Port Configuration

최신 업데이트:2025-02-21 15:48:39

Reading time: About 8 minutes
Prerequisites: The Flood Shield 2.0 service has been activated and CDNetworks technical support has completed resource deployment; a CDNetworks account has been created.

Port Configuration onboards non-website services (TCP, UDP) into the Layer 4 protection of Flood Shield 2.0 — for example, gaming and instant messaging applications built on client custom protocols. After you add a port forwarding rule, traffic is scrubbed at edge nodes and forwarded to the origin server, with no changes required on the origin side.

  • Protocol support: Each rule supports TCP or UDP, and rules using the same protocol cannot reuse the same port number.
  • Back-to-origin mode: Three origin distribution strategies are available — Fast, Polling, and Hash — so you can choose one by business characteristics.
  • Batch create: Paste multiple rules in the dialog box, or import a .txt file to create several rules at once.

How Port Onboarding Differs from Domain Onboarding

Onboarding method Applies to
Port Configuration Non-website services — TCP/UDP applications such as gaming, instant messaging, and custom protocols
Domain Settings HTTP/HTTPS website services; configure ports such as 80, 8080, 443, and 8443 here

View and Filter Rules

  1. Log in to the CDNetworks console, find the Flood Shield 2.0 service you are using under Subscribed Products, and click to enter it.
  2. Go to Asset Management > Port Configuration. The page shows all port forwarding rules that have been created.
  3. Select the filter conditions as needed and click OK to locate the target rule:
Filter Description
Protocol Type Filter by TCP or UDP
Back-to-origin Mode Filter by Fast, Polling, or Hash
Protected Port Filter by the port number used to forward traffic

Create or Modify a Rule

  1. Click Create Rule to create a rule; to change an existing rule, click Modify in the Operation column.
  2. Configure the parameters in the table below, then click OK.
Field Description Example
Protocol Type The service protocol this rule carries TCP
Protected Port The port used to forward traffic; a single port or a port range 1000–1001
Origin Port The port on the origin server that receives forwarded traffic; the range must match the protected port range 1000–1001
Back-to-origin Mode The request distribution strategy for the origin; for the values, see the comparison table below Polling
Origin IP/Domain The origin server’s IP address or domain; separate multiple values with semicolons (;) 1.1.1.1;2.2.2.2

Important: The protected port does not support 80, 8080, 443, 8443, or 65535. Configure HTTP/HTTPS services on those ports in Domain Settings instead. The same protocol cannot share a port number, and each rule can cover a port range of no more than 10 ports.

Back-to-origin mode comparison:

Mode Algorithm Use when
Fast Forwards requests to the origin with the fastest response time first Latency-sensitive businesses, or origins that differ noticeably in performance
Polling Distributes requests to each origin in turn Origins of similar performance, when you want the load spread evenly
Hash Routes requests to a fixed origin by hash value Session persistence is needed, and the same client must always reach the same origin

Batch Create Rules

To create several rules at once, follow these steps:

  1. Click Create Rule > Batch Create.
  2. Choose a creation method:
Method Description Use when
Enter in the dialog box One rule per line; the system parses and creates them in batch There are few rules, or you are adding rules ad hoc
Import a .txt file Write the rules to a file in the same format and upload it; the system parses and creates them in batch The rules are already generated in bulk in a spreadsheet or file, or there are many of them
  1. Enter the rules line by line in the following format.
TCP 101 101 1 1.1.1.1;2.2.2.2

From left to right, each line contains:

Position Field Accepted values
1st Protocol Type TCP or UDP
2nd Protected Port / Port Range A single port such as 101, or a port range such as 1000–1010
3rd Origin Port / Port Range Must match the protected port range
4th Back-to-origin Mode 1 (Fast), 2 (Polling), 3 (Hash)
5th Origin IP / Domain Multiple IPs or domains separated by semicolons

Next Steps

  • → Onboard Non-Website Protection — After a rule is created, configure a CNAME record for the service domain before protection takes effect
  • → Onboard Website Protection — If your business also includes HTTP/HTTPS websites, see that topic to complete onboarding
이 문서의 내용이 도움이 되었습니까?
예
아니오
정상적으로 제출되었습니다.피드백을 주셔서 감사합니다.앞으로도 개선을 위해 노력하겠습니다.