Integrate Anti-DDoS Proxy with CDN or DCDN so that traffic uses acceleration nodes during normal operations and automatically switches to Anti-DDoS Proxy for scrubbing during attacks.
Feature overview
Alibaba Cloud provides two solutions for services that need both acceleration and DDoS protection:
-
Solution 1: DDoS Mitigation at the Edge for DCDN (Recommended)
Add a domain to DCDN, then enable DDoS Mitigation at the Edge in the DCDN console with one click. No Anti-DDoS Proxy configuration is required. Protection Configuration.
NoteOnly DCDN supports DDoS Mitigation at the Edge. To use this feature with CDN, migrate your domain to DCDN first. Upgrade a CDN domain name to DCDN.
-
Solution 2: Anti-DDoS Proxy interaction with CDN or DCDN
This topic covers this solution. Anti-DDoS scrubs attack traffic and forwards clean traffic directly to the origin server. Configure your domain in both the acceleration service and Anti-DDoS Proxy, then set up the interaction in the Traffic Scheduler.
With the interaction feature, scrubbed traffic goes directly to the origin server. With DDoS Mitigation at the Edge, scrubbed traffic goes to DCDN, maintaining acceleration during attacks.
Precautions
-
If your bandwidth exceeds 3 Gbps or QPS exceeds 10,000, contact your account manager for evaluation before using this feature.
-
For websites attacked more than three times a week, use Anti-DDoS Proxy alone to avoid disruptions from frequent traffic switching.
-
The interaction feature supports both IPv4 and IPv6 Anti-DDoS IPs.
-
When traffic switches to Anti-DDoS Proxy during an attack, the DNS TTL may affect activation time.
-
Before using this feature, verify that your domain is not in a Sandbox state in the acceleration service. If it is, contact your account manager to remove it before configuring DDoS protection.
Supported Anti-DDoS instance types
Anti-DDoS Proxy (Chinese Mainland) Professional or Advanced Plan, and Anti-DDoS Proxy (Outside Mainland China) Insurance or Unlimited Plan. All instances must use the Enhanced Function plan.
Prerequisites
-
CDN or DCDN acceleration is enabled for your domain. Add a domain name to CDN or Add a domain name to DCDN.
-
You have purchased an Anti-DDoS Proxy instance and added your website to it. For more information, see Purchase an Anti-DDoS Proxy instance and Add a website.
-
The Anti-DDoS Proxy instance correctly forwards traffic. Locally verify the forwarding configuration.
Procedure
Log on to the Anti-DDoS Proxy console.
In the top navigation bar, select the region of your instance.
Anti-DDoS Proxy (Chinese Mainland): Choose the Chinese Mainland region.
Anti-DDoS Proxy (Outside Chinese Mainland): Choose the Outside Chinese Mainland region.
-
In the left-side navigation pane, choose and click the CDN/DCDN Interaction tab.
NoteIf you are using the interaction feature for the first time, click Authorize Now and follow the on-screen instructions to authorize Anti-DDoS Proxy to access the acceleration service.
-
Find the domain that you want to manage and click Actions in the Actions column. In the Create Interaction Rule panel, complete the configuration and click Next.
Parameter
Description
Anti-DDoS Proxy Instance
Select the Anti-DDoS Proxy instance to integrate with the acceleration service.
Note-
If the message To enable CDN interaction, you must use an instance of the Enhanced function plan. appears, follow the instructions to upgrade your instance.
-
If the message No instance is selected. appears, first add your domain to an Anti-DDoS Proxy instance. Add a website.
Resource for Interaction
The associated resource is automatically selected.
If the domain has not been added to an acceleration service, add it and wait about 10 minutes before configuring the interaction. Add a domain name to CDN or Add a domain name to DCDN.
Access QPS
Set the minimum QPS threshold to trigger a switch to Anti-DDoS Proxy.
For more information about traffic switching, see Traffic switching.
NoteSet the threshold to at least 2-3 times your historical peak QPS. Minimum recommended value: 500, even for low-traffic websites.
-
-
Verify that the traffic scheduling rule works by modifying your local hosts file. This prevents compatibility issues from inconsistent back-to-origin policies. Locally verify the forwarding configuration.
For example, if CDN interacts with Anti-DDoS and the origin is an OSS bucket: CDN allows modifying the back-to-origin HOST header, but Anti-DDoS does not. If traffic switches to Anti-DDoS during an attack, the OSS bucket may reject the requests, causing a service failure.
-
Point your domain's DNS record to the CNAME generated by the Traffic Scheduler. Change the CNAME record to use the Traffic Scheduler.
NoteThree CNAMEs are generated: one by the acceleration service, one by Anti-DDoS, and one by the Traffic Scheduler. Point your DNS record to the Traffic Scheduler CNAME.
Traffic switching
Traffic switches automatically or manually between the acceleration service and Anti-DDoS Proxy. Automatic switching is recommended.
Automatic switching
|
Switching Type |
Switching Condition |
|
From acceleration service to Anti-DDoS Proxy |
Triggered when either condition is met:
|
|
From Anti-DDoS Proxy back to acceleration service |
Triggered when all conditions are met:
Important
Switchbacks only occur between 08:00 and 23:00. |
Manual switching
|
Operation |
Description |
|
From acceleration service to Anti-DDoS Proxy |
Manually switch traffic to Anti-DDoS for scrubbing when traffic spikes but automatic switching conditions are not met. Important
|
|
From Anti-DDoS Proxy back to acceleration service |
Manually switch traffic back to the acceleration service if it was routed to Anti-DDoS due to a normal traffic spike. Important
Before switching back, confirm the attack has ended and the domain is not in a sandbox state. |
Related operations
-
Modify an interaction rule: On the CDN/DCDN Interaction tab, find the target domain, click Actions in the Actions column, and modify the Anti-DDoS Proxy Instance or Access QPS.
-
Delete an interaction rule: On the CDN/DCDN Interaction tab, find the target domain and click Actions in the Actions column.
WarningBefore deleting an interaction rule, ensure your DNS record no longer points to the Traffic Scheduler CNAME. Otherwise, your website becomes inaccessible.

