SNS-IX Service Configuration

CDN & SCDN faster and safer

Deliver content closer to your users and protect websites and APIs at the edge. CDN for delivery; SCDN for WAF, L7 DDoS controls, bot management and HTTPS.

01 · Content Delivery
CDN
02 · SCDN Web Protection
WAF
03 · Secure Connections
TLS
01HOW THE SERVICE WORKS

CDN & SCDN from SNS-IX

We assess your audience, origin and traffic profile, then select CDN delivery or SCDN with web protection. Local caching in Tashkent and external coverage are available design options. Delivery regions, security processing and performance targets are defined for your configuration.

Service illustration: a compact bank of edge cache and storage servers.
Service illustration
speed
01

Faster delivery

Serving cacheable content closer to the audience can shorten load times and support stronger user journeys.

dns
02

Origin offload

CDN handles static file delivery, reducing your backend load and outbound costs.

security
03

Security at the edge

SCDN adds WAF, L7 flood and bot controls before requests reach the application. Modules and policies are selected for your service.

CDN + Security CDN

Fast delivery. Protected access.

A CDN accelerates content delivery. SCDN adds request inspection and web application protection at the edge, before requests reach your origin. Choose the scope around your workload and its risks.

CDN

Content delivery

When the main goal is faster loading and fewer repeated requests to the origin.

  • Static caching and cache lifetime policies.
  • Optimized delivery of images, files and application assets.
  • Measurement of cache hits, latency and origin load.
CDN onboarding
SCDN

Acceleration & security

When a website or API needs both performance and protection against malicious requests.

  • CDN, WAF, L7 DDoS protection and bot management in one delivery path.
  • HTTPS configuration and origin connection policies.
  • Domain-level policies and security events for analysis.
SCDN capabilities
L3 / L4

IP network protection

For network prefixes and TCP/UDP services that require more than a web proxy.

  • Network scrubbing for volumetric and protocol attacks.
  • BGP and an agreed clean-traffic delivery path.
  • A dedicated design for network assets.
Network Anti-DDoS

How protected delivery works

  1. 01

    Visitor → SCDN

    DNS routes domain requests to the security and delivery edge.

  2. 02

    Inspection & cache

    Security policies are applied; eligible content is served from cache.

  3. 03

    SCDN → origin

    Allowed dynamic requests and cache misses are forwarded to the origin.

Accounts, payments and personalized API responses need specific policies: they must not be indiscriminately stored in a shared cache. Delivery and security rules are configured together.

In detail

What SCDN can do

One request path combines delivery optimization, application protection and access control. We select functions per domain and validate them against real user journeys.

WAF & virtual patching

Rules address SQL injection, XSS, unsafe file uploads and scanning. Custom policies can restrict an identified exploit path while an application fix is prepared. Observation mode helps assess matches before blocking.

L7 DDoS & HTTP floods

Request-rate and access controls reduce automated flood load, including CC attacks. Browser traffic can use client challenges; APIs and mobile applications need separately tuned rules.

Bots & abuse

Automated-traffic analysis helps identify scraping and credential attacks. Policies support observation, blocking or verification, with exceptions for useful crawlers and integrations.

Caching & origin delivery

Resource-specific lifetimes, gzip, WebP adaptation and browser caching optimize delivery. Persistent connections, Range requests and origin health checks support file delivery and dynamic responses.

TLS & protocols

Upload your certificates or use managed issuance and renewal when domain-validation requirements are met. Origin HTTPS, HTTP/2, WebSocket and headers are configured for the application.

Policies & analytics

WAF events, request sources and bot data help explain what is being blocked and why. IP, URL and request conditions allow tuning for login, search and APIs. Log access and retention are agreed for the configuration.

02USE CASES

Designed for:

Delivery and security for critical digital user journeys.

01 shopping_cart

Commerce

Deliver catalogs faster and apply tailored controls to checkout, login and scraping traffic.

02 play_circle

Media

More consistent delivery of heavy files, previews and static assets during demand peaks.

03 smartphone

Mobile apps

Deliver updates and protect web APIs using policies compatible with machine clients.

04 school

Education

Stable, high-bandwidth delivery of educational video content.

Service illustration: cache server modules, storage bays and optical uplinks. Service illustration
03Measured for Your Audience

Edge delivery design

We select the cache topology, regions, origin rules, TLS settings and purge strategy around your traffic. The delivery footprint can combine local SNS-IX nodes with external CDN partners; final capacity and performance targets are documented before launch.

Scoped
Regions & Capacity
Measured
Cache Performance
Integration Flow
01

Assess

Domains, origins, audience, traffic, security needs and critical workflows.

