This topic describes how to associate IP addresses of multiple cloud resources to one Anti-DDoS Pro or Anti-DDoS Premium instance in cloud service interaction and tiered protection scenarios. If one of the cloud resources is attacked, service traffic of this cloud resource is switched to Anti-DDoS Pro or Anti-DDoS Premium.
Cloud service interaction
- Configure Sec-Traffic Manager.For example, you have three cloud resources. Add an interaction rule for the IP address of each resource and associate the three rules with the IP address of the Anti-DDoS Pro or Anti-DDoS Premium instance. For more information, see Create a cloud service interaction rule.
- Modify the DNS records.Add three CNAME records for your domain name and set the record values to the CNAME addresses in the three rules created in Step 1. For more information, see Change the CNAME record to redirect traffic to Sec-Traffic Manager.
- Verify the DNS records. Open a DNS test website to verify that the CNAME records added in Step 2 take effect.
Tiered protection
- Purchase an Anti-DDoS Origin Enterprise instance.Add the three cloud resources to Anti-DDoS Origin Enterprise for protection. For more information, see Add an object for protection.
- Configure Sec-Traffic Manager.Create a tiered protection rule for the IP address of each cloud resource and associate the three rules with the IP address of the Anti-DDoS Pro or Anti-DDoS Premium instance. For more information, see Create a tiered protection rule.
- Modify the DNS records.Add three CNAME records for your domain name and set the record values to the CNAME addresses in the three rules created in Step 2. For more information, see Change the CNAME record to redirect traffic to Sec-Traffic Manager.
- Verify the DNS records. Open a DNS test website to verify that the CNAME records added in Step 3 take effect.