op_ecs_prefix_page](./assets/img-e903128d.png)

2. Switch to the region where your origin instance is located.![esa_op_ecs_region](./assets/img-09cdd1ba.png)

3. Click **Create prefix list** for IPv4: name it `list-esa-ipv4`, **Address family** = IPv4, **Max entries** = 200, then paste the IPv4 CIDR blocks from the ESA list under **Prefix list entries** and click **OK**.![esa_op_ecs_prefix_v4](./assets/img-86361700.png)

5. Go to **ECS console > Security groups > Create security group**. Select the VPC, delete the default rules, click **Add Manually**, and set the **Authorization object** to the two prefix lists you created for the service ports (e.g., 443).![esa_op_ecs_sg_rules](./assets/img-7861da8c.png)

6. Go to **ECS console > Instances**, click the target instance ID, open the **Security groups** tab, and click **Change security groups**.![esa_op_ecs_change_sg](./assets/img-93180035.png)

2. In the Origin Protection section, add all new IP address ranges to your origin allowlist, then click **Review**.![esa_op_update_review](./assets/img-50b2a7b7.png)

1. In the ESA console, open **Security > Origin Protection**, click **Configure**, and turn off the **Status** switch. Select **I understand the risks** and click **OK**.![esa_op_disable](./assets/img-23c573c6.png)
