All Products
Search
Document Center

Anti-DDoS:Network acceleration

Last Updated:Aug 28, 2026

Network acceleration integrates an Anti-DDoS Proxy (Outside Chinese Mainland) instance (Insurance or Unlimited plan) with a Chinese Mainland Acceleration (CMA) instance. During normal operation, traffic is routed through the CMA instance for faster access. When an attack is detected, traffic automatically switches to the Anti-DDoS Proxy (Outside Chinese Mainland) instance for scrubbing, and only legitimate traffic is forwarded to your origin server.

Prerequisites

  • You have purchased a Chinese Mainland Acceleration (CMA) instance. For more information, see Purchase an Anti-DDoS Proxy instance.

  • You have purchased an Insurance plan or Unlimited plan instance of Anti-DDoS Proxy (Outside Chinese Mainland). For more information, see Purchase an Anti-DDoS Proxy instance.

    Important

    The service bandwidth, Queries Per Second (QPS), and other specifications of the Insurance or Unlimited plan instance must meet your typical business protection needs.

  • You have added your website to Anti-DDoS Proxy (Outside Chinese Mainland) for protection and associated the website with an Insurance or Unlimited plan instance and a CMA instance. For more information, see Add a website configuration.

  • You have verified that both the Insurance or Unlimited plan instance and the CMA instance can forward traffic correctly. For more information, see Verify that forwarding configurations take effect on your local computer.

Background information

Network acceleration is designed for scenarios where your origin server is outside the Chinese mainland but your primary user base is inside.

With CMA enabled and a network acceleration rule configured, users in the Chinese mainland access your server through the CMA instance during normal operation. When an attack occurs, traffic is rerouted to the Insurance or Unlimited plan instance for scrubbing.

The following figure shows how network acceleration works. For more information, see Configure Chinese Mainland Acceleration (CMA) for Anti-DDoS Proxy (Outside Chinese Mainland).

Add a network acceleration rule

  1. Log on to the Anti-DDoS Proxy console.

  2. In the top menu bar at the upper left corner, choose the Outside Chinese Mainland region.

    If you select this region, you are redirected to the Anti-DDoS Proxy (Outside Chinese Mainland) console.

  3. In the left-side navigation pane, choose Onboarding > Sec-Traffic Manager.

  4. On the General Interaction tab, click Add Rule, configure the interaction rule, and then click OK.

    Parameter

    Description

    Interaction Scenario

    Select Network Acceleration.

    Rule Name

    The rule name must contain only letters, digits, and underscores (_) and be no more than 128 characters long.

    Anti-DDoS IP Address

    Select the Anti-DDoS Proxy instance to configure filter interaction.

    CMA IP Address

    Select the CMA IP address for this rule.

    switchback time

    The wait time after an attack stops before traffic switches back to the CMA instance. Options:

    • Automatic Switchback: Traffic automatically switches back to the CMA instance a set time after the attack ends. Specify a duration from 10 to 60 minutes.

    • Custom: Set a custom switchback time. The allowed time range is 30 to 120 minutes. To avoid frequent switching, we recommend that you set this value to 60 minutes.

  5. Modify the DNS record configuration: To ensure that the interaction rules for Sec-Traffic Manager take effect, modify the DNS record configuration as prompted on the page.

    1. Validate in a local environment: Before you change the public DNS records, we strongly recommend that you first simulate the record change by modifying the hosts file on your local computer. This validates the scheduling rules and helps avoid incompatibility issues caused by inconsistent back-to-origin policies. A typical risk scenario is as follows:

      Note

      For instructions on how to validate scheduling rules, see Locally validate your forwarding configuration.

      • Scenario: Interaction between CDN, Anti-DDoS, and OSS

      • Potential conflict:

        • CDN: Allows you to customize the Configure default origin host to correctly identify OSS buckets.

        • Anti-DDoS: Does not typically support modifying the origin HOST. By default, it uses the Host header from the request.

      • Symptom: When an attack triggers an automatic switchover to Anti-DDoS, the Host header forwarded by Anti-DDoS does not match the one that OSS expects. As a result, OSS cannot recognize normal traffic, leading to service access failures.

    2. Modify DNS records: After you complete and confirm the local validation, modify the DNS records for the domain name. Point the records to the CNAME address provided by Sec-Traffic Manager. Follow the instructions for your domain name registrar:

      Domain registration platform

      Instructions

      Alibaba Cloud

      Log on to the Alibaba Cloud DNS console to make the changes.

      Third-party platform

      Log on to your third-party registrar's management platform to modify the DNS records for the domain name.

    3. Verify the result: After you modify the DNS records, use a browser to test whether the website is accessible.

      Note

Traffic switching

  • Once the rule is configured, traffic from users in the Chinese mainland is routed through the CMA instance.

  • When an attack is detected, traffic is automatically rerouted to the Insurance or Unlimited plan of Anti-DDoS Proxy (Outside Chinese Mainland) for scrubbing, which then forwards only legitimate traffic to your origin server.

  • After an attack ends, the system waits for the configured switchback time before automatically routing traffic back through the CMA instance.

You can also manually switch traffic to the Insurance or Unlimited plan of Anti-DDoS Proxy (Outside Chinese Mainland) or switch it back to the CMA instance.

Actions

Description

Switch to Anti-DDoS

  1. On the General Interaction tab of the Sec-Traffic Manager page, locate the entry for which the Interaction Scenario is Network Acceleration and a DDoS mitigation rule has not been automatically triggered (indicated by the green icon under Resource for Interaction).

  2. In the Actions column, click Switch to Anti-DDoS to manually switch traffic to Anti-DDoS Proxy for scrubbing.

Switchback

  1. On the Sec-Traffic Manager page, on the General Interaction tab, find the rule where the Interaction Scenario is Network Acceleration and the service traffic is scrubbed by an Anti-DDoS scrubbing rule (a green green icon is displayed under the instance).

  2. In the Actions column, click Switchback and then click OK in the confirmation dialog box to route traffic back to the CMA instance.

Other operations

After you add a General Interaction rule, perform the following operations on it in the rule list.

Operation

Description

Edit

Edit the General Interaction rule. You can modify all parameter settings except for Interaction Scenario and Rule Name.

Delete

Delete the General Interaction rule.

Warning

Before you delete an interaction rule, ensure that the DNS record for your website's domain name does not point to the Sec-Traffic Manager CNAME. Otherwise, your website will become inaccessible after the rule is deleted.