Combining SCDN and protected IP by service path

Map assets, APIs and game ports to appropriate paths before combining protection products.

Contents of this article

Assign products from the service inventory

A business may serve website assets, dynamic APIs and game ports. Evaluate SCDN for web delivery and supported application controls, and protected IP for independent protocol mitigation and forwarding. Map each path before combining products.

Stacking services is not automatically better

Chained proxies can change origin addresses, client metadata, TLS and timeouts. Define each layer and verify that there are no routing loops, certificate mismatches or duplicate challenges. Validate the actual topology.

Maintain one entry-to-origin map

Record the layers and final origin for each hostname, protocol and port, plus the owner of allow rules. Include old addresses and health checks so untracked bypasses are not overlooked.

Diagnose with layer-specific checks

Observe DNS, TLS, edge processing, mitigation, forwarding and application responses separately. Locate the first failing hop, and size legitimate bandwidth, connections and ports rather than adding advertised capacities.

References

AWS DDoS protection overview

Related products and onboarding

View products and onboarding information

Back to industry insights Contact technical support