All Products
Search
Document Center

Anti-DDoS:Interaction between Anti-DDoS Proxy and CDN or DCDN

Last Updated:Jun 02, 2026

Integrate Anti-DDoS Proxy with CDN or DCDN so that traffic uses acceleration nodes during normal operations and automatically switches to Anti-DDoS Proxy for scrubbing during attacks.

Feature overview

Alibaba Cloud provides two solutions for services that need both acceleration and DDoS protection:

  • Solution 1: DDoS Mitigation at the Edge for DCDN (Recommended)

    Add a domain to DCDN, then enable DDoS Mitigation at the Edge in the DCDN console with one click. No Anti-DDoS Proxy configuration is required. Protection Configuration.

    Note

    Only DCDN supports DDoS Mitigation at the Edge. To use this feature with CDN, migrate your domain to DCDN first. Upgrade a CDN domain name to DCDN.

  • Solution 2: Anti-DDoS Proxy interaction with CDN or DCDN

    This topic covers this solution. Anti-DDoS scrubs attack traffic and forwards clean traffic directly to the origin server. Configure your domain in both the acceleration service and Anti-DDoS Proxy, then set up the interaction in the Traffic Scheduler.

With the interaction feature, scrubbed traffic goes directly to the origin server. With DDoS Mitigation at the Edge, scrubbed traffic goes to DCDN, maintaining acceleration during attacks.

image

Precautions

  • If your bandwidth exceeds 3 Gbps or QPS exceeds 10,000, contact your account manager for evaluation before using this feature.

  • For websites attacked more than three times a week, use Anti-DDoS Proxy alone to avoid disruptions from frequent traffic switching.

  • The interaction feature supports both IPv4 and IPv6 Anti-DDoS IPs.

  • When traffic switches to Anti-DDoS Proxy during an attack, the DNS TTL may affect activation time.

  • Before using this feature, verify that your domain is not in a Sandbox state in the acceleration service. If it is, contact your account manager to remove it before configuring DDoS protection.

Supported Anti-DDoS instance types

Anti-DDoS Proxy (Chinese Mainland) Professional or Advanced Plan, and Anti-DDoS Proxy (Outside Mainland China) Insurance or Unlimited Plan. All instances must use the Enhanced Function plan.

Prerequisites

Procedure

  1. Log on to the Anti-DDoS Proxy console.

  2. In the top navigation bar, select the region of your instance.

    • Anti-DDoS Proxy (Chinese Mainland): Choose the Chinese Mainland region.

    • Anti-DDoS Proxy (Outside Chinese Mainland): Choose the Outside Chinese Mainland region.

  3. In the left-side navigation pane, choose Onboarding > Sec-Traffic Manager and click the CDN/DCDN Interaction tab.

    Note

    If you are using the interaction feature for the first time, click Authorize Now and follow the on-screen instructions to authorize Anti-DDoS Proxy to access the acceleration service.

  4. Find the domain that you want to manage and click Actions in the Actions column. In the Create Interaction Rule panel, complete the configuration and click Next.

    Parameter

    Description

    Anti-DDoS Proxy Instance

    Select the Anti-DDoS Proxy instance to integrate with the acceleration service.

    Note
    • If the message To enable CDN interaction, you must use an instance of the Enhanced function plan. appears, follow the instructions to upgrade your instance.

    • If the message No instance is selected. appears, first add your domain to an Anti-DDoS Proxy instance. Add a website.

    Resource for Interaction

    The associated resource is automatically selected.

    If the domain has not been added to an acceleration service, add it and wait about 10 minutes before configuring the interaction. Add a domain name to CDN or Add a domain name to DCDN.

    Access QPS

    Set the minimum QPS threshold to trigger a switch to Anti-DDoS Proxy.

    For more information about traffic switching, see Traffic switching.

    Note

    Set the threshold to at least 2-3 times your historical peak QPS. Minimum recommended value: 500, even for low-traffic websites.

  5. Verify that the traffic scheduling rule works by modifying your local hosts file. This prevents compatibility issues from inconsistent back-to-origin policies. Locally verify the forwarding configuration.

    For example, if CDN interacts with Anti-DDoS and the origin is an OSS bucket: CDN allows modifying the back-to-origin HOST header, but Anti-DDoS does not. If traffic switches to Anti-DDoS during an attack, the OSS bucket may reject the requests, causing a service failure.

  6. Point your domain's DNS record to the CNAME generated by the Traffic Scheduler. Change the CNAME record to use the Traffic Scheduler.

    Note

    Three CNAMEs are generated: one by the acceleration service, one by Anti-DDoS, and one by the Traffic Scheduler. Point your DNS record to the Traffic Scheduler CNAME.

Traffic switching

Traffic switches automatically or manually between the acceleration service and Anti-DDoS Proxy. Automatic switching is recommended.

Automatic switching

Switching Type

Switching Condition

From acceleration service to Anti-DDoS Proxy

Triggered when either condition is met:

  • QPS exceeds the threshold 3 times within 3 minutes or more than 6 times within 10 minutes, and normal service traffic does not exceed 10 Gbps.

  • Anti-DDoS detects that the domain entered a sandbox state, and normal service traffic does not exceed 10 Gbps.

From Anti-DDoS Proxy back to acceleration service

Triggered when all conditions are met:

  • For 12+ consecutive hours, QPS stays below 80% of the threshold and attack requests account for less than 10% of traffic.

  • The target Anti-DDoS IP is not in scrubbing or blackhole state, and no such events occurred in the past hour.

  • The domain is not in a sandbox state.

Important

Switchbacks only occur between 08:00 and 23:00.

Manual switching

Operation

Description

From acceleration service to Anti-DDoS Proxy

Manually switch traffic to Anti-DDoS for scrubbing when traffic spikes but automatic switching conditions are not met.Switch to Anti-DDoS

Important
  • You can switch to Anti-DDoS only if the Anti-DDoS IP is not in a blackhole.

  • After a manual switch, traffic automatically returns to the acceleration service when switchback conditions are met.

From Anti-DDoS Proxy back to acceleration service

Manually switch traffic back to the acceleration service if it was routed to Anti-DDoS due to a normal traffic spike.Switch back to acceleration service

Important

Before switching back, confirm the attack has ended and the domain is not in a sandbox state.

Related operations

  • Modify an interaction rule: On the CDN/DCDN Interaction tab, find the target domain, click Actions in the Actions column, and modify the Anti-DDoS Proxy Instance or Access QPS.

  • Delete an interaction rule: On the CDN/DCDN Interaction tab, find the target domain and click Actions in the Actions column.

    Warning

    Before deleting an interaction rule, ensure your DNS record no longer points to the Traffic Scheduler CNAME. Otherwise, your website becomes inaccessible.

Related documents

FAQ