# Welcome to the Medianova Knowledge Base

<p align="center">Comprehensive CDN documentation and API references, with integration, troubleshooting and developer guides across all Medianova services.</p>

<table data-view="cards" data-full-width="false"><thead><tr><th align="center"></th><th></th><th></th><th></th><th></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td align="center"><strong>Security</strong></td><td><a href="https://medianova-cloud.gitbook.io/clients.medianova.com/products/security/web-application-firewall-waf">Web Application Firewall</a></td><td><a href="https://medianova-cloud.gitbook.io/clients.medianova.com/products/security/ddos-protection">DDoS Protection</a></td><td><a href="https://medianova-cloud.gitbook.io/clients.medianova.com/products/security/rate-limiting">Rate Limiting</a></td><td><a href="https://medianova-cloud.gitbook.io/clients.medianova.com/products/security/geoblocking">Geoblocking</a></td><td><a href="https://medianova-cloud.gitbook.io/clients.medianova.com/products/security/ip-restriction">IP Restriction</a></td><td><a href="/files/mwdsnPerfwMuRopq2Kkc">/files/mwdsnPerfwMuRopq2Kkc</a></td></tr><tr><td align="center"><strong>Performance</strong></td><td><a href="https://medianova-cloud.gitbook.io/clients.medianova.com/products/performance-cdn/static-content-delivery">Static CDN</a></td><td><a href="https://medianova-cloud.gitbook.io/clients.medianova.com/products/performance-cdn/dynamic-content-acceleration">Dynamic CDN</a></td><td><a href="https://medianova-cloud.gitbook.io/clients.medianova.com/products/performance-cdn/streaming-content-delivery">Streaming</a></td><td><a href="https://medianova-cloud.gitbook.io/clients.medianova.com/products/performance-cdn/image-optimization-and-webp">Image Optimization &#x26; WebP</a></td><td><a href="https://medianova-cloud.gitbook.io/clients.medianova.com/products/performance-cdn/api-caching">API Caching</a></td><td><a href="/files/2D6VLJogLz8mzPWNDlyW">/files/2D6VLJogLz8mzPWNDlyW</a></td></tr><tr><td align="center"><strong>Big Data &#x26; AI</strong></td><td><a href="/pages/vPenkY1H1Oj6vDhGhdvK">Instant Logs</a></td><td><a href="/pages/Nt4Z8sJeqfxBL7iAqveF">Logpush</a></td><td><a href="/pages/BfhkePwrpvAHVSpJV5p8">Analytics</a></td><td><a href="/pages/CNZeeScyBHDPcdwN8BBZ">Alerts</a></td><td></td><td data-object-fit="contain"><a href="/files/KntAy5qZV0iynuiFbTaP">/files/KntAy5qZV0iynuiFbTaP</a></td></tr><tr><td align="center"><strong>Storage</strong></td><td><a href="https://github.com/Medianova-Tech/medianova_docs/tree/main/knowledge-base/products/object-storage-stook/stook-cloud-object-storage.md">Stook: Cloud Object Storage</a></td><td><a href="https://github.com/Medianova-Tech/medianova_docs/tree/main/knowledge-base/products/object-storage-stook/getting-started-with-stook.md">Getting Started</a></td><td><a href="https://github.com/Medianova-Tech/medianova_docs/tree/main/knowledge-base/products/object-storage-stook/connect-stook-bucket-to-cdn.md">Stook Integration</a></td><td><a href="https://github.com/Medianova-Tech/medianova_docs/tree/main/knowledge-base/products/object-storage-stook/integration-and-usage-guides/README.md">Usage Guides</a></td><td><a href="https://github.com/Medianova-Tech/medianova_docs/tree/main/knowledge-base/api-documentation/object-storage-stook/README.md">Stook API</a></td><td><a href="/files/Rab9KtczfumQmdGomUlm">/files/Rab9KtczfumQmdGomUlm</a></td></tr></tbody></table>

#### [Discover Our API Documentation](https://medianova-cloud.gitbook.io/mn/api-documentation/authentication)

Learn how to integrate and optimize your workflows with our detailed API documentation.


# Concepts

Medianova provides a range of content delivery, performance optimization, and security services designed to accelerate websites, applications, APIs, and media delivery.

This section introduces the core concepts used throughout the documentation and provides an overview of the main technologies available on the Medianova platform.

## Key Services and Concepts

### CDN (Content Delivery Network)

A Content Delivery Network (CDN) is a globally distributed network of edge servers that delivers content from locations closer to users. By serving content from the nearest Point of Presence (PoP), a CDN reduces latency, improves response times, and decreases the load on the origin server.

### Static Content Delivery

Static Content Delivery is designed to accelerate the delivery of cacheable assets such as images, CSS files, JavaScript, fonts, downloadable files, and other static resources.

Medianova provides **Small CDN** and **Large CDN** resource types for static content delivery, allowing organizations to optimize different types of workloads while reducing origin traffic and improving page load times.

**Related concepts**

* [Small CDN](/products/performance-cdn/static-content-delivery/create-small-cdn-resource)
* [Large CDN](/products/performance-cdn/static-content-delivery/create-large-cdn-resource)
* [Static Content Delivery](/products/performance-cdn/static-content-delivery)

### Dynamic Content Caching

Dynamic Content Caching accelerates websites, applications, and APIs whose responses are generated by the origin application.

Medianova's **Dynamic CDN** optimizes request routing and supports configurable caching policies for eligible dynamic responses, helping reduce latency and origin load while maintaining application responsiveness.

**Related concepts**

* [Dynamic CDN](/products/performance-cdn/dynamic-content-acceleration/create-dynamic-resource)
* [API Caching](/products/performance-cdn/api-caching)
* [Dynamic Content Acceleration](/products/performance-cdn/dynamic-content-acceleration)

### Video on Demand (VOD)

Video on Demand (VOD) enables users to access pre-recorded video content whenever they choose.

Medianova delivers VOD content using adaptive streaming technologies such as HLS and MPEG-DASH, allowing video players to adjust playback quality automatically according to available network bandwidth and device capabilities.

**Related concepts**

* [Video on Demand](/products/performance-cdn/static-content-delivery/create-vod-resource)

### Private CDN

Private CDN provides dedicated content delivery infrastructure for organizations that require greater control over network architecture, security, capacity planning, or compliance requirements.

Unlike shared CDN environments, a Private CDN is designed specifically for a single organization and can be customized to meet its operational and business requirements.

**Related concepts**

* [Private CDN](/products/performance-cdn/private-cdn)

### Image Optimization

Image Optimization performs real-time image transformations at the edge without modifying the original files stored at the origin.

Supported operations include resizing, cropping, quality adjustment, format conversion, watermarking, and responsive image delivery. Modern image formats such as WebP and AVIF are also supported to improve performance while reducing bandwidth usage.

**Related concepts**

* [Image Optimization](/products/performance-cdn/image-optimization-and-webp/image-optimization)
* [WebP](/products/performance-cdn/image-optimization-and-webp/webp)
* [WebP+](/products/performance-cdn/image-optimization-and-webp/webp+)
* [AVIF](/products/performance-cdn/image-optimization-and-webp/avif-optimization)

### Stook Cloud Object Storage

Stook is Medianova's S3-compatible cloud object storage service for storing and retrieving unstructured data.

It can be used as a scalable storage platform or as an origin for CDN resources, providing high availability and seamless integration with existing S3-compatible applications and tools.

**Related concepts**

* [Stook Object Storage](/products/object-storage-stook/stook-cloud-object-storage)

### SSL/TLS Encryption

SSL/TLS encrypts communication between clients and servers, protecting data while it is transmitted across the network.

