Overview
This guide will cover the L4 proxy service. It protects a single IP address (Internet-facing asset) against incoming threats. It includes Network DDoS protection, IP reputation, and Geo-fencing. If you have been assigned a Threat Protection Frontend IP from our anycast range, you can protect your asset by updating the A-record in your DNS server to point to the Frontend IP of the installed L4 Proxy. Customers who route their whole network through our Threat Protection Centers (Routed DSR) can create a proxy service using a Frontend IP from their own prefix (Customer Anycast IP range) without the need for any DNS changes mentioned in this document. This is called Route-to-Proxy.
To ensure a successful setup, the right staff members from your team should be available during the process.
* A proxy service can be created, installed, and set to protect an asset in approximately 5-10 minutes, if the following conditions are met:
- The customer account is already set up
- The customer has set a low TTL (120 seconds or less)
Deploying L4 proxy services
Proxies are configured using assigned anycast IPs from Threat Protection’s or the customer’s own prefixes. Proxy traffic is bidirectional through our Threat Protection Centers. All traffic from our TPCs to your backend services is proxied. We can pass the original client IP address via a PROXY protocol header. This needs to be enabled in the L4 proxy configuration, as explained in the configuration section.
Benefits of L4 proxy deployments
- Quickly protect Internet-facing assets in 5-10 minutes
- Protection from DDoS attacks (Layer 3 & 4)
- Protection from known bad actors (IP Reputation)
- Easy-to-use geofencing
- Always on protection
- Low false positives and false negatives