Because network attacks happen from time to time, in order to ensure the normal and stable operation of the website, many users will configure the high-defense IP for the website, but there may be some users who will prompt a 502 error after configuring the high-defense IP. The anti-IP is the source site itself. In this article, we will analyze the reasons and solutions for the 502 error after the high-defense IP is configured on the website.
Reason 1: Anti-DDoS Pro back-to-source IP is intercepted or speed-limited by the source site
After the website is configured with Anti-Defense IP, the IP of the source site will be hidden because the Anti-Defense IP is in the middle of the proxy. Therefore, from the perspective of the source site, all client IPs accessed through the Anti-Defense IP service will become Anti-Defense Pro's back-to-source IP. Under normal circumstances, the client requests to access the high-defense IP of the website. After receiving the request, the high-defense IP service converts the client IP into the high-defense back-to-source IP and sends it to the source site. If the source site IP is exposed, the client can directly request to access the source site, which will bypass the protection provided by Anti-DDoS Pro.
When the Anti-Defense Proxy is not configured, the source site sees that the client addresses are very scattered. Under normal circumstances, the request amount of each source IP is not large, and the IP segment of Anti-Defense back to the source after the website is configured with Anti-Defense IP service Fixed and limited, so from the source site, all access requests come from the high-defense back-to-source IP segment, and the request volume will increase, which may cause the source site to mistakenly think that the high-defense back-to-source IP is attacking the source site, and if the source If the website has a security policy to defend against DDoS, it may block or limit the return-to-source IP.
According to the above principles, as long as all the anti-virus back-to-source IPs are released on the source site of the website, the 502 error can be solved. There are two ways to set the source site to no longer block or limit the speed of anti-virus back-to-source IPs:
Method 1: In the firewall and host security protection software of the source site, add the anti-virus back-to-source IP network segment to the white list of the website.
Method 2: Directly close the firewall and website security software of the source site.
Reason 2: The source site itself is abnorma
Abnormalities of the source site of the website itself include the following situations:
1) The IP of the source site is exposed, and the website system is paralyzed by malicious attacks.
2) There is a physical failure in the computer room of the source website.
3) There are problems with web programs such as Apache and Nginx in the origin server.
4) The CPU and memory usage of the website is too high, resulting in a sudden drop in performance.
5) The uplink of the source station is congested and blocked.
Judgment method:
Modify the website hosts file and point the domain name directly to the IP of the source site. If you cannot access it directly through the IP of the source site, and accompanied by Ping source site IP packet loss, telnet timeout, etc., it can be judged to be caused by such reasons.
Troubleshooting steps:
1: Check whether there is a large increase in the traffic and request volume of the source site, and compare the monitoring in the Anti-Defense IP management console. If the source site is attacked by a large amount of traffic but the Anti-Defense IP management console shows no abnormalities, it may be an attack bypass Directly attack the source site through the Anti-Defense IP of the website. In this case, you need to change the source site IP as soon as possible.
2: After excluding the cause of the attack, you can check the process status, CPU and memory usage of the source site website, and the monitoring status of the bandwidth of the computer room, etc. If there is any abnormality, you need to contact the relevant technical personnel of the website or the personnel in the computer room to assist in troubleshooting.
3: If an individual client prompts a 502 error, it is recommended to collect the client IP and the time when the exception occurred, and report to the website's after-sales technical support to assist in the investigation.
The above are the reasons and solutions for the 502 error prompt after the high-defense IP is configured on the website, hoping to help website users in need