Reading time: About 5 minutes
Prerequisites: The Flood Shield 2.0 service has been activated and CDNetworks technical support has completed resource deployment; a CDNetworks account has been created.
This topic explains how to add non-website applications (based on TCP and UDP) to achieve Layer 4 acceleration and protection.
Step 1: Add a Port Forwarding Rule
1. Create a Rule
- Log in to the console, find Flood Shield 2.0 under Subscribed Products, and click to enter it.
- Go to Asset Management > Port Configuration.
- Click Create Rule.
2. Configure Rule Information
| Parameter |
Description |
| Protocol Type |
TCP and UDP are supported |
| Protected Port |
The port used to forward traffic; it can be added as a port or a port range. Note: Ports such as 80, 8080, 443, 8443, and 65535 are not supported; the same protocol cannot reuse a port number; each rule can cover a port range of no more than 10 ports |
| Origin Port |
The origin port range must match the protected port range |
| Back-to-origin Mode |
Fast, Polling, and Hash are supported |
| Origin IP / Domain |
The IP address or domain of the origin server |
Back-to-origin mode algorithms:
- Fast: Focuses on server response speed and traffic-handling capacity to ensure high performance and availability; the preferred choice when there are few origins or their performance differs noticeably.
- Polling: Distributes requests across servers in a cyclic order; choose it when origins have similar capacity and you want requests distributed evenly.
- Hash: Distributes requests across servers by computing a hash value; choose it when requests from the same client must always be forwarded to the same origin.
3. Create Rules in Batch (Optional)
Click Create Rule > Batch Create to use either method:
- Enter rules in the dialog box (one rule per line)
Format example: TCP 101 101 1 1.1.1.1;2.2.2.2
From left to right: protocol type, protected port/range, origin port/range, back-to-origin mode (1 = Fast, 2 = Polling, 3 = Hash), origin IP
- Import a .txt file (same format)
4. Confirm the Rule Deployment Status
- Return to the Port Configuration page.
- Check the Deploy Status: it shows “Deploying” right after creation and updates to “Deployed Successfully” once the rule takes effect.
Step 2: Enable Non-Website Protection
After the rule is deployed successfully, you must configure a CNAME record for the service domain to enable protection.
- Copy the CNAME value from the top of the rule list on the Port Configuration page.
- Log in to the console of the DNS provider that hosts the service domain, and add a CNAME record for it.
- Set the record value to the CNAME value copied in step 1 and save.
- Wait for DNS resolution to take effect, and protection is then enabled; the time it takes depends on the TTL configured at your DNS provider.
Next Steps
- → Onboard Website Protection — If your business also includes HTTP/HTTPS websites, see that topic to complete onboarding
- → Manage Resource Groups — Isolate domains into resource groups by business so that a single attack does not affect everything