Anti-DDoS Proxy (Outside Chinese Mainland) supports Secure Chinese Mainland Acceleration (Sec-CMA) to accelerate access for users in the Chinese mainland to your services hosted outside the Chinese mainland, while providing protection against large-volume DDoS attacks. This topic describes how to add your services to Sec-CMA.
Overview
To address latency issues for users in the Chinese mainland accessing origin servers outside the Chinese mainland, Alibaba Cloud Anti-DDoS Proxy provides two acceleration solutions: Secure Chinese Mainland Acceleration (Sec-CMA) and Chinese Mainland Acceleration (CMA).
Secure Chinese Mainland Acceleration (Sec-CMA)
Description: With built-in DDoS scrubbing capabilities, Sec-CMA provides both access acceleration and advanced mitigation for all protected services. During an attack, Sec-CMA scrubs DDoS traffic inline without requiring a switch to the Anti-DDoS Proxy (Outside Chinese mainland) line. This ensures both robust protection and high-speed access.
ImportantTraffic from outside the Chinese mainland is not routed through Sec-CMA. If you need to serve users from outside the Chinese mainland, you must combine Sec-CMA with an Anti-DDoS Proxy (Outside Chinese Mainland) instance that uses the Insurance or Unlimited plan. You can then use Sec-Traffic Manager to configure traffic scheduling.
Instance types: Sec-CMA provides four types of instances. The following table compares these instances.
NoteNew purchases of Sec-CMA 1.0 are no longer supported. If you need to purchase this instance type, contact your presales account manager.
The features of Sec-CMA 2.0 (Insurance) and Sec-CMA 2.0 (Unlimited) have been consolidated into Sec-CMA 2.0. New purchases of these legacy instance types are not recommended.
Instance type
Mitigation capacity
Protected carrier lines
Advanced mitigation sessions
Purchase options
Secure Chinese Mainland Acceleration (Sec-CMA) 1.0
2 Tbps
China Telecom and China Unicom in the Chinese mainland
2 per calendar month
Yes. Purchase a global advanced mitigation session.
Secure Chinese Mainland Acceleration (Sec-CMA) 1.0 (Basic Edition)
2 Tbps
China Telecom and China Unicom in the Chinese mainland
1 per calendar month
Yes. Purchase a global advanced mitigation session.
Sec-CMA 2.0
Over 2 Tbps
China Telecom, China Unicom, and China Mobile in the Chinese mainland
You can select from the following options: No, 1, 2, or Unlimited sessions.
No. You must select a different specification at the time of purchase.
Sec-CMA 2.0 (Insurance)
Over 2 Tbps
China Telecom, China Unicom, and China Mobile in the Chinese mainland
2 per calendar month
No. You can upgrade to Sec-CMA 2.0 or Sec-CMA 2.0 (Unlimited).
Sec-CMA 2.0 (Unlimited)
Over 2 Tbps
China Telecom, China Unicom, and China Mobile in the Chinese mainland
Unlimited
Not applicable.
Chinese Mainland Acceleration (CMA)
CMA provides only access acceleration and does not have built-in DDoS scrubbing capabilities. It must be deployed together with an Anti-DDoS Proxy (Outside Chinese Mainland) instance that uses the Insurance or Unlimited plan. To mitigate an attack, you must switch traffic to the Anti-DDoS Proxy (Outside Chinese Mainland) line. Frequent attacks require frequent switching.
Limitations
Port Config does not support UDP ports.
Use Sec-CMA 2.0
Protect China Telecom, Unicom, and Mobile traffic
You can use a Sec-CMA 2.0 instance alone.
Log on to the Anti-DDoS Proxy console.
In the top menu bar at the upper left corner, choose the Outside Chinese Mainland region.
If you select this region, you are redirected to the Anti-DDoS Proxy (Outside Chinese Mainland) console.
Add your service to the Sec-CMA 2.0 instance.
Website Config: When adding the service, set Instance to the Sec-CMA 2.0 instance. For details, see Add a website.
Port Config: Configure port forwarding rules in the Sec-CMA 2.0 instance. For details, see Create a port forwarding rule.
Switch your service traffic to the Sec-CMA 2.0 instance to enable secure acceleration.
Website Config: Resolve your domain name to the CNAME record of Anti-DDoS Proxy. For details, see Use a CNAME or IP address to resolve a domain name to Anti-DDoS Proxy.
Port Config: Set the service address to the IP address of the Sec-CMA 2.0 instance.
Protect all carrier lines
You must combine Sec-CMA 2.0 with an Anti-DDoS Proxy (Outside Chinese Mainland) instance that uses the Insurance or Unlimited plan.
Log on to the Anti-DDoS Proxy console.
In the top menu bar at the upper left corner, choose the Outside Chinese Mainland region.
If you select this region, you are redirected to the Anti-DDoS Proxy (Outside Chinese Mainland) console.
Add your service to an Anti-DDoS Proxy (Outside Chinese Mainland) instance. This section uses an instance with the Unlimited plan as an example.
Website Config: When you add the service, set Instance to both the Anti-DDoS Proxy (Outside Chinese Mainland) Unlimited instance and the Sec-CMA 2.0 instance. For details, see Add a website.
Port Config: Configure port forwarding rules in both the Anti-DDoS Proxy (Outside Chinese Mainland) Unlimited instance and the Sec-CMA 2.0 instance. For details, see Create a port forwarding rule.
ImportantAutomatic scheduling relies on CNAME records and does not work if your service is accessed directly by its IP address.
Configure a secure acceleration rule in Sec-Traffic Manager.
On the page, click the General Interaction tab.
Click Add Rule, configure the rule, and then click OK.
Interaction Scenario: Select Sec-CMA.
Rule Name: Enter a custom name for the rule.
Sec-CMA: Select the Sec-CMA 2.0 instance.
Anti-DDoS Proxy (Outside Chinese Mainland): Select the Anti-DDoS Proxy (Outside Chinese Mainland) Unlimited instance.
After you create the scheduling rule, Sec-Traffic Manager generates a CNAME. Point the DNS record of your domain name to this CNAME to enable automatic scheduling:
Traffic from China Telecom, China Unicom, and China Mobile in the Chinese mainland is routed to the IP address of the Sec-CMA 2.0 instance.
Traffic from other carriers in the Chinese mainland and from outside the Chinese mainland is routed to the IP address of the Anti-DDoS Proxy (Outside Chinese Mainland) Unlimited instance.
NoteMake sure that all IP addresses you select in the scheduling nodes are configured to forward traffic to the origin server.
At your DNS provider, change the DNS record for the domain name.
Point the domain name to the CNAME from the scheduling rule to direct service traffic to Sec-Traffic Manager for automatic scheduling.
NoteAutomatic traffic scheduling requires using a CNAME record for domain name resolution.
Use Sec-CMA 1.0
Sec-CMA 1.0 does not protect traffic from China Mobile.
Protect China Telecom and China Unicom traffic
You can use a stand-alone Sec-CMA 1.0 instance.
Log on to the Anti-DDoS Proxy console.
In the top menu bar at the upper left corner, choose the Outside Chinese Mainland region.
If you select this region, you are redirected to the Anti-DDoS Proxy (Outside Chinese Mainland) console.
Add your service to the Sec-CMA 1.0 instance.
Website Config: When adding the service, set Instance to the Sec-CMA 1.0 instance. For details, see Add a website.
Port Config: Configure port forwarding rules in the Sec-CMA 1.0 instance. For details, see Create a port forwarding rule.
Switch your service traffic to the Sec-CMA 1.0 instance to enable secure acceleration.
Website Config: Resolve your domain name to the CNAME record of Anti-DDoS Proxy. For details, see Use a CNAME or IP address to resolve a domain name to Anti-DDoS Proxy.
Port Config: Set the service address to the IP address of the Sec-CMA 1.0 instance.
Protect all carrier lines
You must combine Sec-CMA 1.0 with an Anti-DDoS Proxy (Outside Chinese Mainland) instance that uses the Insurance or Unlimited plan.
Log on to the Anti-DDoS Proxy console.
In the top menu bar at the upper left corner, choose the Outside Chinese Mainland region.
If you select this region, you are redirected to the Anti-DDoS Proxy (Outside Chinese Mainland) console.
Add your service to an Anti-DDoS Proxy (Outside Chinese Mainland) instance. This section uses an instance with the Unlimited plan as an example.
Website Config: When you add the service, set Instance to both the Anti-DDoS Proxy (Outside Chinese Mainland) Unlimited instance and the Sec-CMA 1.0 instance. For details, see Add a website.
Port Config: Configure port forwarding rules in both the Anti-DDoS Proxy (Outside Chinese Mainland) Unlimited instance and the Sec-CMA 1.0 instance. For details, see Create a port forwarding rule.
ImportantAutomatic scheduling relies on CNAME records and does not work if your service is accessed directly by its IP address.
Configure a secure acceleration rule in Sec-Traffic Manager.
On the page, click the General Interaction tab.
Click Add Rule, configure the rule, and then click OK.
Interaction Scenario: Select Sec-CMA.
Rule Name: Enter a custom name for the rule.
Sec-CMA: Select the Sec-CMA 1.0 instance.
Anti-DDoS Proxy (Outside Chinese Mainland): Select the Anti-DDoS Proxy (Outside Chinese Mainland) Unlimited instance.
After you create the scheduling rule, Sec-Traffic Manager generates a CNAME. Point the DNS record of your domain name to this CNAME to enable automatic scheduling:
Traffic from China Telecom and China Unicom in the Chinese mainland is routed to the IP address of the Sec-CMA 1.0 instance.
Traffic from China Mobile in the Chinese mainland and all traffic from outside the Chinese mainland is routed to the IP address of the Anti-DDoS Proxy (Outside Chinese Mainland) Unlimited instance.
NoteMake sure that all IP addresses you select in the scheduling nodes are configured to forward traffic to the origin server.
At your DNS provider, change the DNS record for the domain name.
Point the domain name to the CNAME from the scheduling rule to direct service traffic to Sec-Traffic Manager for automatic scheduling.
NoteAutomatic traffic scheduling requires using a CNAME record for domain name resolution.