Connecting to the Origin Server ECS in Port Access Mode
Scenarios
If non-website access is used and the origin server is a Huawei Cloud ECS, access traffic may bypass AAD and directly reach the origin server. To avoid this risk, you are advised to use the port mode to connect to the origin server ECS.
Prerequisites
- You have purchased an AAD instance, and the access type is IP access. For details, see Purchasing an AAD Instance.
- Create an ECS. For details, see section Purchasing an ECS.
- Purchase an EIP. For details, see Obtaining an EIP.
Resource and Cost Planning
| Resource | Resource Description | Quantity | Cost Description |
|---|---|---|---|
| Elastic Cloud Server (ECS) | Bind an EIP. | 1 | For details about the ECS billing modes and standards, see ECS Billing. |
| AAD | Defend against DDoS attacks. | 1 | For details about the AAD billing modes and pricing, see AAD Billing. |
Step 1: Obtain the Back-to-Origin IP Address Range to the Whitelist
- Log in to the AAD console.
- In the navigation pane on the left, choose . The Forwarding Configuration page is displayed.
- Above the forwarding configuration list, click Back-to-Origin IP Address Range.
- In the Back-to-Origin IP Address Segment dialog box, view information about the back-to-origin IP address range.
Step 2: Add a Forwarding Rule
- Log in to the AAD console.
- In the navigation pane on the left, choose .
- Select the instance and route for the forwarding rule to be added.
- Click Add to add a forwarding rule and set parameters as required.
- Confirm that all information is correct and click OK.
Return to the forwarding rule page. If the new forwarding rule is displayed in the list and its status is normal, the access is successful.
Step 3: Allow the Origin IP Address in the ECS Security Group
- Log in to the ECS console.
- Choose ECSs > Name/ID. The Summary page is displayed.
- Click the security group name to go to the Inbound Rules tab page.
- Add the IP address range obtained in Step 1 to the inbound rule of the ECS security group.
Click Add Rule to go to the Add Inbound Rule page.
- Set the parameters as required and click OK.
The new rule is displayed on the Inbound Rules page.
Step 4: Verify the Connectivity
Open Telnet and run the following command to test the connectivity:
telnet <source-server-IP-address> <forwarding port> to check whether the ECS service can be accessed.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot