tencent cloud

Tencent Cloud EdgeOne

Cross-regional Secure Acceleration (Oversea Sites)

Download
Focus Mode
Font Size
Last updated: 2026-08-07 14:41:33
AI-Translated
EdgeOne provides a cross-regional performance and security solution to help users address network latency and security challenges in global business deployments. Through its globally distributed edge nodes, EdgeOne offers users in different regions a one-stop acceleration and security service, including nearby access, intelligent routing, DDoS protection, and Web protection.
Cross-MLC-border Secure Acceleration is a specialized capability launched by EdgeOne for overseas services and Mainland China user access scenarios. It applies to the following business requirements:
The origin site is deployed in regions outside Mainland China, such as Hong Kong (China), Singapore, or the United States, but it needs to provide users in Mainland China with a low-latency, highly stable access experience.
Your service is under cross-region traffic attack. You need to combine acceleration and security protection capabilities.
You need to complete the configuration for global access performance optimization, DDoS protection, Web protection, cache acceleration, and more in a one-stop manner.
Attention:
This feature is only available in the EdgeOne Enterprise plan.

Background Introduction

A certain Web service is deployed overseas and provides services to the public through www.example.us (overseas site). It is temporarily unable to be hosted on servers within Mainland China due to its overseas location. This poses challenges for the service as its main customer base is located in Mainland China, resulting in network issues such as delays, jitter, packet loss, and the risk of interruptions. To optimize the user experience for Mainland China users, EdgeOne provides the Cross-MLC-border acceleration function, which leverages the Hong Kong access point and Tencent Cloud acceleration network to effectively solve the problems faced by cross-regional services.

Solution Description

Based on your business protection requirements, this solution can be divided into the following two types:
Solution 1: Enable Cross-MLC-border Acceleration Only. This solution applies to scenarios where you only need to improve the access experience for users in Mainland China to your overseas site and do not require additional DDoS/CC protection capabilities.
When your service is under attack, traffic from Mainland China is prioritized to use the resources of the overseas Anti-DDoS scrubbing centers, and Cross-MLC-border Acceleration is temporarily disabled. After the attack ends, the Cross-MLC-border Acceleration effect is restored. During the switching process, client connections may be reset.
An additional traffic fee will be charged for the Cross-MLC-border Acceleration feature. For details, refer to Cross-MLC-border acceleration traffic fee (Pay-as-You-Go).




Solution 2: Cross-MLC-border Acceleration + Cross-Region DDoS/CC Protection
. If, in addition to Solution 1, you also require dedicated DDoS/CC attack protection for the "Cross-MLC-border Acceleration" route, you can subscribe to a DDoS Defender plan (Essential/Premium) and the Cross-Region Protection Capability Add-on on top of Solution 1, and configure the DDoS protection level for your domain names or L4 proxy instances to Ultimate Protection.
When your service is under attack, attack traffic originating from Mainland China is scrubbed by the three major carriers and then reinjected into the EdgeOne Hong Kong (China) access node. Attacks originating from outside Mainland China are defended using overseas scrubbing center nodes, ensuring the access experience for normal users to the greatest extent possible during the attack.
The billing items for Solution 2 include the base plan fee, cross-region protection capability add-on fee, and protected resources fee within the DDoS Defender, as well as the DDoS Clean Traffic Fee (Cross-Region), in addition to the Cross-MLC-border acceleration traffic fee (Pay-as-You-Go).
Attention:
When using Solution 2, note the following restrictions:
1. Security Protetion Policy Always Remains Active: To ensure the security of the Cross-MLC-border Acceleration route, the cross-region security protection policy always remains active after being enabled (regardless of whether an attack is currently in progress). During the scrubbing process, a small number of normal requests may be mistakenly blocked. We recommend that your client has a retry mechanism. For long-lived connections and high-real-time services (such as gaming, audio/video interaction), enabling this policy may introduce additional latency or connection interruption risks. We recommend that you first verify service compatibility on a small scale before enabling it fully.
2. Protection Limitations in Extreme Scenarios: When extremely high-volume attacks or unknown new attack methods are faced, there remains a certain risk of penetration, and 100% interception cannot be guaranteed.
3. Multi-tenant Joint Protection Impact: When multiple customers are under DDoS attack simultaneously within the same time period, the system may temporarily lower the blocking threshold for a single IP address. In this case, your service IP address may be mistakenly blocked.


User Guide

Prerequisites

You need to add a site according to the Site Access guide, purchase an EdgeOne Enterprise plan, and set the acceleration region for Layer 7 domains/Layer 4 instances to Global (excluding Mainland China) area.

