CDN DDoS protection
The public hostname should fail closed at the edge, not at origin.
When the origin is the public address, volumetric and application attacks share fate with legitimate users. Capacity you bought for customers is spent on junk.
Terminate visitors at Cloud CDN. L3-L7 DDoS mitigation, TLS and access policies sit in the delivery path. Origin Shield and origin validation keep the origin off the open internet.
Why teams use Aptranet
What CDN DDoS protection looks like on this network.
Cloud CDN caches and accelerates eligible content on 210+ points of presence, with Origin Shield when the origin must stay out of the way.
L3-L7 mitigation in the path
Attacks are absorbed on a 200+ Tbps network instead of the origin pipe.
Origin is not the public target
Visitors reach the distribution. Origin pull is controlled.
Anycast delivery
Traffic is answered from 210+ locations rather than a single anycast-less host.
How to set it up
A cutover you can validate before DNS moves.
Create the Cloud CDN configuration, prove it on an Aptranet hostname, then point production DNS when the path looks correct.
- 1Hide the origin
Restrict origin access to Cloud CDN and validate over TLS.
- 2Put the public hostname on the distribution
Cut over DNS only after certificates and origin health are correct.
- 3Set access policies
Use ACLs and token authentication for paths that should not be public.
- 4Know the emergency path
If you are already under attack, use the Aptranet emergency response page.
Outcomes
What changes once the hostname is on Aptranet.
- The public IP is the edge, not the origin
- Volumetric junk is absorbed off-origin
- Private paths can require a token
- Emergency response is available during an incident
Keep reading
Related pages
More CDN use cases on the same Cloud CDN footprint.
Frequently Asked Questions
Cloud CDN includes L3-L7 DDoS mitigation, TLS, access policies and token authentication in the delivery path. Review current controls for application-layer rules you need.
Yes. Authoritative Cloud DNS is DDoS-protected Anycast DNS. Use both when the zone is on Aptranet.
Contact emergency response. Call first if traffic is already failing. See the emergency page.
Yes. Cloud CDN can be one path. Origin restrictions must allow every CDN you actually use.
