Network acceleration integrates an Anti-DDoS Proxy (Outside Chinese Mainland) instance (Insurance or Unlimited plan) with a Chinese Mainland Acceleration (CMA) instance. During normal operation, traffic is routed through the CMA instance for faster access. When an attack is detected, traffic automatically switches to the Anti-DDoS Proxy (Outside Chinese Mainland) instance for scrubbing, and only legitimate traffic is forwarded to your origin server.
Prerequisites
You have purchased a Chinese Mainland Acceleration (CMA) instance. For more information, see Purchase an Anti-DDoS Proxy instance.
You have purchased an Insurance plan or Unlimited plan instance of Anti-DDoS Proxy (Outside Chinese Mainland). For more information, see Purchase an Anti-DDoS Proxy instance.
ImportantThe service bandwidth, Queries Per Second (QPS), and other specifications of the Insurance or Unlimited plan instance must meet your typical business protection needs.
You have added your website to Anti-DDoS Proxy (Outside Chinese Mainland) for protection and associated the website with an Insurance or Unlimited plan instance and a CMA instance. For more information, see Add a website configuration.
You have verified that both the Insurance or Unlimited plan instance and the CMA instance can forward traffic correctly. For more information, see Verify that forwarding configurations take effect on your local computer.
Background information
Network acceleration is designed for scenarios where your origin server is outside the Chinese mainland but your primary user base is inside.
With CMA enabled and a network acceleration rule configured, users in the Chinese mainland access your server through the CMA instance during normal operation. When an attack occurs, traffic is rerouted to the Insurance or Unlimited plan instance for scrubbing.
The following figure shows how network acceleration works. For more information, see Configure Chinese Mainland Acceleration (CMA) for Anti-DDoS Proxy (Outside Chinese Mainland).
Add a network acceleration rule
Log on to the Anti-DDoS Proxy console.
In the top menu bar at the upper left corner, choose the Outside Chinese Mainland region.
If you select this region, you are redirected to the Anti-DDoS Proxy (Outside Chinese Mainland) console.
In the left-side navigation pane, choose .
On the General Interaction tab, click Add Rule, configure the interaction rule, and then click OK.
Parameter
Description
Interaction Scenario
Select Network Acceleration.
Rule Name
The rule name must contain only letters, digits, and underscores (_) and be no more than 128 characters long.
Anti-DDoS IP Address
Select the Anti-DDoS Proxy instance to configure filter interaction.
CMA IP Address
Select the CMA IP address for this rule.
switchback time
The wait time after an attack stops before traffic switches back to the CMA instance. Options:
Automatic Switchback: Traffic automatically switches back to the CMA instance a set time after the attack ends. Specify a duration from 10 to 60 minutes.
Custom: Set a custom switchback time. The allowed time range is 30 to 120 minutes. To avoid frequent switching, we recommend that you set this value to 60 minutes.
Modify the DNS record configuration: To ensure that the interaction rules for Sec-Traffic Manager take effect, modify the DNS record configuration as prompted on the page.
Validate in a local environment: Before you change the public DNS records, we strongly recommend that you first simulate the record change by modifying the
hostsfile on your local computer. This validates the scheduling rules and helps avoid incompatibility issues caused by inconsistent back-to-origin policies. A typical risk scenario is as follows:NoteFor instructions on how to validate scheduling rules, see Locally validate your forwarding configuration.
Scenario: Interaction between CDN, Anti-DDoS, and OSS
Potential conflict:
CDN: Allows you to customize the Configure default origin host to correctly identify OSS buckets.
Anti-DDoS: Does not typically support modifying the origin HOST. By default, it uses the Host header from the request.
Symptom: When an attack triggers an automatic switchover to Anti-DDoS, the Host header forwarded by Anti-DDoS does not match the one that OSS expects. As a result, OSS cannot recognize normal traffic, leading to service access failures.
Modify DNS records: After you complete and confirm the local validation, modify the DNS records for the domain name. Point the records to the CNAME address provided by Sec-Traffic Manager. Follow the instructions for your domain name registrar:
Domain registration platform
Instructions
Alibaba Cloud
Log on to the Alibaba Cloud DNS console to make the changes.
Third-party platform
Log on to your third-party registrar's management platform to modify the DNS records for the domain name.
Verify the result: After you modify the DNS records, use a browser to test whether the website is accessible.
NoteAfter you modify the records, the rule may take some time to take full effect due to the global DNS Time to Live (TTL). For detailed instructions, see Modify a CNAME record for Traffic Scheduler.
If you have problems accessing the website, troubleshoot the issue first. For specific instructions, see Troubleshoot slow response, high latency, and access failures for services protected by Anti-DDoS Proxy.
Traffic switching
Once the rule is configured, traffic from users in the Chinese mainland is routed through the CMA instance.
When an attack is detected, traffic is automatically rerouted to the Insurance or Unlimited plan of Anti-DDoS Proxy (Outside Chinese Mainland) for scrubbing, which then forwards only legitimate traffic to your origin server.
After an attack ends, the system waits for the configured switchback time before automatically routing traffic back through the CMA instance.
You can also manually switch traffic to the Insurance or Unlimited plan of Anti-DDoS Proxy (Outside Chinese Mainland) or switch it back to the CMA instance.
Actions | Description |
Switch to Anti-DDoS |
|
Switchback |
|
Other operations
After you add a General Interaction rule, perform the following operations on it in the rule list.
Operation | Description |
Edit | Edit the General Interaction rule. You can modify all parameter settings except for Interaction Scenario and Rule Name. |
Delete | Delete the General Interaction rule. Warning Before you delete an interaction rule, ensure that the DNS record for your website's domain name does not point to the Sec-Traffic Manager CNAME. Otherwise, your website will become inaccessible after the rule is deleted. |
icon under Resource for Interaction).