Modifying Domain Name Configuration
After a domain name is connected to Advanced Anti-DDoS, if the origin server information changes, you can update the configuration on the console. You can modify the origin server type, forwarding protocol, origin server port, and SSL certificate. This section describes how to modify a domain name configuration.
- Modifying the origin server IP address may cause protection failure or service interruption. Exercise caution when performing this operation.
- If you cannot evaluate the risks, submit a service ticket for consultation.
Limitations and Constraints
- If this protected domain name will share a high-defense IP address and port with another domain name, ensure that they have the same Origin Server Type value.
- To change the Origin Server Type value from IP address to Domain name, ensure that Basic Web Protection is disabled for the domain name.
- A maximum of two different ports can be used across all website services connected to an Advanced Anti-DDoS instance.
Modifying Domain Name Configuration
- Log in to the AAD console.
- In the navigation pane on the left, choose . The Domain Name Access page is displayed.
- In the row containing the desired domain name, click Modify in the Operation column.
- In the Modify Domain Name dialog box that is displayed, modify the domain name configurations. Figure 1 Modifying the domain name configuration
Table 1 Parameter description Parameter
Description
Domain Name
This parameter cannot be modified.
Origin Server Type
- IP address: Public IP address of the origin server. Enter a maximum of 20 IP addresses and separate them using commas (,). The IP addresses must be unique.
- If the origin server is on Huawei Cloud, enter the EIP of the ECS.
- If the origin server is not on Huawei Cloud, run ping DomainName to resolve the IP address.
- Domain name
Currently, only Huawei Cloud WAF CNAMEs are supported.
Domain names can only contain letters, numbers, hyphens (-), underscores (_), and periods (.). They cannot start or end with a hyphen (-) or underscore (_). The length of a single segment cannot exceed 63 characters, and the total length cannot exceed 255 characters.
- Forwarding Protocol
Protocol used by AAD to forward requests from clients (such as browsers) The options are HTTP and HTTPS.
Up to two forwarding protocols can be configured.
- Origin Server Port
Port used by AAD to forward client requests to the server
The default port for HTTP is 80, and the default port for HTTPS is 443.
NOTICE:- If the protected domain name to be added shares the high-defense IP address and protocol or port with another domain name, the values for the Origin Server Type of these domain names must be the same.
- If the Origin Server Type of other domain names is IP address, ensure that web attack protection has been enabled for these domain names.
- If Origin Server Type of the other domain name is set to Domain name, ensure that the two domain names are connected to the same WAF region.
- Do not alter or remove the CNAME details of the first origin server on WAF. Should changes be necessary, first remove the related domain name details in AAD, then proceed with modifications or deletions in the WAF settings.
- If Origin Server Type is set to Domain name, ensure that the domain name has been allowed to use a proxy. Otherwise, the service may be unavailable after being connected to AAD.
- If you connect your service to AAD using a WAF CNAME but no longer need WAF protection, delete the service domain name from AAD first.
Certificate Name
If Origin Server Type is set to Origin Server IP Address and Forwarding Protocol is set to HTTPS, you need to upload a certificate.
For details about how to update a certificate, see Updating a Certificate.
- IP address: Public IP address of the origin server. Enter a maximum of 20 IP addresses and separate them using commas (,). The IP addresses must be unique.
- Click OK.
Related Operations
- If the domain name supports HTTP/2, you can modify it on the Domain Name Access page. For details, see Setting the HTTP2 Protocol.
- You can modify the LTS configuration on the Domain Name Access page. For details, see Modify TLS Configuration.
- You can update, view, or delete certificates on the Domain Name Access page. For details, see Certificate Management.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot