최신 업데이트:2025-02-21 15:48:39
Reading time: About 8 minutes
Prerequisites: The Flood Shield 2.0 service has been activated and CDNetworks technical support has completed resource deployment; a CDNetworks account has been created.
Port Configuration onboards non-website services (TCP, UDP) into the Layer 4 protection of Flood Shield 2.0 — for example, gaming and instant messaging applications built on client custom protocols. After you add a port forwarding rule, traffic is scrubbed at edge nodes and forwarded to the origin server, with no changes required on the origin side.
| Onboarding method | Applies to |
|---|---|
| Port Configuration | Non-website services — TCP/UDP applications such as gaming, instant messaging, and custom protocols |
| Domain Settings | HTTP/HTTPS website services; configure ports such as 80, 8080, 443, and 8443 here |
| Filter | Description |
|---|---|
| Protocol Type | Filter by TCP or UDP |
| Back-to-origin Mode | Filter by Fast, Polling, or Hash |
| Protected Port | Filter by the port number used to forward traffic |
| Field | Description | Example |
|---|---|---|
| Protocol Type | The service protocol this rule carries | TCP |
| Protected Port | The port used to forward traffic; a single port or a port range | 1000–1001 |
| Origin Port | The port on the origin server that receives forwarded traffic; the range must match the protected port range | 1000–1001 |
| Back-to-origin Mode | The request distribution strategy for the origin; for the values, see the comparison table below | Polling |
| Origin IP/Domain | The origin server’s IP address or domain; separate multiple values with semicolons (;) |
1.1.1.1;2.2.2.2 |
Important: The protected port does not support 80, 8080, 443, 8443, or 65535. Configure HTTP/HTTPS services on those ports in Domain Settings instead. The same protocol cannot share a port number, and each rule can cover a port range of no more than 10 ports.
Back-to-origin mode comparison:
| Mode | Algorithm | Use when |
|---|---|---|
| Fast | Forwards requests to the origin with the fastest response time first | Latency-sensitive businesses, or origins that differ noticeably in performance |
| Polling | Distributes requests to each origin in turn | Origins of similar performance, when you want the load spread evenly |
| Hash | Routes requests to a fixed origin by hash value | Session persistence is needed, and the same client must always reach the same origin |
To create several rules at once, follow these steps:
| Method | Description | Use when |
|---|---|---|
| Enter in the dialog box | One rule per line; the system parses and creates them in batch | There are few rules, or you are adding rules ad hoc |
| Import a .txt file | Write the rules to a file in the same format and upload it; the system parses and creates them in batch | The rules are already generated in bulk in a spreadsheet or file, or there are many of them |
TCP 101 101 1 1.1.1.1;2.2.2.2
From left to right, each line contains:
| Position | Field | Accepted values |
|---|---|---|
| 1st | Protocol Type | TCP or UDP |
| 2nd | Protected Port / Port Range | A single port such as 101, or a port range such as 1000–1010 |
| 3rd | Origin Port / Port Range | Must match the protected port range |
| 4th | Back-to-origin Mode | 1 (Fast), 2 (Polling), 3 (Hash) |
| 5th | Origin IP / Domain | Multiple IPs or domains separated by semicolons |