Medianova supports SSL/TLS termination at the edge and multiple certificate deployment options, including shared and custom certificates. Secure connections help protect sensitive information while enabling modern HTTPS features and protocols.

**Related concepts**

* [SSL Certificates](/products/security/ssl-tls-encryption/upload-and-manage-ssl-certificates)
* [TLS/SSL](/products/security/ssl-tls-encryption)

### Web Application Firewall (WAF)

A Web Application Firewall (WAF) inspects HTTP and HTTPS traffic to identify and block malicious requests before they reach the origin application.

Medianova WAF provides managed rule sets and configurable security policies that help protect web applications against common threats such as SQL injection, cross-site scripting (XSS), and other application-layer attacks.

**Related concepts**

* [Web Application Firewall (WAF)](/products/security/web-application-firewall-waf)
* [Page Rules](/api-documentation/performance-cdn/page-rule)
* [Security](/products/security)

### DDoS Protection

Medianova's DDoS protection helps mitigate distributed denial-of-service attacks by filtering malicious traffic across the global edge network before it reaches the origin.

Protection can be combined with additional security features such as Rate Limiting, WAF, IP filtering, and geoblocking to improve service availability during attack scenarios.

**Related concepts**

* [DDoS Protection](/products/security/ddos-protection)
* [Rate Limiting](/products/security/rate-limiting)
* [Security](/products/security)

## Conclusion

These concepts provide the foundation for understanding how Medianova delivers, accelerates, and protects digital content. Each topic links to dedicated documentation that explains configuration, architecture, and implementation details in greater depth.


# HTTP Response Codes

HTTP response status codes indicate the outcome of a request after it has been processed by a server, proxy, or CDN. They help clients determine whether a request succeeded, requires additional action, or failed due to client- or server-side conditions.

When using a CDN, understanding HTTP status codes is essential for troubleshooting origin connectivity, cache behavior, redirects, authentication, and application errors.

They fall into **five primary categories**:

<table><thead><tr><th width="172.6666259765625">Category</th><th>Description</th></tr></thead><tbody><tr><td><strong>1xx Informational</strong></td><td>Indicates that the request was received and the process is continuing.</td></tr><tr><td><strong>2xx Success</strong></td><td>Indicates that the request was successfully received, understood, and accepted.</td></tr><tr><td><strong>3xx Redirection</strong></td><td>Instructs the client to perform additional actions to complete the request (typically follow a different URL).</td></tr><tr><td><strong>4xx Client Error</strong></td><td>Indicates that the error is due to something the client sent (invalid request, missing auth, etc.).</td></tr><tr><td><strong>5xx Server Error</strong></td><td>Indicates that the server failed to fulfill a valid request.</td></tr></tbody></table>

### HTTP Status Codes in a CDN

When requests pass through a CDN, HTTP status codes are still generated by the origin server, the CDN itself, or both, depending on how the request is processed. Understanding these status codes helps identify issues related to caching, origin connectivity, redirects, authentication, and security policies.

Common examples include:

<table><thead><tr><th width="219.333251953125">Status Code</th><th>Typical CDN Scenario</th></tr></thead><tbody><tr><td><strong>200 OK</strong></td><td>Content is successfully delivered from the cache or origin.</td></tr><tr><td><strong>301 / 302</strong></td><td>Redirect rules forward the client to another URL.</td></tr><tr><td><strong>304 Not Modified</strong></td><td>The client or CDN reuses a cached copy of the resource.</td></tr><tr><td><strong>403 Forbidden</strong></td><td>Access is denied by the origin or a security policy such as WAF.</td></tr><tr><td><strong>429 Too Many Requests</strong></td><td>A rate limiting policy rejects excessive requests.</td></tr><tr><td><strong>502 Bad Gateway</strong></td><td>The CDN receives an invalid response from the origin server.</td></tr><tr><td><strong>503 Service Unavailable</strong></td><td>The origin server is temporarily unavailable or overloaded.</td></tr><tr><td><strong>504 Gateway Timeout</strong></td><td>The origin server does not respond before the configured timeout expires.</td></tr></tbody></table>

{% hint style="info" %}
A CDN does not replace HTTP status codes. Instead, it forwards, generates, or interprets them while processing requests. Depending on the request flow, a response code may originate from the client, the CDN, or the origin server.
{% endhint %}

### 1xx Informational

These codes indicate that the request was received and the process is continuing. They do **not finalize** the HTTP transaction — the client must wait for or send more data.

<table><thead><tr><th width="216.6666259765625">Code</th><th>Meaning</th></tr></thead><tbody><tr><td><strong>100 Continue</strong></td><td>The server has received the initial request headers and the client should proceed to send the request body (used with <code>Expect: 100-continue</code>).</td></tr><tr><td><strong>101 Switching Protocols</strong></td><td>The server agrees to switch protocols as requested by the client (for example upgrading from HTTP to WebSocket).</td></tr><tr><td><strong>102 Processing</strong></td><td>(WebDAV) The server has received and is processing the request, but no response is available yet. Prevents client timeouts on long operations.</td></tr><tr><td><strong>103 Early Hints</strong></td><td>Used to return some response headers before the final HTTP message, typically to allow the client to start preloading resources (via <code>Link</code> headers) while the server prepares the final response.</td></tr></tbody></table>

### 2xx Success

These codes indicate that the client’s request was successfully received, understood, and accepted.

<table><thead><tr><th width="212.6666259765625">Code</th><th>Meaning</th></tr></thead><tbody><tr><td><strong>200 OK</strong></td><td>The standard response for successful HTTP requests. The actual response depends on the request method (GET returns a resource, POST might return confirmation, etc).</td></tr><tr><td><strong>201 Created</strong></td><td>The request was successful and resulted in the creation of a new resource. Often includes a <code>Location</code> header pointing to the new resource.</td></tr><tr><td><strong>202 Accepted</strong></td><td>The request has been accepted for processing, but the processing is not complete. Typically used for async workflows.</td></tr><tr><td><strong>203 Non-Authoritative Information</strong></td><td>The server successfully processed the request but is returning information from another source (like a proxy or transformation) that might not be exactly the original.</td></tr><tr><td><strong>204 No Content</strong></td><td>The server successfully processed the request and is not returning any content. Useful for operations that do not need to change the current page (like clearing a form via JS).</td></tr><tr><td><strong>205 Reset Content</strong></td><td>The server processed the request successfully, but asks the client to reset the document view (like clearing form inputs).</td></tr><tr><td><strong>206 Partial Content</strong></td><td>The server is delivering only part of the resource due to a <code>Range</code> header sent by the client. Used for resumable downloads or streaming.</td></tr><tr><td><strong>207 Multi-Status</strong></td><td>(WebDAV) Conveys information about multiple resources, returning XML that contains multiple status codes.</td></tr><tr><td><strong>208 Already Reported</strong></td><td>(WebDAV) Used inside a DAV: propstat response element to avoid repeatedly enumerating the same internal members.</td></tr></tbody></table>

### 3xx Redirection

These codes indicate that further action needs to be taken by the client in order to complete the request. Usually involves following a different URI.