Enabling Cross-MLC-border Acceleration

Scenario 1: Configure L7 site-wide acceleration
Scenario 2: Configure a single L4 proxy acceleration
If you need to enable the Cross-MLC-border acceleration function for the entire site, please follow the steps below:
1. Log in to the Tencent Cloud EdgeOne console, enter Service Overview in the left menu bar, and click the site to be configured under Website Security Acceleration.
2. On the site details page, click Site Acceleration to enter the Site Global Configuration page. In the right-hand navigation bar, click Network Optimization.
3. On the network optimization page, find the Cross-MLC-border acceleration function configuration card, and click

to enable the Cross-MLC-border acceleration function for the entire site.

4. In the confirmation window, click Enable to complete the configuration.

If you need to enable the Cross-MLC-border acceleration function for a single L4 proxy instance, please follow the steps below:
1. Log in to the Tencent Cloud EdgeOne console, enter Service Overview in the left menu bar, and click the site to be configured under Website Security Acceleration.
2. On the site details page, click L4 Proxy and then Target Instance Name.
3. Under the target L4 proxy instance, find the Cross-MLC-border acceleration function, and click

to enable the Cross-MLC-border acceleration function for this instance.

4. In the confirmation window, click Enable to complete the configuration.


Perform an Access Test

Scenario 1: Configure L7 site-wide acceleration
Scenario 2: Configure a single L4 proxy acceleration
For domains that have enabled the Cross-MLC-border acceleration function, when the customer initiates a visit from the Chinese Mainland, EdgeOne will automatically schedule the access to the Hong Kong access node. You can verify this by checking whether the currently assigned node belongs to Hong Kong, China.
1. You can obtain the IP address of the assigned node by using any of the following methods:
Attention:
Please ensure that the access test is initiated from the Chinese Mainland since the Cross-MLC-border acceleration function affects the outgoing user requests from the Chinese Mainland.
Windows
Mac/Linux
Visit the site
In Windows system, open the command prompt. Taking the domain www.example.com as an example, run the nslookup -qt=A www.example.com command. Then you can get the IP address of the domain obtained by the A record resolution.

In Mac/Linux system, you can use the dig command for verification. Taking the domain www.example.com as an example, run the dig www.example.com command in the terminal. Then you can get the IP address of the domain obtained by the A record resolution.

You can also obtain the IP address by visiting the site. Taking the domain www.example.com as an example, you can press F12 in the browser to open the developer tools. Then click any request record, and you can view the IP address that the request points to.

2. You can query the location information of the IP through any IP query tool. If it belongs to Tencent Hong Kong, the Chinese mainland network optimization (international acceleration) function is effective.
For L4 proxy instances that have enabled the Cross-MLC-border acceleration function, when the customer initiates a visit from the Chinese Mainland, EdgeOne will automatically schedule the access to the Hong Kong access node. You can verify this by checking whether the currently assigned node belongs to Hong Kong, China.
1. View the L4 proxy instance access domain name. On the site details page, click L4 Proxy. Under the target L4 proxy instances, view the access domain name.

2. You can obtain the IP address of the assigned node by using any of the following methods:
Windows
Mac/Linux
In Windows system, open the command prompt. Taking the domain example.com.eo.dnse.com as an example, run the nslookup -qt=A example.com.eo.dnse.com command. Then you can get the IP address of the domain obtained by the A record resolution.

In Mac/Linux system, you can use the dig command for verification. Taking the example.com.eo.dnse.com as an example, run the dig example.com.eo.dnse.com command in the terminal. Then you can get the IP address of the domain obtained by the A record resolution.

3. You can query the location information of the IP through any IP query tool. If it belongs to Tencent Hong Kong, the Chinese mainland network optimization (international acceleration) function is effective.

Configuring DDoS Protection (Optional)

If you decide to adopt Solution 2, which adds DDoS/CC protection capabilities on top of the Cross-MLC-border Acceleration, you also need to perform the following steps:
1. Subscribe to DDoS Defender service. Select any base plan and the Cross-Region Protection Capability add-on.
2. Configure the DDoS protection level to Ultimate Protection for the domain names or L4 proxy instances that have enabled the Cross-MLC-border Acceleration feature.
After the above configuration is completed, the IP address assigned to you will be changed to enable cross-region security protection capabilities.
Attention:
If you decide to unsubscribe from Cross-MLC-border Acceleration capability later, first ensure that the DDoS protection level for the relevant domain names or L4 proxy instances has been changed to Standard Protection or Advanced Protection. Then, disable the Cross-MLC-border Acceleration switch. Otherwise, EdgeOne will perform configuration validation and block this operation.














Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback