Exposed Origin IP

Troubleshoot attacks that bypass the protected IP and reach the origin directly.

Problem

If an origin IP remains discoverable or publicly reachable after the service is connected to a protected IP, attackers may bypass the protection service and attack the origin directly.

Updating DNS does not erase historical exposure. An attacker may already have recorded the old origin IP.

Common Exposure Paths

  • Historical DNS records pointed directly to the origin.
  • Other domains, subdomains, or services still use the same public IP.
  • Email, file-transfer, monitoring, or API services connect directly to the origin.
  • Application content, errors, logs, or third-party systems reveal the address.
  • The origin firewall permits unrestricted public access to application ports.

Resolution

  1. Confirm the bypass: Verify that the attack targets the origin IP, rather than the protected IP or a broken origin path.
  2. Inventory exposure: Check current and historical DNS, related domains, third-party services, and published configuration.
  3. Restrict origin access: Permit only required administration sources and confirmed protection-service traffic on application ports.
  4. Evaluate a new IP: If the old address is under sustained attack, request a new public IP from the infrastructure provider.
  5. Update origin rules: Change the origin server in the console and verify protocol, port, domain, and certificate settings.
  6. Verify before cutover: Confirm that the service works through the protected IP before retiring the old origin address.
Firewall changes or replacing an origin IP can interrupt service immediately. Confirm allowed forwarding sources, retain administrative access, and prepare a rollback first.

Verification Checklist

  • Public DNS no longer returns the origin IP.
  • The service works through the protected IP.
  • Unauthorized public sources cannot reach the origin application port directly.
  • Origin logs no longer show abnormal traffic bypassing the protection path.
  • Independent email, monitoring, and callback services still work.

Support

If you cannot identify the forwarding source or attack path, prepare the instance ID, protected IP, origin IP, event time, and relevant logs, then email hy.swzx@hiddos.cn.