<table><thead><tr><th width="216.6666259765625">Code</th><th>Meaning</th></tr></thead><tbody><tr><td><strong>300 Multiple Choices</strong></td><td>Indicates multiple options for the resource that the client may follow (for example, different file formats). Rarely used in practice.</td></tr><tr><td><strong>301 Moved Permanently</strong></td><td>The resource has been permanently moved to a new URI. Clients should update their references. Future requests should use the new URL.</td></tr><tr><td><strong>302 Found</strong></td><td>The resource resides temporarily under a different URI. The client should continue to use the original URI for future requests. (Most common for standard redirects, but technically should use 303/307).</td></tr><tr><td><strong>303 See Other</strong></td><td>The server directs the client to get the requested resource at another URI using a GET request, typically after a POST.</td></tr><tr><td><strong>304 Not Modified</strong></td><td>Indicates that the resource has not been modified since the version specified by the <code>If-Modified-Since</code> or <code>If-None-Match</code> headers. Client can use cached version.</td></tr><tr><td><strong>307 Temporary Redirect</strong></td><td>The resource resides temporarily at a different URI, and the client should repeat the request using the same method. Unlike 302, it guarantees the same method (POST stays POST).</td></tr><tr><td><strong>308 Permanent Redirect</strong></td><td>The resource has been permanently moved to a new URI. The client should use the new URI and repeat the request with the same method. POST stays POST.</td></tr></tbody></table>

### 4xx Client Error

These codes indicate that the client seems to have made an error. The server understood the request, but it cannot or will not process it due to something that is perceived to be a client problem.

<table><thead><tr><th width="336.6666259765625">Code</th><th>Meaning</th></tr></thead><tbody><tr><td><strong>400 Bad Request</strong></td><td>The server could not understand the request due to invalid syntax (malformed JSON, missing required parameters, invalid query strings, etc).</td></tr><tr><td><strong>401 Unauthorized</strong></td><td>Authentication is required and has failed or has not yet been provided. The client should provide valid authentication credentials.</td></tr><tr><td><strong>402 Payment Required</strong></td><td>Reserved for future use. Intended to be used for digital payment systems but rarely implemented.</td></tr><tr><td><strong>403 Forbidden</strong></td><td>The client does not have access rights to the content. Unlike 401, authentication will not help; it is an explicit refusal.</td></tr><tr><td><strong>404 Not Found</strong></td><td>The server can not find the requested resource. This is the most common client error.</td></tr><tr><td><strong>405 Method Not Allowed</strong></td><td>The method specified in the request (e.g. POST, GET, DELETE) is not allowed for the resource.</td></tr><tr><td><strong>406 Not Acceptable</strong></td><td>The requested resource is capable of generating only content not acceptable according to the Accept headers sent by the client.</td></tr><tr><td><strong>407 Proxy Authentication Required</strong></td><td>The client must authenticate itself with the proxy before the request can be served.</td></tr><tr><td><strong>408 Request Timeout</strong></td><td>The client did not produce a request within the time that the server was prepared to wait.</td></tr><tr><td><strong>409 Conflict</strong></td><td>The request could not be completed due to a conflict with the current state of the resource. Typical in REST APIs when there is a version conflict.</td></tr><tr><td><strong>410 Gone</strong></td><td>The requested resource is no longer available and will not be available again. Typically used to indicate intentionally removed resources.</td></tr><tr><td><strong>411 Length Required</strong></td><td>The server refuses to accept the request without a defined Content-Length header.</td></tr><tr><td><strong>412 Precondition Failed</strong></td><td>One or more conditions given in the request header fields evaluated to false when tested on the server.</td></tr><tr><td><strong>413 Content Too Large</strong></td><td>The request entity is larger than limits defined by the server. (Previously called Payload Too Large).</td></tr><tr><td><strong>414 URI Too Long</strong></td><td>The URI provided was too long for the server to process. Often happens with overly large query strings.</td></tr><tr><td><strong>415 Unsupported Media Type</strong></td><td>The media format of the requested data is not supported by the server (e.g., sending XML where JSON is expected).</td></tr><tr><td><strong>416 Range Not Satisfiable</strong></td><td>The range specified by the Range header field in the request can't be fulfilled; the requested range is outside the size of the target resource.</td></tr><tr><td><strong>417 Expectation Failed</strong></td><td>The server cannot meet the requirements of the Expect request-header field.</td></tr><tr><td><strong>418 I'm a teapot</strong></td><td>Defined in RFC 2324, returned by teapots requested to brew coffee. Not actually used in production systems.</td></tr><tr><td><strong>421 Misdirected Request</strong></td><td>The request was directed at a server that is not able to produce a response (commonly seen in HTTP/2 multiplexed connections).</td></tr><tr><td><strong>422 Unprocessable Content</strong></td><td>The server understands the content type of the request and the syntax is correct but was unable to process the contained instructions. (Common in REST validation errors).</td></tr><tr><td><strong>423 Locked</strong></td><td>The resource that is being accessed is locked. (WebDAV).</td></tr><tr><td><strong>424 Failed Dependency</strong></td><td>The request failed due to failure of a previous request. (WebDAV).</td></tr><tr><td><strong>425 Too Early</strong></td><td>Indicates that the server is unwilling to risk processing a request that might be replayed. Used in early TLS handshake.</td></tr><tr><td><strong>426 Upgrade Required</strong></td><td>The server refuses to perform the request using the current protocol but might be willing if the client upgrades to a different protocol (e.g., switch to TLS/1.2).</td></tr><tr><td><strong>428 Precondition Required</strong></td><td>The server requires the request to be conditional. Intended to prevent the 'lost update' problem.</td></tr><tr><td><strong>429 Too Many Requests</strong></td><td>The user has sent too many requests in a given amount of time (rate limiting).</td></tr><tr><td><strong>431 Request Header Fields Too Large</strong></td><td>The server is unwilling to process the request because its header fields are too large.</td></tr><tr><td><strong>444 No Response</strong></td><td>The server closes the connection without sending any HTTP response to the client. Typically used to drop malicious or unwanted requests silently. Logged in <code>access.log</code> as <code>444</code>.</td></tr><tr><td><strong>451 Unavailable For Legal Reasons</strong></td><td>The server is denying access to the resource as a consequence of a legal demand (for example, geo-blocking or copyright takedown).</td></tr><tr><td><strong>494 Request Header Too Large</strong></td><td>The client sent HTTP headers that exceed the server’s configured maximum (<code>large_client_header_buffers</code>). The server closes the connection.</td></tr><tr><td><strong>495 SSL Certificate Error</strong></td><td>The server failed to verify the client’s SSL certificate during the handshake (invalid or untrusted client cert).</td></tr><tr><td><strong>496 SSL Certificate Required</strong></td><td>The server expected a client SSL certificate (mutual TLS), but the client did not provide one.</td></tr><tr><td><strong>497 HTTP Request Sent to HTTPS Port</strong></td><td>The client sent a plain HTTP request to an HTTPS port (like port 443). The server detects this mismatch.</td></tr><tr><td><strong>499 Client Closed Request</strong></td><td>The client closed the connection before the server could send a response. This code appears in <code>access.log</code>; it is not sent back to the client.</td></tr></tbody></table>

### 5xx Server Error

These codes indicate that the server failed to fulfill a valid request. The problem is on the server side, not the client's.

