CDN DDoS protection

Absorb L3-L7 attacks at the Aptranet edge with Cloud CDN: TLS 1.3, Origin Shield, access policies and a 200+ Tbps network.

210+Points of presence worldwide
200+ TbpsNetwork capacity
30 msAverage latency worldwide
85%Average cache hit ratio

CDN DDoS protection

The public hostname should fail closed at the edge, not at origin.

When the origin is the public address, volumetric and application attacks share fate with legitimate users. Capacity you bought for customers is spent on junk.

Terminate visitors at Cloud CDN. L3-L7 DDoS mitigation, TLS and access policies sit in the delivery path. Origin Shield and origin validation keep the origin off the open internet.

Why teams use Aptranet

What CDN DDoS protection looks like on this network.

Cloud CDN caches and accelerates eligible content on 210+ points of presence, with Origin Shield when the origin must stay out of the way.

L3-L7 mitigation in the path

Attacks are absorbed on a 200+ Tbps network instead of the origin pipe.

Origin is not the public target

Visitors reach the distribution. Origin pull is controlled.

Anycast delivery

Traffic is answered from 210+ locations rather than a single anycast-less host.

How to set it up

A cutover you can validate before DNS moves.

Create the Cloud CDN configuration, prove it on an Aptranet hostname, then point production DNS when the path looks correct.

  1. 1
    Hide the origin

    Restrict origin access to Cloud CDN and validate over TLS.

  2. 2
    Put the public hostname on the distribution

    Cut over DNS only after certificates and origin health are correct.

  3. 3
    Set access policies

    Use ACLs and token authentication for paths that should not be public.

  4. 4
    Know the emergency path

    If you are already under attack, use the Aptranet emergency response page.

Outcomes

What changes once the hostname is on Aptranet.

  • The public IP is the edge, not the origin
  • Volumetric junk is absorbed off-origin
  • Private paths can require a token
  • Emergency response is available during an incident

Frequently Asked Questions

Cloud CDN includes L3-L7 DDoS mitigation, TLS, access policies and token authentication in the delivery path. Review current controls for application-layer rules you need.

Yes. Authoritative Cloud DNS is DDoS-protected Anycast DNS. Use both when the zone is on Aptranet.

Contact emergency response. Call first if traffic is already failing. See the emergency page.

Yes. Cloud CDN can be one path. Origin restrictions must allow every CDN you actually use.

Put CDN DDoS protection on the Aptranet edge.

Get started in the Management Console, or talk through origin, DNS and cutover with Aptranet.