How much time does Shield Advanced needed to propagate the protection plan to all edge locations?

0

A customer is wondering how much time does it need to take effect if they enable Shield Advanced to protect CloudFront?

The customer has a HTTP-based service which wants to leverage CloudFront and Shield Advanced to protect their origin. However, there is an additional data transfer out fee apply to Shield Advanced. They'd like to optimize the cost, thus they proposed the following solution.

  1. They will manually enable the protection when the data transfer grows up to a certain value. (or automate this by using API)
  2. They will disable the protection when the attack stops

Does anyone known how much time does it needed to propagate the protection plan to all edge locations?

profile pictureAWS
Joe SHI
已提問 6 年前檢視次數 334 次
1 個回答
1
已接受的答案

AWS Shield Advanced does not change how CloudFront mitigates attacks. Activating or deactivating a Protected Resource during an attack would not have any positive effect.

The benefit of adding the CloudFront distribution as a protected resource is that the traffic to that distribution will be baselined for the purpose of attack detection. This requires the resource to be permanently added as a Protected Resource. Similarly, the other benefits of AWS Shield Advanced, like AWS WAF at no additional cost, Cost Protection, and the SLA require the resource to be continuously subscribed.

已回答 6 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南