<table><thead><tr><th width="312.666748046875">Code</th><th>Meaning</th></tr></thead><tbody><tr><td><strong>500 Internal Server Error</strong></td><td>A generic error message indicating an unexpected condition was encountered and the server cannot fulfill the request. No more specific message is suitable.</td></tr><tr><td><strong>501 Not Implemented</strong></td><td>The server does not support the functionality required to fulfill the request (e.g. an unsupported HTTP method).</td></tr><tr><td><strong>502 Bad Gateway</strong></td><td>The server, while acting as a gateway or proxy, received an invalid response from the upstream server.</td></tr><tr><td><strong>503 Service Unavailable</strong></td><td>The server is currently unable to handle the request due to temporary overload or scheduled maintenance. Usually a temporary condition.</td></tr><tr><td><strong>504 Gateway Timeout</strong></td><td>The server, while acting as a gateway or proxy, did not receive a timely response from the upstream server it needed to access.</td></tr><tr><td><strong>505 HTTP Version Not Supported</strong></td><td>The server does not support the HTTP protocol version used in the request (like HTTP/1.0 vs HTTP/2).</td></tr><tr><td><strong>506 Variant Also Negotiates</strong></td><td>Transparent content negotiation for the request results in a circular reference. Very rare.</td></tr><tr><td><strong>507 Insufficient Storage</strong></td><td>The server is unable to store the representation needed to complete the request (typically in WebDAV scenarios).</td></tr><tr><td><strong>508 Loop Detected</strong></td><td>The server detected an infinite loop while processing a request (also seen in WebDAV collections).</td></tr><tr><td><strong>510 Not Extended</strong></td><td>Further extensions to the request are required for the server to fulfill it. Very uncommon.</td></tr><tr><td><strong>511 Network Authentication Required</strong></td><td>The client needs to authenticate to gain network access, often used by captive portals (Wi-Fi login pages).</td></tr></tbody></table>

### References

* **RFC 7231:** HTTP/1.1 Semantics and Content\
  (core HTTP methods, standard status codes)
* **RFC 7235:** HTTP/1.1 Authentication\
  (`401 Unauthorized`, `407 Proxy Authentication Required` and authentication mechanisms)
* **RFC 6585:** Additional HTTP Status Codes\
  (defines `429 Too Many Requests`, `431 Request Header Fields Too Large`, `511 Network Authentication Required`)
* **RFC 4918:** HTTP Extensions for WebDAV\
  (defines WebDAV-specific codes like `207 Multi-Status`, `422 Unprocessable Entity`, `423 Locked`, `424 Failed Dependency`, `507 Insufficient Storage`, `508 Loop Detected`)
* **RFC 8470:** HTTP 103 Early Hints\
  (specifies `103 Early Hints` for resource preloading)


# Security


# Always Use HTTPS

Automatically redirect HTTP requests to HTTPS to enforce encrypted connections for all visitors.

**Always Use HTTPS** automatically redirects HTTP requests to HTTPS, ensuring that visitors use encrypted connections when accessing your content.

You can manage Always Use HTTPS in the [Medianova Control Panel](https://cloud.medianova.com).

Navigate to the relevant CDN Resource and open the **Security** section.

## Configure Always Use HTTPS

{% stepper %}
{% step %}

### Enable Always Use HTTPS

Toggle **Status** to **On**.

<figure><img src="/files/05Jsx5RRidIUC3k8xn1u" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Select the Redirect Code

Choose the HTTPS redirect status code:

* **301** — Permanent Redirect
* **302** — Temporary Redirect
  {% endstep %}

{% step %}

### Save the Configuration

Click **Submit** to apply the configuration.
{% endstep %}
{% endstepper %}

### Behaviour

* All HTTP requests are redirected to the HTTPS version of the same URL.
* Query strings and request paths are preserved during the redirect.
* HTTPS requests are not affected.
* A valid SSL certificate must be configured for HTTPS delivery.

### Redirect Codes

Select the redirect status code used when HTTP requests are redirected to HTTPS.

* **301 (Permanent Redirect)** — Recommended for production environments and SEO.
* **302 (Temporary Redirect)** — Use when HTTPS enforcement may change in the future.

For detailed information about [HTTP Response Codes](/getting-started/concepts/http-response-codes)

### FAQ

**Should I use 301 or 302?**\
For most production environments, 301 is recommended.

**Does this affect existing HTTPS requests?**\
No. Only HTTP requests are redirected.

**What happens if HTTPS is not configured correctly?**\
Clients may receive SSL/TLS errors after being redirected.

**Does this improve security?**\
Yes. It helps ensure traffic is delivered over encrypted HTTPS connections.


# Security Token

Control access to your CDN resources by requiring a valid security token in every request URL.

**Security Token** restricts access to CDN-delivered content by requiring a valid token in the request URL. Requests that do not include a valid token are denied before content is served.

**How Security Token Works**

When Security Token is enabled for a CDN Resource, the CDN validates the token included in the request URL before serving content.

* Requests with a valid token are served normally.
* Requests without a token or with an invalid token are denied.

Token generation must be handled on your origin server or application. The CDN validates the token but does not generate it.

**When to Use Security Token**

Use Security Token to:

* Restrict access to time-limited content such as video streams or temporary download links
* Protect private files that should not be publicly accessible without authorization
* Prevent unauthorized sharing or hotlinking of protected resources

**Configuration**

Security Token is configured per CDN Resource in the [Medianova Control Panel](https://cloud.medianova.com).

{% stepper %}
{% step %}

### Access Security Token

Go to **CDN → CDN Resources** and select the resource you want to protect.

Open the **Security** tab and locate the **Security Token** section.
{% endstep %}

{% step %}

### Enable Security Token

Toggle **Status** to enable the feature.

<figure><img src="/files/084GHNfT52sKlq2oB5LA" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Configure Token Parameters

{% endstep %}
{% endstepper %}

**Notes**

* Token generation is the responsibility of your origin or application layer. The CDN validates but does not generate tokens.
* Requests without a valid token are denied at the CDN edge before reaching your origin.


# Bot Protection

Reduce unwanted automated traffic by blocking known malicious bots and content scraping tools at the CDN edge.

Bot Protection helps reduce unwanted automated traffic by identifying and blocking known malicious bots.

When enabled for a CDN Resource, Bot Protection evaluates incoming requests and blocks requests that match configured bot detection rules.

{% hint style="info" %}
Bot Protection is managed at the CDN level and does not require changes to your origin infrastructure.
{% endhint %}

## How Bot Protection Works

When Bot Protection is enabled, incoming requests are evaluated against the bot detection rules maintained by Medianova.

Requests identified as blocked bots are rejected, helping reduce unwanted automated traffic before it reaches the protected resource.

Bot Protection can help reduce:

* Automated scanning activity
* Content scraping by known malicious bots
* Unwanted crawler traffic
* Other requests originating from blocked automated clients

### Configure Bot Protection

In the [Medianova Control Panel](https://cloud.medianova.com), select the CDN Resource and navigate to the **Security** tab.

{% stepper %}
{% step %}

### Enable Bot Protection

Enable the **Status** toggle to activate Bot Protection for the selected CDN Resource.

<figure><img src="/files/8rkWmHUobbYsrzJ86qyy" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### Save the Configuration

Click **Submit** to deploy the updated configuration.
{% endstep %}
{% endstepper %}

## Common Use Cases

### Protect Public Websites

Reduce requests from known malicious automated clients attempting to access or scrape website content.

### Protect Media Assets

Limit access from known automated tools targeting downloadable content, images, or media assets.

### Reduce Unwanted Automated Traffic

Reduce traffic generated by automated clients classified as unwanted or malicious.

## Important Notes

* No origin-side configuration is required.
* Automated services, integrations, monitoring tools, and other legitimate automated clients should be validated after enabling Bot Protection.
* Bot detection rules may change as the protection system evolves.
* Bot Protection should be used as one layer of a broader security strategy and can be combined with IP Restriction, Geo Blocking, Rate Limiting, and other CDN security features.


# Hotlink Protection

Prevent unauthorized use of your media files by blocking external websites from embedding or linking directly to your CDN-hosted assets.

**Hotlink Protection** restricts access to your CDN Resource by verifying the **Referer header** in each HTTP request.\
When enabled, it ensures that only requests originating from your allowed domains can retrieve content from your CDN.\
Requests coming from unauthorized sources — such as external websites directly embedding your files — are blocked or redirected automatically.

