Determination Basis: Node Location, Not Protection Type
Whether a high-defense CDN requires ICP filing is not determined by the 'high-defense' attribute, but strictly by the physical deployment region of the CDN nodes. Whether it's a regular acceleration CDN or a high-defense CDN with DDoS scrubbing, as long as it uses nodes within mainland China, the accessing domain must hold an MIIT ICP filing number; if only Hong Kong or overseas nodes are used, no ICP filing is required at all.
This rule comes from the compliance supervision of domestic CDN services under the 'Measures for the Administration of Internet Information Services': domestic nodes verify the filing status when binding a domain, and unregistered domains are automatically blocked by the system.
Filing Requirements for Two Node Configurations
Using Mainland Nodes: Filing Required
If your high-defense CDN acceleration scope is set to 'Mainland China' or 'Global (including mainland China)', the scheduling system will allocate domestic scrubbing and acceleration nodes, and the domain must complete MIIT ICP filing. Even if the origin server is deployed overseas, as long as the front-end CDN uses domestic nodes to provide services, the domain still needs filing.
The advantage of mainland nodes is the lowest latency for domestic visitors and complete coverage of the three major networks, but the filing process usually takes days to weeks and cannot handle emergency access during sudden attacks.
Using Hong Kong or Overseas Nodes: No Filing Required
If the high-defense CDN is configured for regions such as 'Hong Kong, China', 'Overseas', or 'Asia-Pacific (excluding mainland)', all nodes are deployed outside the mainland, and the domain is completely exempt from MIIT ICP filing jurisdiction and can be accessed directly. Even if your origin is within the mainland, as long as the front-end high-defense nodes are overseas, the domain does not require filing.
This configuration is suitable for unregistered domains, cross-border business, and emergency scenarios that require protection to be online within minutes.
Selection Solutions for Unregistered Domains and Emergency Protection
Scenario 1: Domain not filed, needs immediate defense against attacks
The traditional mainland filing process cannot be completed urgently when an attack occurs. The standard practice is to choose a no-filing Hong Kong or overseas high-defense CDN, switch DNS resolution to the scrubbing nodes, and get DDoS and CC protection online within minutes without waiting for filing review.
Scenario 2: Not filed but need to balance domestic visitor experience
When Hong Kong or overseas nodes connect directly to domestic visitors, if they go through the public international gateway, latency and packet loss may be high. The solution is to choose no-filing high-defense nodes equipped with CN2 direct connections: such nodes are physically located in Hong Kong or overseas (no filing required), but the return link to China uses China Telecom CN2 GIA or optimized dedicated lines from China Unicom/China Mobile, keeping latency for domestic visitors close to that of mainland nodes.
RockCloud's CN2 No-Filing Acceleration solution integrates high-defense scrubbing and CN2 return acceleration in the same link, with fixed peak billing and unlimited traffic, so you don't pay separately for defense. It is suitable for businesses with unregistered domains that need immediate protection without sacrificing domestic access quality. Supports access after free testing.
Key Points to Check
- Look at node region, not origin location: Origin in mainland, CDN nodes in Hong Kong – no filing required; origin overseas, CDN nodes in mainland – filing required.
- Prioritize no-filing nodes for emergencies: When an attack occurs, you cannot wait for filing review; switch directly to Hong Kong/overseas high-defense nodes to stop the bleeding.
- Choose CN2 lines to balance domestic visitors: No-filing nodes paired with CN2 GIA or three-network direct dedicated lines can ensure domestic latency without filing.
- Confirm whether billing and defense are separate: Some providers charge separately for scrubbing on overseas high-defense; check the cost structure when selecting.
If your domain is under attack and not yet filed, or you need to evaluate the return latency and scrubbing capability of a no-filing high-defense solution, you can apply for testing and access guidance through the Emergency Access Portal.
Comments(0)