DDoS and CDNs: absorb junk at the edge

Volumetric and application floods should hit 200+ Tbps of edge, not the origin pipe. How Cloud CDN and Cloud DNS split that job.

DDoS is a capacity contest. If the public IP is the origin, you brought a VM to a network fight. If the public IP is Cloud CDN, the fight happens on 200+ Tbps with the origin off to the side.

Volumetric versus application

L3-L4 floods fill pipes. L7 floods fill workers with expensive requests. The edge should take both. Origin Shield and cache also mean many L7 GETs never become origin GETs.

Hide then restrict

Cut over DNS, then firewall origin to pull paths only. An uncovered origin IP is a second public hostname you forgot.

DNS is a separate flood

Authoritative Cloud DNS is DDoS-protected Anycast. Host the zone there if the name itself is the target.

Practice before you need the phone

Know the emergency page and the number. An active incident is a poor time to create a distribution from scratch.

Frequently Asked Questions

It absorbs volumetric junk and unauthenticated GETs that hit cache. Targeted application abuse still needs origin and app controls.

Yes. Traffic is answered from 210+ locations rather than a single anycast-less host.

No. Put the hostname on Cloud CDN while you can still validate calmly. Use emergency response if you are already failing.

Talk through CDN and DNS with Aptranet.

Get started with our Management Console in less than 2 minutes, or connect with an expert to supercharge your business today.