User Guide

更新时间:
复制 MD 格式

You can manage resources in the Dynamic Content Delivery Network (DCDN) or Edge Security Acceleration (ESA) console.

doutub_gifEdge Security Acceleration (ESA) User Guide

doutub_gifDynamic Content Delivery Network (DCDN) User Guide

Edge Security Acceleration (ESA)

Feature set

Feature

Description

References

Site management

Version management

The version management feature of Edge Security Acceleration (ESA) allows you to maintain different versions for custom website configurations and test, deploy, and roll back configuration changes.

Version management

Analytics and logs

  • Edge Security Acceleration (ESA) logs requests that pass through ESA points of presence (POPs) and analyzes these logs to help you troubleshoot issues, check the impact of updated configurations, and monitor metrics.

  • Edge Security Acceleration (ESA) logs requests to your website. It collects and aggregates the logs generated by each module for you to view. You can use these logs to troubleshoot faults, generate monitoring metrics, and debug or test network connectivity between clients and your website.

Analytics and logs

DNS

Edge Security Acceleration (ESA) provides a flexible Domain Name System (DNS) feature. ESA supports NS setup and CNAME setup. After you connect your site to ESA, ESA provides services such as dynamic and static content acceleration, security protection, and edge computing to improve your site's access experience and security.

DNS

SSL/TLS

ESA provides SSL/TLS protocol configurations to encrypt your network traffic. This prevents data theft and tampering.

SSL/TLS

Security protection

  • ESA combines edge Web Application Firewall (WAF) capabilities with rule-based features to provide fine-grained filtering and management of origin traffic.

  • ESA provides two modes, Smart Mode and Professional Mode, to meet the security protection requirements of different business scenarios.

  • ESA monitors traffic in real time to detect attack patterns, such as SYN floods, ACK floods, and CC attacks. When unusual traffic is detected, ESA responds quickly by automatically blocking malicious data while allowing legitimate traffic to pass through. This process ensures business continuity and stability.

  • Add the list of ESA node IP addresses to your origin server's firewall rules. This protects your origin server by allowing access only from whitelisted IP addresses.

Speed and network

  • Edge Security Acceleration (ESA) provides an image transformation feature. You can use this feature to transform the format and quality of images from your origin server, and also crop, scale, and cache them. This process speeds up image retrieval and reduces origin traffic.

  • Edge Security Acceleration (ESA) provides features such as network access optimization, IPv6 support, as well as WebSocket and gRPC connections to optimize cross-region network performance and user experience.

Caching

After you add a website to Edge Security Acceleration (ESA), ESA points of presence (POPs) determine whether to cache resources that are requested by clients based on configured cache rules. After a POP caches a file, when clients request the file, the POP responds the file to clients without retrieving it from the origin server over a long route. This reduces latency and improves load times. If the requested file does not exist on the POP or has expired, the POP asks the origin server for the most recent file.

Rules

Edge Security Acceleration (ESA) lets you create rules to customize settings for incoming requests. To apply custom settings like transform, redirect, or cache to specific requests, or to gain detailed control over security and traffic management, use syntax and configuration logic to filter requests based on specific characteristics and configure the appropriate features.

Traffic

  • This topic introduces what smart routing is, how it is billed, and how to enable the feature in the ESA console.

  • When your origin server receives a high volume of requests, a waiting room helps manage the traffic. This feature prevents surges from causing origin server downtime by limiting concurrent users and queuing the excess.

  • Load balancing distributes traffic among origin servers according to traffic steering policies to reduce latency and improve service availability.

TCP/UDP proxy

If your application, such as a real-time multiplayer game, interactive video stream, or IoT service, relies on layer-4 (TCP/UDP) protocols, you may experience high latency and network instability over the public internet, which degrades the user experience. Edge Security Acceleration (ESA) mitigates these issues by routing user traffic to the nearest global Point of Presence (POP). From the POP, traffic is forwarded to your origin server over Alibaba Cloud's optimized network, which reduces latency and packet loss. This ensures a smooth, responsive, and secure experience for your end-users, regardless of their location.

Edge computing

Edge function

Functions and Pages is an all-in-one, full-stack development platform from Edge Security Acceleration (ESA). It integrates Git workflows, a global edge network, and an intelligent build system to provide a complete deployment solution. This solution allows enterprises and developers to manage the entire deployment process, from code commit to global distribution. The platform supports various use cases, such as static websites, Single-Page Applications (SPAs), Server-Side Rendering (SSR) applications, and Edge Functions. It is designed to meet diverse deployment needs, from personal projects to complex enterprise architectures.

Functions and Pages

Edge Container

Edge Container provides elastic, easy-to-maintain computing resources based on containerized applications. Edge Container implements global deployment and proximity-based scheduling on points of presence (POPs) all over the world. This simplifies protocol processing and reduces response latency. You do not need to purchase server resources or worry about application scaling and O&M. This allows you to focus on application development rather than underlying infrastructure management.

Edge Container

Edge Storage

Edge KV is a key-value pair storage service available at points of presence (POPs). Data written to Edge KV is quickly synchronized globally across POPs. Edge Routine (ER) allows for fast reading of Edge KV data from the same POP. Use Edge KV with ER to deploy lightweight Blockchain as a Service (BaaS) and API gateway services.

Edge Storage

Analytics and logs

Account analytics

This topic explains how ESA account analytics provides visualized analysis of different metrics from all the websites under your account and walks you through how to use it.

Logs

Edge Security Acceleration (ESA) logs requests to your website. It collects and aggregates the logs generated by each module for you to view. You can use these logs to troubleshoot faults, generate monitoring metrics, and debug or test network connectivity between clients and your website.

Standard logs

Real-time logs

Instant logs

Global configuration

Groups

Global Settings allows you to create IP addresses or CIDR block lists. You can use the feature to implement batch association and centralized management of Web Application Firewall (WAF) and bot policies, preventing repeated settings of multiple rules. List changes are automatically synchronized to all associated policies to ensure global policy consistency.

Groups

Scenario-specific policies

The scenario policies allow you to address business peak situations such as new game launches and e-commerce promotions. With Major Event templates, DDoS protection policies are adjusted automatically. This adjustment ensures dynamic adaptation to traffic fluctuations during the designated activity period, reduces false positives for normal users, and maintains continuous business operations during high-concurrency periods.

Manage scenario-specific policies

Custom Page

By default, pages with an Edge Security Acceleration (ESA) identifier and the 403 error code are returned for requests that are blocked by ESA. If you want to use a personalized page with a business identifier, you can create a custom error page.

Configure a custom page

Tools

IP geolocation

After you add a website to Edge Security Acceleration (ESA), you can use the IP geolocation feature to check whether the actual IP address that clients request to access belongs to an ESA point of presence (POP), therefore verifies whether acceleration takes effect.

IP geolocation

Billing management

Plan management

You can query your plans, such as the plan type, status, expiration time, and associated websites, to better manage the plans.

Choose a plan that is right for you

Usage query

You can query usage to view traffic overviews and usage details for your websites or plans. This helps you monitor and analyze traffic.

Query usage

Dynamic Content Delivery Network

Feature set

Feature

Description

References

Content delivery

Domain name management

Alibaba Cloud Dynamic Content Delivery Network (DCDN) provides safe and secure acceleration services for content and computing workloads. The initial setup for DCDN requires only a few simple steps. This topic describes how to use DCDN.

Business Monitoring

Resource Monitoring collects data for metrics based on the region or carrier of client IP addresses. By monitoring your DCDN resources, you can obtain a comprehensive view of key metrics, such as bandwidth usage and cache hit ratio. This information helps you optimize your configurations.

The real-time monitoring feature collects data at a 1-minute granularity. You can view traffic, bandwidth, and origin fetch status for and DCDN from the previous minute. You can query data from the last 7 days. The maximum timestamp range for a single query is 24 hours. The 1-minute real-time monitoring data helps you quickly detect and DCDN traffic exceptions and locate issues.

Management tools

After you add an origin server to Dynamic Content Delivery Network (DCDN), you can use the IP address check feature to check whether the IP address that the client accesses belongs to a POP and determine whether the acceleration takes effect.

Detect IP addresses

Edge security

DDoS mitigation

If an accelerated domain name experiences a DDoS attack, it may be added to a sandbox, which causes service interruptions. You can enable the DCDN DDoS mitigation feature for important domain names or those that are at risk of attacks. After you enable the feature, DCDN accelerates your services and provides real-time detection, a fast response, and automatic protection against DDoS attacks.

DDoS mitigation feature

WAF protection

Dynamic Content Delivery Network (DCDN) is integrated with Web Application Firewall (WAF) to identify traffic patterns and filter out and block malicious requests.

Edge WAF protection (new)

Data center

Operations reports

You can use the operations report feature to query offline analytical data for your accelerated domain names over different time periods. This data helps you understand the operational status of your domain names and analyze your business performance.

Customize and subscribe to operations reports

Log Management

The log management service is used to analyze Dynamic Route for CDN (DCDN) logs to troubleshoot issues in a timely manner and improve service quality. This topic describes the log management service and features provided by DCDN.

Log Management

Usage query

Dynamic Route for CDN (DCDN) allows you to query the resource usage data of all your accelerated domain names by day or by month. Usage data is categorized based on billable items.

Query usage details

Edge computing service

Edge function

EdgeRoutine is a serverless runtime environment that allows you to write JavaScript code and deploy and execute it on Alibaba Cloud points of presence (POPs) worldwide. EdgeRoutine supports ES6 syntax and standard Web Service Worker APIs. With EdgeRoutine, user requests can be responded to and processed by the POP that is closest to users. This significantly reduces latency, accelerates response, and enhances user experience.

Edge Storage

Points of presence (POPs) provide the edge storage service EdgeKV, which is based on key-value pairs. After you write data to EdgeKV, the data can be automatically synchronized to POPs around the world. EdgeRoutine (ER) can read and use the key-value pairs on the same POP. You can use EdgeKV together with ER to deploy lightweight Blockchain as a Service (BaaS) services and API gateway services.

Edge Storage

IP Application Accelerator

Layer 4 acceleration

IP Application Accelerator (IPA) is an acceleration feature that is offered by Alibaba Cloud DCDN. IPA provides high-performance Layer 4 acceleration for traffic over TCP and UDP. It ensures low latency and high service stability for real-time interactions such as messaging in social media, data synchronization in online gaming, online education, and financial transactions.