#### Why Use Hotlink Protection?

Hotlink Protection helps you:

* **Protect bandwidth** – Prevent others from using your CDN capacity to serve their own content.
* **Secure digital assets** – Stop unauthorized sharing or embedding of your hosted media.
* **Reduce server load** – Block high-traffic external sites from consuming resources.
* **Maintain brand control** – Ensure your content appears only on trusted domains.
* **Prevent abuse** – Stop third-party sites from monetizing your media.

#### How Hotlink Protection Works

Hotlink Protection checks the **Referer** field of every HTTP request.\
If the Referer does not match your **whitelisted domain list**, the CDN automatically denies or redirects the request.

<table><thead><tr><th width="243">Action</th><th>Description</th></tr></thead><tbody><tr><td><strong>Allow</strong></td><td>Serves content when the Referer is from an authorized source.</td></tr><tr><td><strong>Block</strong></td><td>Rejects requests from unauthorized sites.</td></tr><tr><td><strong>Blacklist</strong></td><td>Denies access specifically to the domains listed in your blacklist.</td></tr><tr><td><strong>Redirect</strong></td><td>Sends unauthorized users to a specified page or image.</td></tr></tbody></table>

{% hint style="warning" %}
Add multiple allowed domains to the whitelist for multi-site deployments (e.g., `www.medianova.com`, `cdn.medianova.com`).
{% endhint %}

[<br>](https://clients.medianova.com/products/security/rate-limiting)


# IP Restriction

Control access to your CDN Resources by allowing or blocking specific IP addresses through whitelist or blacklist configurations.

**IP Restriction (Access Control List – ACL)** allows you to manage which IP addresses can access your CDN Resource.

You can manage IP Restriction in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](/api-documentation/security/ip-restriction-acl).

#### Why Use IP Restriction?

Use IP Restriction to:

* Protect internal or staging environments from unauthorized access.
* Restrict API access to trusted partners or corporate networks.
* Block known malicious IP ranges or suspicious activity.
* Ensure compliance with internal security policies.

## Configuration IP Restriction

You can choose between two modes: **Whitelist** or **Blacklist**, to define how access is granted or denied.

* **Whitelist Mode:** Only the IP addresses you specify are allowed to access your resource. All other IPs are denied.
* **Blacklist Mode:** The IP addresses you specify are denied access. All other IPs are allowed.

<figure><img src="/files/HFYFL2nvAvad3VJBRSrF" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
Whitelist and Blacklist modes are **mutually exclusive** — only one can be active at a time.
{% endhint %}

#### Key Features

* **Whitelist Mode** – Only the IP addresses you specify are allowed to access the resource. All other traffic is blocked.
* **Blacklist Mode** – The IP addresses you specify are denied access, while all other IPs are permitted.
* **Edge-Level Enforcement** – Filtering occurs at the CDN edge, ensuring zero impact on origin performance.
* **CIDR Range Support** – Define large IP ranges using CIDR notation (e.g., `192.168.1.0/24`).
* **Mutually Exclusive Modes** – You can use either whitelist or blacklist mode, but not both simultaneously.

{% hint style="warning" %}
Use Whitelist mode for restricted corporate APIs and Blacklist mode for public-facing applications that need selective blocking.
{% endhint %}

Medianova’s **IP Restriction** system provides a simple yet powerful way to enforce access control at the CDN level.

{% hint style="info" %}
Ready to configure IP Restriction for a CDN Resource?\
See: [Configure IP Restriction](/products/security/ip-restriction/configure-ip-restriction)
{% endhint %}

By validating requests before they reach your infrastructure, it prevents unauthorized access and improves overall performance stability.\
Combined with other **Security features** such as **Rate Limiting**, **WAF**, and **Hotlink Protection**, it forms a robust multi-layer defense mechanism.

[<br>](https://clients.medianova.com/docs/page-rules)


# Configure IP Restriction

Learn how to enable and configure IP Restriction in the Medianova Control Panel to allow or block access from specific IP addresses.

**IP Restriction** enables you to define which IP addresses can access your CDN Resources by using either **whitelist** or **blacklist** rules.\
When configured, access control is enforced at the **CDN edge**, ensuring that unauthorized requests are blocked before they reach your origin server.

You can enable IP Restriction for each CDN Resource in the [**Medianova Control Panel**](https://cloud.medianova.com).

{% stepper %}
{% step %}
**Access the IP Restriction**

1. Log in to the **Medianova Control Panel**.
2. Go to **CDN → CDN Resources**.
3. Select the resource where you want to apply IP restrictions.
4. Click the **Security** tab.
5. Open the **IP Restriction (ACL)** section.

{% hint style="info" %}
IP Restriction is available only for active CDN Resources.
{% endhint %}
{% endstep %}

{% step %}
**Choose Restriction Mode**

Select one of the following modes based on your access policy:

<table><thead><tr><th width="138">Mode</th><th>Description</th></tr></thead><tbody><tr><td><strong>Whitelist</strong></td><td>Only the IP addresses you add will be allowed. All others will be blocked.</td></tr><tr><td><strong>Blacklist</strong></td><td>The IP addresses you add will be blocked. All others will be allowed.</td></tr></tbody></table>

{% hint style="info" %}
Whitelist and Blacklist modes are **mutually exclusive** — only one can be active at a time.
{% endhint %}
{% endstep %}

{% step %}
**Add IP Addresses or Ranges**

1. Click **Add IP**.
2. Enter an IP address or subnet range in CIDR format (e.g., `192.168.0.0/24`).
3. Press **Enter** or click the **+** icon to add it to the list.
4. Repeat for additional IPs or ranges.
5. Click **Save** to apply changes.

{% hint style="info" %}
Use CIDR notation to efficiently manage large network ranges.
{% endhint %}
{% endstep %}

{% step %}
**Edit or Remove Existing Entries**

* **Edit:** Click the **Edit** icon to update an IP or range.
* **Delete:** Click the **Delete** icon to remove it.
* **Save Changes:** Click **Save** after every modification to ensure updates are applied at the edge.

{% hint style="info" %}
**Removing an entry from a Whitelist immediately blocks that IP from accessing your resource.**
{% endhint %}
{% endstep %}

{% step %}
**Verify Configuration**

Once saved, you can verify your configuration:

* Attempt access from an **allowed IP** → content should load successfully.
* Attempt access from a **restricted IP** → access should be denied or redirected.
* Review logs or analytics to confirm correct enforcement.

{% hint style="info" %}
Test from different networks (VPN, mobile, or office IPs) to ensure your list is accurate.
{% endhint %}
{% endstep %}
{% endstepper %}


# DDoS Protection

Protect your applications and APIs from volumetric and protocol-based attacks with Medianova’s multi-layer, always-on DDoS mitigation system.

A Distributed Denial of Service (DDoS) attack is a malicious attempt to disrupt normal traffic by overwhelming a target system or network with excessive requests.\
Medianova’s **DDoS Protection** automatically detects and mitigates these attacks without requiring any manual activation.\
From rate limiting to IP and Geo blocking, Medianova ensures uninterrupted availability even under heavy attack conditions.

### **How Medianova DDoS Protection Works**

Medianova integrates several protection layers designed to stop attacks before they impact your services.

<figure><img src="/files/oPlYkaAExBW8xGZTwqEz" alt=""><figcaption><p>Medianova DDoS Protection Architecture</p></figcaption></figure>

#### **Always-On Defense**

Your DDoS protection is active by default.\
There is no need for additional setup — your web assets are continuously monitored and protected against common attack types such as:

* DNS Query Floods
* Slowloris Attacks
* HTTPS GET / POST Floods

#### **Anycast DNS Infrastructure**

Medianova’s global [Anycast DNS](/products/dns/dns-vs-dynamic-dns-vs-anycast-dns) distributes thousands of requests across multiple servers.\
This prevents traffic overload on a single endpoint and mitigates large-scale network floods.

{% hint style="warning" %}
Anycast DNS not only improves security but also reduces latency by routing users to the nearest edge location.
{% endhint %}

#### **IP and Origin Protection**

You can reduce the risk of DDoS threats by concealing your origin IP before an attack begins.\
Medianova provides an extra layer of protection through **Secure Cloud**, limiting exposure of your origin infrastructure and filtering harmful traffic before it reaches your servers.

**Warning:** Exposing your origin IP directly allows attackers to bypass DDoS mitigation layers.

#### **Rate Limiting and Geo Blocking**

Edge-level rate limiting and Geo-based filtering restrict malicious or excessive traffic patterns.\
This ensures that legitimate users maintain access while harmful requests are dropped early in the network path.

#### **WAF Integration**

When combined with Medianova’s [**Web Application Firewall (WAF)**](https://clients.medianova.com/products/security/web-application-firewall-waf), DDoS Protection forms a complete multi-layer defense system.\
This integration protects not only against volumetric attacks but also against **application-layer threats**, such as bot floods or malicious payloads targeting web applications.

### **Best Practices**

* Conceal your origin IP using **Secure Cloud** or **Origin Shield**.
* Combine **DDoS Protection** with **WAF** for enhanced multi-layer defense.
* Keep critical DNS zones under [**Anycast DNS**](/products/dns/dns-vs-dynamic-dns-vs-anycast-dns) to distribute load globally.
* Regularly review threat and access logs to identify abnormal patterns.

Medianova DDoS Protection delivers continuous and intelligent protection against both volumetric and application-layer attacks.\
By combining global Anycast DNS distribution, adaptive rate limiting, and origin shielding, Medianova ensures your online services remain fast, secure, and always available.


# SSL/TLS Encryption

Secure your CDN traffic and applications with SSL/TLS encryption to ensure private, authenticated communication between clients and servers.

**Secure Sockets Layer (SSL)** and **Transport Layer Security (TLS)** are cryptographic protocols that protect data exchanged between clients and servers. Although the term *SSL* is still widely used, modern HTTPS connections rely on TLS.

Medianova CDN uses SSL/TLS certificates to secure HTTPS connections between end users and CDN edge servers.

Depending on your deployment, you can use a shared certificate, upload your own certificate, or request a free certificate through the **SSL / TLS** page in the [Medianova Control Panel](https://cloud.medianova.com).

{% hint style="info" %}
Medianova supports modern TLS versions for secure content delivery. TLS 1.2 and TLS 1.3 are recommended for all deployments.
{% endhint %}

### Why SSL/TLS Matters

SSL/TLS provides several essential security benefits for websites and applications.

* **Confidentiality** – Encrypts data exchanged between clients and servers.
* **Integrity** – Protects data from modification while in transit.
* **Authentication** – Verifies the identity of the website through trusted Certificate Authorities (CAs).
* **Trust** – Enables HTTPS, improving user confidence and browser security indicators.
* **Performance** – Modern TLS versions provide faster and more efficient encrypted connections.

### Supported Certificate Types

Medianova supports the most common SSL/TLS certificate types.

| Certificate Type                   | Description                                               | Recommended For                |
| ---------------------------------- | --------------------------------------------------------- | ------------------------------ |
| **Domain Validation (DV)**         | Verifies domain ownership. Fast and simple to issue.      | Personal websites, blogs, APIs |
| **Organization Validation (OV)**   | Verifies both domain ownership and organization identity. | Corporate websites             |
| **Extended Validation (EV)**       | Provides the highest level of organizational validation.  | Financial services, e-commerce |
| **Wildcard**                       | Protects a domain and all first-level subdomains.         | Multi-subdomain deployments    |
| **Subject Alternative Name (SAN)** | Secures multiple domains using a single certificate.      | Multi-domain environments      |

{% hint style="info" %}
Wildcard and SAN certificates simplify certificate management when serving multiple domains or subdomains.
{% endhint %}

### **How SSL/TLS Works on Medianova CDN**

<figure><img src="/files/3t9twbqZfYDP6vWuGHKd" alt="" width="563"><figcaption><p>Two-Layer Encryption Flow</p></figcaption></figure>

When a client requests content over HTTPS:

1. The client connects securely to the nearest Medianova edge server.
2. The edge server presents a valid SSL/TLS certificate.
3. A TLS handshake establishes an encrypted connection.
4. The CDN serves cached content or retrieves the requested object from the origin.
5. If origin SSL is enabled, communication between the CDN and the origin server is also encrypted.

This process ensures that data remains protected while traveling across the network.

{% hint style="info" %}
The Control Panel provides notifications for important SSL lifecycle events, including certificate validation and provisioning status changes.
{% endhint %}

### Best Practices

For secure and reliable HTTPS delivery:

* Enable HTTPS for every production CDN Resource.
* Prefer TLS 1.3 whenever client compatibility allows.
* Keep SSL certificates valid and renewed before expiration.
* Use Wildcard or SAN certificates when serving multiple domains.
* Ensure every custom CNAME is covered by the selected certificate.
* Serve all website assets over HTTPS to avoid mixed-content warnings.
* Complete DNS validation before using newly requested Free SSL certificates.

### Related Concepts

The following guides explain how to configure SSL/TLS in the Medianova Control Panel

* [Upload and Manage SSL Certificates](/products/security/ssl-tls-encryption/upload-and-manage-ssl-certificates)
* [Use Free SSL Certificates](/products/security/ssl-tls-encryption/use-free-ssl-certificates)
* [CNAME & SSL](/products/performance-cdn/static-content-delivery/advanced-configuration/cname-and-ssl)
* [Extract Certificate and Private Key from a PKCS#12 (.pfx) File](/products/security/ssl-tls-encryption/extract-crt-and-key-files-from-a-pfx-certificate)


# Upload and Manage SSL Certificates

Learn how to upload and manage SSL certificates in the Medianova Control Panel.

SSL/TLS certificates enable encrypted HTTPS communication between users and CDN Resources. From the **SSL / TLS** page, you can upload your own certificates or request free Let's Encrypt certificates using a guided provisioning wizard.

{% hint style="info" %}
TLS is the modern version of SSL. Medianova supports TLS 1.2 and TLS 1.3 for all SSL/TLS connections.
{% endhint %}

Manage your certificates from the **SSL / TLS** page in the [Medianova Control Panel](https://cloud.medianova.com/)

## Upload SSL Certificates

1. Open **SSL / TLS** from the left navigation menu.
2. Review the certificates currently available in your account.
3. Click **Add New SSL**.

<figure><img src="/files/3U7clYcJ3tTgU0cdcHFb" alt="" width="563"><figcaption></figcaption></figure>

{% stepper %}
{% step %}

## Choose the Certificate Type

Select how you want to provision the certificate.

* **Add Own SSL** – Upload or import an existing certificate issued by a Certificate Authority (CA).
* **Free SSL** – Request a free Let's Encrypt certificate through DNS/CNAME validation.

<figure><img src="/files/gd6AeP9aSqWqigFXjuFx" alt="" width="539"><figcaption></figcaption></figure>

### Add Your Own SSL

Upload an existing SSL/TLS certificate using one of the supported import methods.

#### SSL Certificate Name

Enter a descriptive name to identify the certificate within the Control Panel.

This name is used only for management purposes and does not affect the certificate itself.

#### Certificate Import Methods

Choose one of the following import methods.

#### Domain SSL

Retrieve an existing certificate directly from a domain that already serves HTTPS.

Configure:

* **SSL Certificate Name**
* **Domain**

Click **Check SSL** to retrieve the certificate information.

The wizard displays:

* Subject
* Issuer
* Expiration date

After verification, provide the matching private key before continuing.

