How much time does Shield Advanced needed to propagate the protection plan to all edge locations?

0

A customer is wondering how much time does it need to take effect if they enable Shield Advanced to protect CloudFront?

The customer has a HTTP-based service which wants to leverage CloudFront and Shield Advanced to protect their origin. However, there is an additional data transfer out fee apply to Shield Advanced. They'd like to optimize the cost, thus they proposed the following solution.

  1. They will manually enable the protection when the data transfer grows up to a certain value. (or automate this by using API)
  2. They will disable the protection when the attack stops

Does anyone known how much time does it needed to propagate the protection plan to all edge locations?

profile pictureAWS
Joe SHI
已提问 6 年前335 查看次数
1 回答
1
已接受的回答

AWS Shield Advanced does not change how CloudFront mitigates attacks. Activating or deactivating a Protected Resource during an attack would not have any positive effect.

The benefit of adding the CloudFront distribution as a protected resource is that the traffic to that distribution will be baselined for the purpose of attack detection. This requires the resource to be permanently added as a Protected Resource. Similarly, the other benefits of AWS Shield Advanced, like AWS WAF at no additional cost, Cost Protection, and the SLA require the resource to be continuously subscribed.

已回答 6 年前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则