02

Configure

DNS integration, certificates, cache rules, origin access and selected security modules.

03

Pilot

Compare performance and test WAF matches, API calls, login, payment and integrations.

04

Launch & tune

Switch traffic in the agreed window, monitor events and refine policies.

04Seamless Onboarding

Validate before switching

We prepare DNS, TLS, cache and origin rules before switching traffic. For SCDN, we validate security policies against login, payment, APIs and integrations, then agree the launch and rollback procedure.

verified Powered by 24/7 NOC Support
Common Questions

FAQ

What is the difference between CDN and SCDN?

add
A CDN handles delivery: it caches eligible resources closer to the audience and reduces repeated origin load. SCDN adds web traffic protection through WAF, L7 DDoS controls, bot management and TLS. Modules are selected for the application; using a CDN does not by itself mean WAF protection is enabled.

Which websites and applications can be connected?

add
SCDN suits HTTP/HTTPS websites and APIs, including shops, account portals, SaaS and mobile application web services. The origin can be hosted in your own infrastructure or a cloud if the required connectivity is available. Arbitrary TCP/UDP protocols need a separately designed network protection service.

Do I need to move the website or change its code?

add
The origin usually remains where it is, and DNS changes direct traffic through SCDN. CNAME or NS integration is selected for the design. Code changes are often unnecessary, but resource URLs, real-client-IP headers, TLS, redirects, origin access restrictions and integrations must be validated.

What is cached and what must reach the origin?

add
Shared images, stylesheets, scripts and files are commonly cached for agreed lifetimes. Personalized pages, carts, payments and API responses need bypass rules or correctly isolated cache keys. Policies are checked against cookies, authorization, URL parameters and application headers.

Can SCDN accelerate dynamic requests and APIs?

add
A dynamic response does not have to be cached: it can pass through the edge with connection and origin-route optimization. Results depend on audience location, network paths and application processing time. The pilot measures cacheable resources and dynamic operations separately; a CDN alone does not fix a slow database.

What does the WAF inspect?

add
The WAF inspects web requests for SQL injection, XSS, malicious scanning, unsafe uploads and exploit attempts. Managed and custom rules can be observed before blocking is enabled. It is an additional layer in front of the application, not a substitute for patching, secure code or application authorization.

How does SCDN address HTTP floods and CC attacks?

add
These attacks generate requests that consume web application resources. Controls include rate limits, request-condition policies and client verification. Thresholds account for normal traffic and individual URLs so a marketing campaign or sale is not mistaken for an attack.

How are malicious bots separated from crawlers and integrations?

add
Bot management analyzes automated traffic and supports observation, blocking or verification. Appropriate exceptions are configured for required search crawlers, partner systems and monitoring. Changes are reviewed through logs and workflow availability; an unknown bot should not automatically be treated as trusted.

Will protection break APIs, webhooks or mobile applications?

add
Browser CAPTCHA or JavaScript challenges must not be enabled indiscriminately for machine clients. They need separate access conditions, rate limits and exceptions for trusted workflows. Authentication, payment callbacks, uploads and other critical operations are tested before switching; observation mode helps identify unwanted matches.

How are HTTPS and origin access configured?

add
Both connection legs are checked: visitor to SCDN and SCDN to origin. Your own certificates or managed issuance and renewal can be used when domain validation requirements are met. Origin protection restricts direct access and configures trusted sources; an edge certificate alone does not enable HTTPS to the origin.

Are WebSocket, HTTP/2 and large files supported?

add
The SCDN platform supports HTTP/2, WebSocket enablement and Range requests for partial file delivery. Supported ports, object sizes, connection lifetimes and cache policies are checked for your application. Platform support does not remove the need to validate the selected package’s limits.

How do we update content and measure results?

add
Before launch, cache lifetimes, purge procedures and file versioning are agreed. The pilot compares response times, cache hit ratios, errors and origin load. SCDN adds review of WAF and bot events and successful login, checkout and other critical actions.

Where is traffic processed and how long are logs retained?

add
Delivery and processing regions, log access and retention depend on the configuration. Data and location requirements should be provided before the design is selected. A local cache in Tashkent does not mean that all protection processing and logs are automatically hosted only in Uzbekistan.

What determines service scope and pricing?

add
A proposal needs domains, geography, traffic profile and volume, peak load and the required security modules. Limits, analytics access, support and SLA are explicitly defined. The process can start with an assessment and an agreed pilot; timing and terms follow application review.
Service illustration: cache server modules, storage bays and optical uplinks. Service illustration
Plan the next step

Build your delivery and protection plan

Tell us your domains, audience and critical workflows. We will propose CDN or SCDN, the required policies and a validation plan.