<figure><img src="/files/Zr0y2SaDX6TbS56g9JvY" alt=""><figcaption></figcaption></figure>

#### Paste .crt / .key

Paste the certificate and private key directly into the corresponding fields.

Required fields:

* Certificate (.crt / .pem)
* Private Key (.key)

Use this method when certificate files are already available as text.

<figure><img src="/files/lJigqCx8tsG7ZktleFVe" alt=""><figcaption></figcaption></figure>

#### Upload Certificate Files

Upload the certificate and private key files from your local computer.

Supported file types include:

* `.crt`
* `.pem`
* `.key`

<figure><img src="/files/URzRwjv8XjYV48WziR0U" alt=""><figcaption></figcaption></figure>

#### Upload PKCS#12 (.pfx)

Upload a PKCS#12 certificate bundle.

Configure:

* `.pfx` file
* PFX Password (if required)

The wizard extracts the certificate and private key automatically.

<figure><img src="/files/27x7LVpUJK1Cb1jg34W7" alt=""><figcaption></figcaption></figure>

#### Certificate Validation

Before continuing, verify the following:

* The certificate and private key belong to the same certificate pair.
* The uploaded certificate is valid and has not expired.
* The certificate covers the required domain or wildcard domain.

> **Important**
>
> Always upload the complete certificate chain, including intermediate certificates when provided. Uploading only the leaf certificate may result in browser trust warnings or incomplete certificate validation.

Click **Next** after completing the required information.

### Request a Free SSL Certificate

Request a free Let's Encrypt certificate directly from the wizard.

#### SSL Certificate Name

Enter a descriptive name for the certificate.

#### Domain

Choose one of the following options.

#### Existing Domain

Select a domain that already exists in your account.

Then choose the required certificate coverage.

<figure><img src="/files/TKuygMbIs1vTOJoK3IFp" alt="" width="537"><figcaption></figcaption></figure>

#### New Domain

Enter a new domain that will be secured by the certificate.

The domain must resolve to the Medianova edge network before DNS validation can complete.

<figure><img src="/files/PflilgD6RFpifDGTClqt" alt="" width="538"><figcaption></figcaption></figure>

#### Coverage

Select the required certificate scope.

<table><thead><tr><th width="175">Option</th><th>Description</th></tr></thead><tbody><tr><td><strong>Single Domain</strong></td><td>Protects a single hostname.</td></tr><tr><td><strong>Wildcard</strong></td><td>Protects all subdomains of a domain. DNS/CNAME validation is required.</td></tr></tbody></table>

Click **Next** to continue.
{% endstep %}

{% step %}

## Review & Activate

Review the certificate configuration before creating the certificate.

The summary includes:

* Provisioning method
* Certificate name
* Domain
* Coverage

Optionally assign the certificate to one or more CDN Resources during this step.

The Control Panel automatically determines the required DNS validation workflow based on the selected certificate type and the associated CDN Resource configuration.

The resource list includes:

* CDN URL
* Resource Type
* Domain

Select the resources that should use the certificate immediately after creation.

<figure><img src="/files/P2gG58wqPA5ZVCikt3pI" alt="" width="563"><figcaption></figcaption></figure>

Click **Create SSL** to start certificate provisioning.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
**Notifications**

After an SSL certificate is created, updated, or its validation status changes, Medianova sends notifications to the user who initiated the request and the account owner.

Status updates are also available through Control Panel notifications.
{% endhint %}

## Manage Certificates

After a certificate is created, it appears on the **SSL / TLS** page.

From this page you can:

* Search certificates
* View certificate details
* Review expiration dates
* Delete unused certificates
* Assign certificates to additional CDN Resources

Certificates requested through **Free SSL** automatically enter the validation process after creation.

{% hint style="info" %}
The required DNS validation records vary depending on the selected certificate type and associated CDN Resource configuration. Always use the DNS values displayed by the Control Panel during certificate provisioning.

For DNS validation, pending requests, renewal, and validation status, see **Use Free SSL Certificates**.
{% endhint %}

### Related Concepts

* [SSL / TLS Encryption](/products/security/ssl-tls-encryption)
* [Use Free SSL Certificates](/products/security/ssl-tls-encryption/use-free-ssl-certificates)
* [CNAME & SSL](/products/performance-cdn/static-content-delivery/advanced-configuration/cname-and-ssl)


# Use Free SSL Certificates

Learn how to enable and manage free SSL certificates in the Medianova Control Panel.

Free SSL certificates allow you to secure your CDN Resources using Let's Encrypt without purchasing or managing a commercial SSL certificate.

After requesting a Free SSL certificate, Medianova guides you through the required DNS validation process and automatically issues the certificate once domain ownership has been verified.

Request Free SSL certificates from the **SSL / TLS** page in the [Medianova Control Panel](https://cloud.medianova.com).

For the certificate creation workflow, see [**Upload and Manage SSL Certificates**](/products/security/ssl-tls-encryption/upload-and-manage-ssl-certificates).

Free SSL certificates require DNS/CNAME validation before they can be issued. The requested domain must resolve to the Medianova edge network.

Depending on the selected resource type and SSL configuration, the required DNS mapping may differ. During resource creation, the Control Panel displays the exact DNS record that must be configured for your deployment.

## Request a Free SSL Certificate

Create a new certificate from the **SSL / TLS** page by selecting **Free SSL** in the certificate wizard.

Configure:

* SSL Certificate Name
* Domain
* Coverage (Single Domain or Wildcard)

After reviewing the configuration, click **Create SSL**.

<figure><img src="/files/toEDiEQ6V2XwxuaDS82p" alt="" width="375"><figcaption></figcaption></figure>

For detailed certificate creation steps, see [**Upload and Manage SSL Certificates**](/products/security/ssl-tls-encryption/upload-and-manage-ssl-certificates).

{% hint style="info" %}
The DNS record that must be configured depends on both the selected resource type and the SSL configuration. Always use the DNS values displayed in the Control Panel, as they are generated specifically for your certificate request and deployment scenario.
{% endhint %}

## Complete DNS Validation

After creating the certificate request, Medianova displays the DNS validation dialog.

<figure><img src="/files/2ExUUZKG3xEztlZHBBD6" alt=""><figcaption></figcaption></figure>

The dialog guides you through the remaining Let's Encrypt validation steps.

{% stepper %}
{% step %}

### Open your DNS provider

Open the DNS management interface where your domain records are managed.

This may be your:

* Domain registrar
* DNS hosting provider

Examples include Cloudflare, Amazon Route 53, GoDaddy, Namecheap, and similar DNS providers.
{% endstep %}

{% step %}

### Add the required CNAME record

The dialog displays the DNS record required to validate your domain.

<table><thead><tr><th width="216.3333740234375">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Host / Name</strong></td><td>The hostname that must be created in your DNS zone.</td></tr><tr><td><strong>Value</strong></td><td>The CNAME target provided by Medianova.</td></tr></tbody></table>

Use the copy button next to each field to copy the values directly.

Create the CNAME record exactly as displayed.

{% hint style="info" %}
DNS propagation may take from a few minutes to several hours depending on your DNS provider and DNS TTL settings.
{% endhint %}

#### Where do I add this?

If you are unsure where to create the DNS record, click **Where do I add this?**.

The dialog explains that the CNAME record must be created in the DNS management interface for your domain, typically provided by your domain registrar or DNS hosting provider.
{% endstep %}

{% step %}

### Save & Verify

After publishing the CNAME record, return to the dialog and click **Confirm**.

Medianova automatically starts DNS validation and monitors the record until validation completes. Once the DNS record is detected, the certificate is issued automatically.

