How much time does Shield Advanced needed to propagate the protection plan to all edge locations?

0

A customer is wondering how much time does it need to take effect if they enable Shield Advanced to protect CloudFront?

The customer has a HTTP-based service which wants to leverage CloudFront and Shield Advanced to protect their origin. However, there is an additional data transfer out fee apply to Shield Advanced. They'd like to optimize the cost, thus they proposed the following solution.

  1. They will manually enable the protection when the data transfer grows up to a certain value. (or automate this by using API)
  2. They will disable the protection when the attack stops

Does anyone known how much time does it needed to propagate the protection plan to all edge locations?

1개 답변
1
수락된 답변

AWS Shield Advanced does not change how CloudFront mitigates attacks. Activating or deactivating a Protected Resource during an attack would not have any positive effect.

The benefit of adding the CloudFront distribution as a protected resource is that the traffic to that distribution will be baselined for the purpose of attack detection. This requires the resource to be permanently added as a Protected Resource. Similarly, the other benefits of AWS Shield Advanced, like AWS WAF at no additional cost, Cost Protection, and the SLA require the resource to be continuously subscribed.

답변함 6년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