Requirement Background
Affected by objective factors, Anti-DDoS Pro only supports users in Beijing, Shanghai, and Guangzhou regions of Tencent Cloud and promises full protection capabilities. Full protection aims to successfully defend against every DDoS attack, integrating the current local cleaning center capabilities while dynamically adjusting according to the actual network status at that time to fully resist attacks. In addition, high-defense package products have not yet been launched in other regions of the Chinese mainland such as Chengdu and Chongqing. If a user's business origin server is deployed on Tencent Cloud and needs to use the Anti-DDoS Pro protection capability of non-origin server regions of Tencent Cloud, this solution can be referred to.
Protection Solution
This solution mainly consists of Anti-DDoS Pro, Cloud Load Balancer (CLB), and origin server business servers. Deploy CLB in regions with Anti-DDoS Pro resources and bind it with Anti-DDoS Pro. Configure the private network origin-pull rules of CLB to ensure that the business can be accessed through the public IP of CLB.
Under regular circumstances, the business can resolve to the origin server's public IP address as needed (or directly resolve to the CLB public IP address in a different location), allowing business traffic to access the origin server nearby.
After an attack occurs, resolve the business to the CLB IP address to clean the DDoS attack traffic. After cleaning is completed, CLB forwards the traffic back to the origin server through the private network dedicated line.
The specific protection solution is shown in the following figure:

Solution Effect
Break the limitation of regional protection capabilities and have up to 300 Gbps of Anti-DDoS protection capabilities.
Business traffic is forwarded using Tencent Cloud's private network dedicated line, which has high reliability and low delay.
Fully enjoy the advantages of Tencent Cloud's Anti-DDoS network. All public IP addresses are BGP IPs with low delay.
Advice and Precautions
Deploy Anti-DDoS Pro and CLB instances in advance.
Establish a business availability monitoring mechanism. In the absence of an automatic switching mechanism, intervene in a timely manner when access exceptions to the origin server are detected.
Conduct verification and drills regularly to understand and be familiar with the details of the solution and solve possible problems.