Reverse proxy
A reverse proxy is a layer-7 application, which talks directly to the client resolvers.
We use this method on our DNS2 anycast. In this scenario, we have an arrangement with a completely separate DDoS mitigation provider who operates their own DDoS-protected CDN.
Then we have a private constellation sitting behind that CDN, and our DNS2 nameserver IP is published as the public-facing CDN.
Queries come in to the mitigation layer, which is always active, and that passes clean traffic back to our layer, which responds back to the CDN, which responds back to the client. Excessive round-trips are minimized by the mitigation layer, optimizing RTTs to the nearest private nodes and by maintaining a query cache, it will answer back from ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access