Multi-path failover associates multiple cloud resource IPs with one Anti-DDoS Proxy instance, distributing traffic across paths. When a path is attacked, only that path reroutes to Anti-DDoS Proxy for mitigation.
Cloud service interaction
Configure Sec-Traffic Manager.
For each cloud resource IP, add an Cloud Service Interaction rule and associate all rules with the same Anti-DDoS Proxy IP.
Modify DNS resolution.
Add three CNAME records under the same host record. Set each record value to the CNAME from the corresponding cloud service interaction rule in Step 1. Modify the CNAME record to onboard traffic to Sec-Traffic Manager.
On a DNS checker website (for example, ChinaZ), verify that the CNAME records from Step 2 have propagated.
Tiered protection
Configure Anti-DDoS Native (Enterprise).
Add multiple Objects for protection in Anti-DDoS Native (Enterprise).
Configure Sec-Traffic Manager.
For each object for protection from Step 1, add a Tiered Protection rule and associate all rules with the same Anti-DDoS Proxy IP.
Modify DNS resolution.
Add three CNAME records under the same host record. Set each record value to the CNAME from the corresponding tiered protection rule in Step 2. Modify the CNAME record to onboard traffic to Sec-Traffic Manager.
On a DNS checker website (for example, ChinaZ), verify that the CNAME records from Step 3 have propagated.