Best Practices of Yisu Cloud Anti-DDoS IP
Best practice access
- To purchase Yisu Cloud Anti-DDoS IP, please access Anti-DDoS IP, choose the apIPpriate configuration to purchase.
- If the website supports HTTPS, prepare the certificate and private key, including a public key file in the
.crt format or certificate file in the .pem format and a private key in the .key format. - After purchasing the Anti-DDoS IP, use the ping command to check whether the Anti-DDoS IP can be pinged.
- Add a website (see the following tutorial for specific steps)
- Modify the local hosts file, assign the domain name to Anti-DDoS IP, refresh the DNS cache, and test whether the access is successful through the browser.
- If the above steps are successful, obtain an administrator account of the DNS service. This account is used to modify DNS records to redirect traffic to Anti-DDoS IP.
- You must add the IP addresses of these clients to a whitelist.
Check whether the website service has added the IP segment of the Anti-DDoS IP to the whitelist (the Anti-DDoS IP IP segment can be viewed in 4 in the following tutorial). - Perform a stress test before you add the website to Anti-DDoS IP.
Add website




- Enter the client of Anti-DDoS IP, click section 1 in the preceding figure,
"Website Protection". - Click section 2 in the preceding figure,
"Add Website". - Click section 3 in the preceding figure to select the Anti-DDoS IP to use.
- Section 4 in the preceding figure is the whitelisted IP segments that need to be added to the origin security group.
- Add domain name in section 5 in the preceding figure.
- Section 6 in the preceding figure indicates the supported IP potocol type.
- Section 7 in the preceding figure is the origin type, you can choose the IP address, or you can fill in the domain name.
- Add the source address at section 8 in the preceding figure. If it is IP addresses, it supports multiple, and split by”
,“. - Section 9 in the preceding figure are forwarding ports that can be customized.
- Section 10 and 11 in the preceding figure are whether to force http or https access.
Notice
- If your original server is a windows IIS server, you need to additionally prohibit the following options when using HTTPS domain name.

- Website Protection supports wildcard domain names. In principle, if wildcard domain name rules are set, they can be applied to all second-level domain names under the domain name. If a second-level domain name rule has been set, the second-level domain name rule will be used first.