Website Protection

최신 업데이트:2025-12-19 11:48:59

Reading time: About 13 minutes
Prerequisites: The Flood Shield 2.0 service has been activated.

This topic walks you through onboarding a website for protection: add a domain and configure security policies, so that DDoS Protection, WAF Protection, Bot Management, and API Security take effect for the website.


Step 1: Add a Domain

1. Create a Domain

  1. Log in to the CDNetworks console, find the Flood Shield 2.0 service you are using under Subscribed Products, and click to enter it.
  2. Go to Domain Settings and click Add Domain.

2. Configure Domain Information

Field Description
Contract Item Select the product and contract to associate with the new domain; once the domain is added, it is automatically assigned to the corresponding contract control group
Domain Type Select Domain
Custom Control Group Optional. Assign the domain to a specific control group; domains in the same control group can be managed together and their analytics data viewed in one place

Domain

Format Example Description
Subdomain www.cdnetworks.com The most common onboarding method
Wildcard domain *.cdnetworks.com Covers all subdomains at that level
Root domain .cdnetworks.com Covers second-level domains by default; third-level domains must be added separately

A wildcard domain and its subdomains must belong to the same account. Third-level domains such as cdn.console.cdnetworks.com are not covered by a root domain and must be added separately.

Origin IP / Domain

Origin type Configuration requirement
Custom origin — Origin IP Up to 64 IP addresses separated by semicolons (;); IPv4 and IPv6 are supported
Custom origin — Origin domain Only one domain can be configured
WCS origin When the origin is CDNetworks object storage, select the WCS origin directly; no IP or domain needs to be entered

Operation

Operation Description
Add Add a new domain configuration
Delete Delete the corresponding domain configuration
Origin Check Enter a URL to verify that the origin is reachable; the check is triggered once, only when you click Check, and does not run on a schedule
Batch Add Add up to 300 domains at a time, one per line; separate multiple origin IPs with ;

Acceleration Region (this option appears when the contract region includes Mainland China)

Option Description ICP filing requirement
Include Mainland China CDN acceleration is provided preferentially from Mainland China nodes Per MIIT regulations, the domain must pass ICP filing review; the system verifies this automatically on submission
Exclude Mainland China Mainland China nodes do not provide acceleration for this domain The system does not perform ICP filing review

Acceleration Configuration

Method Description Use when
Duplicate configuration from an existing domain Add the domain certificate and select an existing domain as a reference, applying its configuration to the new domain Adding a domain under the same business that must stay consistent with an existing domain
Custom configuration Add the domain certificate and select the resource group to apply First-time onboarding, or when independent resource configuration is required

When you duplicate configuration from an existing domain, the following settings are not copied: Basic Origin, Advanced Origin, Origin Host Header, Origin Request Port, and Forward Client IP.
After selecting a reference domain, you can view general console configurations only. For special configurations, contact CDNetworks technical support.
Resource groups provide resource isolation: when a domain in one IP group is attacked, domains in other IP groups are unaffected. To use this feature, contact CDNetworks technical support first to request resources.

3. Submit the Configuration

  1. After completing the configuration above, click Submit.
  2. If you selected Include Mainland China for the acceleration region, handle the ICP filing verification result as follows:
Status field Value Description
ICP Filing Status Filed Select the domains that passed verification and click Submit to submit the configuration
Not Filed Complete ICP filing for the domain first, then submit again; if you submit without completing ICP filing, the configuration goes to manual review and the domain status shows as “Pending”
Pending Mainland China acceleration becomes available only after manual review passes; if the ICP filing information still cannot be confirmed during review, the domain is rejected

If the status is still “Pending” more than 5 minutes after you submit a new domain, one of the following may be the cause. Contact CDNetworks technical support for assistance:

  • ICP filing has not been completed for the Mainland China acceleration channel.
  • The domain has special configurations that cannot be reviewed automatically.
  • The new domain’s primary domain already exists under another customer, causing a domain conflict.
  • The new domain conflicts with the configuration of the reference domain.

4. Confirm the Deployment Result

After the configuration passes review, the platform deploys it to online nodes and makes it effective within 1–2 minutes, and sends an add-success notification to your registered email address.

  1. Check the progress in Domain Settings. A status of Active means the domain has been added successfully.
  2. Point the domain’s DNS resolution to the CNAME address assigned by the system; acceleration and protection take effect only after that. For details, see Configure a CNAME Record.

Step 2: Configure Security Policies

1. Select the Hostname to Protect

  1. Go to Security Settings > Policies and click + Protected Hostname.
  2. Select the hostname you want to protect with the CDN service, avoiding interference from existing hostnames.
  3. Click Next.

2. Select an Initial Policy

Method Description Use when
Recommended default policies System-preset default configuration, ready to use out of the box, and available for testing and fine-tuning First-time onboarding with no other domain to reference
Duplicate policies from an existing hostname Uses an onboarded hostname as a reference, so the new hostname reuses the same protection policies Adding a domain under the same business that must stay consistent with the existing configuration

Configurations generated dynamically by the system are not copied, including WAF managed rule exceptions and the protection thresholds and rules generated automatically by adaptive protection (L7 DDoS protection).

Click Next when you are done.

3. Confirm the Initial Policy

If you select “Recommended default policies”:

  • No special protection requirements: keep the default policies. Later, you can review protection details in reports and logs and optimize the policies over time.
  • Special protection requirements: adjust the Protection Mode or Action for each protection module. See the table below for how to configure each module:
Protection module Reference
DDoS Protection Configuring DDoS Protection Policies
Bot Management About Bot Management
WAF Configuring WAF Managed Rules
Threat Intelligence Configuring Threat Intelligence

If you select “Duplicate policies from an existing hostname”: confirm that the reference hostname’s policies match your expectations.

Click Next when you are done. The security configuration is created, and protection takes effect immediately.

4. Confirm the Configuration Publishing Status

  1. Return to the Policies page.
  2. Check the configuration’s publishing status:
Status field Value Description
Publishing Status Publishing The configuration is being deployed to edge nodes
Success The configuration is in effect and protection is running normally

Next Steps

  • → Recommended Initial Configuration — Further optimize your protection policies based on your business type
  • → Onboard Non-Website Protection — If you also need to onboard TCP/UDP applications, see that topic
이 문서의 내용이 도움이 되었습니까?
예
아니오
정상적으로 제출되었습니다.피드백을 주셔서 감사합니다.앞으로도 개선을 위해 노력하겠습니다.