Non-website Protection

최신 업데이트:2025-12-19 11:50:26

Reading time: About 5 minutes
Prerequisites: The Flood Shield 2.0 service has been activated and CDNetworks technical support has completed resource deployment; a CDNetworks account has been created.

This topic explains how to add non-website applications (based on TCP and UDP) to achieve Layer 4 acceleration and protection.


Step 1: Add a Port Forwarding Rule

1. Create a Rule

  1. Log in to the console, find Flood Shield 2.0 under Subscribed Products, and click to enter it.
  2. Go to Asset Management > Port Configuration.
  3. Click Create Rule.

2. Configure Rule Information

Parameter Description
Protocol Type TCP and UDP are supported
Protected Port The port used to forward traffic; it can be added as a port or a port range. Note: Ports such as 80, 8080, 443, 8443, and 65535 are not supported; the same protocol cannot reuse a port number; each rule can cover a port range of no more than 10 ports
Origin Port The origin port range must match the protected port range
Back-to-origin Mode Fast, Polling, and Hash are supported
Origin IP / Domain The IP address or domain of the origin server

Back-to-origin mode algorithms:

  • Fast: Focuses on server response speed and traffic-handling capacity to ensure high performance and availability; the preferred choice when there are few origins or their performance differs noticeably.
  • Polling: Distributes requests across servers in a cyclic order; choose it when origins have similar capacity and you want requests distributed evenly.
  • Hash: Distributes requests across servers by computing a hash value; choose it when requests from the same client must always be forwarded to the same origin.

3. Create Rules in Batch (Optional)

Click Create Rule > Batch Create to use either method:

  • Enter rules in the dialog box (one rule per line)

Format example: TCP 101 101 1 1.1.1.1;2.2.2.2
From left to right: protocol type, protected port/range, origin port/range, back-to-origin mode (1 = Fast, 2 = Polling, 3 = Hash), origin IP

  • Import a .txt file (same format)

4. Confirm the Rule Deployment Status

  1. Return to the Port Configuration page.
  2. Check the Deploy Status: it shows “Deploying” right after creation and updates to “Deployed Successfully” once the rule takes effect.

Step 2: Enable Non-Website Protection

After the rule is deployed successfully, you must configure a CNAME record for the service domain to enable protection.

  1. Copy the CNAME value from the top of the rule list on the Port Configuration page.
  2. Log in to the console of the DNS provider that hosts the service domain, and add a CNAME record for it.
  3. Set the record value to the CNAME value copied in step 1 and save.
  4. Wait for DNS resolution to take effect, and protection is then enabled; the time it takes depends on the TTL configured at your DNS provider.

Next Steps

  • → Onboard Website Protection — If your business also includes HTTP/HTTPS websites, see that topic to complete onboarding
  • → Manage Resource Groups — Isolate domains into resource groups by business so that a single attack does not affect everything
이 문서의 내용이 도움이 되었습니까?
예
아니오
정상적으로 제출되었습니다.피드백을 주셔서 감사합니다.앞으로도 개선을 위해 노력하겠습니다.