How a CDN protects origin infrastructure

Cloud CDN hides origin behind TLS, Origin Shield, access policies and L3-L7 DDoS mitigation so the public hostname is the edge.

The origin should not be a public address. Visitors terminate at Cloud CDN. The origin answers the shield, not the internet at large. That is protection even before a named DDoS feature.

Address space

Point the public hostname at the distribution. Restrict origin pull. If the old A record still works, attackers will use it.

L3-L7 in the path

Cloud CDN includes L3-L7 DDoS mitigation, TLS 1.3, access policies and token authentication on a 200+ Tbps network. Junk is absorbed off-origin.

Application rules are still yours

This is not a promise of every WAF signature you might want. Review current controls. Combine with origin-side auth.

DNS floods are a different layer

If the zone is on Cloud DNS, authority is DDoS-protected Anycast too. A CDN cannot save a name that does not resolve.

Frequently Asked Questions

Cloud CDN includes L3-L7 DDoS mitigation, TLS, access policies and token authentication in the delivery path. Review current controls for application-layer rules you need.

Use the emergency response page. Call first if traffic is already failing.

Yes. Origin restrictions must allow every CDN you actually use.

Put this on Cloud CDN.

Get started with our Management Console in less than 2 minutes, or connect with an expert to supercharge your business today.