Protected IP: integration and acceptance checklist

Before accessing, sort out the protocol, port, and origin server information, confirm the forwarding plan, and then verify the business connectivity, logs, and fallback paths.

Contents of this article

Scope of application and delivery method

DDoS Protected IPFor website and non-website businesses, you need to match the business entrance and forwarding rules with the origin server when accessing. Whether the protocol is supported, available ports, number of IPs, business bandwidth and protection scope should be confirmed one by one before purchasing.

When accessing, use the DDoS-protected entrance, forwarding configuration and operation instructions delivered by the service team, and complete integration testing according to the actual application protocol.

For common checking items for accounts, lines and orders, see Purchase requirements and billing

Conditions that should be met before accessing

  • It can manage origin server services, listening ports and firewalls, and can cooperate to check the reachability of forwarding nodes to the origin server.
  • Business entry can be modified. When using a domain name, you need corresponding DNS management permissions; when using the client's built-in address, you need the ability to modify the configuration or publish the client.
  • Business protocols and ports have been organized. Protecting against certain types of attacks does not mean supporting the forwarding of protocols with the same name. Technical personnel should be asked to clarify the supported scope of business protocols.
  • The test environment or test entrance has been prepared, and the original entrance, original configuration and recovery method have been retained.
  • Account authentication, business qualifications, line applicable requirements and billing rules have been confirmed with customer service.

What information needs to be provided

Information Fill in the content
Business entrance Domain name or current client connection address, website, game, API and other business types
Forward relationship The protocol, external port, origin IP or domain name, and origin listening port of each business
Traffic scale Daily and peak bandwidth, number of connections, main user areas; provide time and scale if there are historical attack records
connection features Whether to maintain a long connection, whether to require session maintenance, client timeout and reconnection behavior
Origin restrictions Security groups, firewalls, allow origin policies, and currently used proxies or load balancers
HTTPS requirements Involved domain names, certificate deployment locations, and whether encryption back to the source is required
Online arrangement Test entrance, change window, acceptance person and the original configuration that needs to be restored

Integration

  1. Confirm the plan. Submit the above information to the service team to obtain clear agreement support, forwarding relationships, resource allocation, costs and delivery scope.
  2. Check delivery information. Obtain the real DDoS-protected entrance, the forwarding rules that need to be established, the sources that the origin server needs to allow, and the configuration instructions. When it comes to HTTPS, also confirm at which layer TLS is handled.
  3. Check the origin server first. Use the actual protocol to verify that the origin server service, port, authentication, and dependent services are normal, and retain the pre-access baseline.
  4. integration testing through the test entrance. Configure forwarding according to the delivery plan, and compare the client results with the origin server logs to confirm that the request enters the correct service.
  5. Switch to official business. After passing the test, adjust the DNS or client portal according to the change schedule; observe key business and exception logs, and then complete acceptance.

origin server access restrictions should be adjusted after the real return source is confirmed and verified. The delivery method of the source address and client IP must be confirmed according to this delivery. Do not copy the request header configuration of the website proxy.

How to verify successful access

Check items Suggested verification method
The entrance is correct Check the DNS or the actual connection address of the client to confirm that it is consistent with the delivered DDoS-protected portal.
Forwarded correctly Test the protocols and ports one by one, and confirm in the origin logs that the request reaches the target service
core business Complete real business processes such as login, session creation, transaction or game operation
long connection Continuously connect and test reconnection after disconnection and recovery after idle; record abnormal disconnection and timeout
user experience Record the connection success rate, time consumption and service error rate from major user areas, and compare them with those before access
Fallback preparation Check the original entrance and recovery steps, and confirm the protection status during rollback with the service team

The fact that the page is accessible only means that the access was successful, but it does not prove that all ports, regions or protection capabilities have been accepted. The scope and method of verification of the protective effect should be separately agreed with the service team.

Exception handling and support portal

When the connection cannot be made, first differentiate between the entrance address error, the rule not taking effect, the source port being unreachable and the business itself having errors. Provide the occurrence time and time zone, region and operator, destination address and port, client errors and related origin server logs for easy location.

When recovery is needed, restore the entry and configuration according to the pre-confirmed plan; caching and TTL must also be considered for businesses using DNS. After restoring to the original entrance, re-verify key services and confirm protection arrangements.

PassOnline customer serviceSubmit information or go toContact usUse existing support channels. Please describe "DDoS-protected IP Access" and attach the order or resource identification.

Return to DDoS-protected IP document Return to help center Contact technical support