&#x20;No additional manual verification is required.
{% endstep %}
{% endstepper %}

## Monitor Pending Validation

After clicking **Confirm**, the certificate request appears in the **Pending Validation** section at the top of the **SSL / TLS** page.

<figure><img src="/files/5MD5YwUb0snHJsHZmffn" alt=""><figcaption></figcaption></figure>

This section is displayed only when one or more Free SSL requests are waiting for validation. If there are no pending requests, it is hidden automatically.

Each request displays:

* Certificate name
* Domain
* Current validation status

Select a request to expand its details.

The expanded view displays:

* Validation instructions
* DNS record type
* Host / Name
* Value
* One-click copy buttons

This allows you to monitor the validation process without leaving the **SSL / TLS** page.

### Validation Status

Each pending request displays its current validation state.

<table><thead><tr><th width="166">Status</th><th>Description</th></tr></thead><tbody><tr><td><strong>Validating DNS</strong></td><td>Medianova is waiting for the required DNS record to propagate and complete domain validation.</td></tr><tr><td><strong>Validation Failed</strong></td><td>Domain validation could not be completed. Review the DNS configuration and retry after correcting the issue.</td></tr></tbody></table>

Once validation succeeds:

* the request is removed from **Pending Validation**;
* the certificate is automatically added to the SSL certificate list.

The Pending Validation section and SSL certificate list refresh automatically as the validation status changes.

## Notifications

Medianova automatically notifies users about important certificate lifecycle events.

Notifications are generated when:

* certificate validation starts;
* validation succeeds;
* validation fails;
* certificate provisioning completes.

Notifications are delivered through:

* Control Panel notifications;
* email notifications sent to the user who created the request and the account owner.

This allows certificate requests to be monitored without continuously refreshing the SSL / TLS page.

## Manage Pending Requests

The expanded Pending Validation view provides the following actions.

<figure><img src="/files/BfqLQsITCeSAYXcfUjii" alt="" width="563"><figcaption></figcaption></figure>

### Instructions

Opens the DNS validation guidance directly from the Control Panel.

### Cancel

Cancels the pending certificate request.

After confirmation, the request is removed from the Pending Validation list.

## Automatic Renewal

Free SSL certificates issued through Let's Encrypt are renewed automatically before expiration.

No manual renewal is required as long as:

* the domain continues to resolve to the Medianova edge network;
* DNS validation requirements remain valid.

## Troubleshooting

### Validation is taking longer than expected

Verify that:

* the required CNAME record has been created correctly;
* the Host / Name and Value exactly match the values provided by Medianova;
* the DNS record has propagated successfully.

### Validation failed

Validation failures are commonly caused by:

* incorrect CNAME values;
* missing DNS records;
* conflicting DNS validation records.

Correct the DNS configuration and retry the validation after DNS propagation.

### Certificate does not appear in the SSL list

The certificate is added to the SSL certificate list only after successful domain validation.

If the request is still displayed in **Pending Validation**, wait for DNS propagation or review the validation status.

## Related Concepts

* [Upload and Manage SSL Certificates](/products/security/ssl-tls-encryption/upload-and-manage-ssl-certificates)
* [SSL / TLS Encryption](/products/security/ssl-tls-encryption)
* [CNAME & SSL](/products/performance-cdn/static-content-delivery/advanced-configuration/cname-and-ssl)


# Extract CRT and KEY Files from a PFX Certificate

Learn how to extract .crt and .key files from a .pfx certificate using OpenSSL.

A PKCS#12 (`.pfx`) file contains a certificate, private key, and optional intermediate certificates in a single encrypted bundle. Although the **SSL / TLS** wizard supports uploading `.pfx` files directly, some environments or workflows require separate `.crt` and `.key` files.

This guide explains how to extract the certificate and private key from a PKCS#12 file using OpenSSL.

{% hint style="info" %}
This procedure is optional. If your certificate is already available as a PKCS#12 (`.pfx`) file, you can upload it directly using the **Upload PKCS#12 (.pfx)** option in the **SSL / TLS** wizard.
{% endhint %}

## Prerequisites

Before you begin, ensure that you have:

* A valid PKCS#12 (`.pfx`) certificate file.
* The password protecting the `.pfx` file.
* OpenSSL installed on your system.
* (Optional) A descriptive filename such as `example_com.pfx`.

{% stepper %}
{% step %}

### Create the Extraction Script

Create a new Bash script named **extract-cert.sh** and paste the following content.

```bash
#!/bin/bash
# Usage: ./extract-cert.sh <pfx-password>

# 1. Extract encrypted private key
openssl pkcs12 -in domain.pfx -nocerts -out encrypted-domain.key -passin pass:$1 -passout pass:$1

# 2. Decrypt the private key
openssl rsa -in encrypted-domain.key -out domain.key -passin pass:$1

# 3. Extract public certificate
openssl pkcs12 -in domain.pfx -clcerts -nokeys -out domain.crt -passin pass:$1

# 4. Verify that the certificate and key match
first=$(openssl x509 -in domain.crt -modulus -noout | openssl md5)
second=$(openssl rsa -in domain.key -modulus -noout | openssl md5)

if [[ "$first" == "$second" ]]; then
    echo "✅ Certificate and Key match."
else
    echo "❌ Mismatch between certificate and key."
fi
```

Save the file after replacing `domain.pfx` with your actual filename.

{% hint style="info" %}
For example, if your certificate file is named `medianova_com.pfx`, update the script accordingly before running it.
{% endhint %}
{% endstep %}

{% step %}

### Make the Script Executable

Grant execute permission to the script.

```bash
chmod +x extract-cert.sh
```

This command allows the script to be executed from the command line.
{% endstep %}

{% step %}

### Run the Script

Run the script and provide the password for your PKCS#12 file.

```bash
./extract-cert.sh yourPFXpassword
```

Replace `yourPFXpassword` with the actual password for the `.pfx` file.

The script extracts the certificate and private key, then verifies that they belong to the same certificate pair.
{% endstep %}

{% step %}

### Review the Generated Files

After the script finishes successfully, the following files are created.

| File                   | Description                                                                   |
| ---------------------- | ----------------------------------------------------------------------------- |
| `domain.crt`           | Public certificate.                                                           |
| `domain.key`           | Unencrypted private key.                                                      |
| `encrypted-domain.key` | Temporary encrypted private key. This file can be deleted after verification. |
| {% endstep %}          |                                                                               |

{% step %}

### Verify the Results

If the extraction succeeds, the script prints:

```
✅ Certificate and Key match.
```

If the certificate and private key do not belong to the same certificate:

```
❌ Mismatch between certificate and key.
```

{% hint style="info" %}
If a mismatch is reported, verify that you are using the correct `.pfx` file and password before repeating the extraction process.
{% endhint %}
{% endstep %}
{% endstepper %}

## Next Steps

After extracting the files, you can use either of the following options in the **SSL / TLS** wizard:

* **Upload Certificate Files** to upload the generated `.crt` and `.key` files.
* **Paste Certificate and Private Key** to paste their contents directly into the wizard.

If you do not need separate certificate files, upload the original `.pfx` file directly using the **Upload PKCS#12 (.pfx)** option.

### Related Concepts

* [Upload and Manage SSL Certificates](/products/security/ssl-tls-encryption/upload-and-manage-ssl-certificates)
* [SSL / TLS Encryption](/products/security/ssl-tls-encryption)


# Web Application Firewall (WAF)

Protect your web applications from common exploits and malicious traffic with Medianova’s Web Application Firewall (WAF).

**WAF** is Medianova’s intelligent web security layer that protects your applications from malicious traffic, bots, and exploits. With **real-time filtering**, **custom rule control**, and **built-in analytics**, it helps you prevent attacks before they reach your origin servers.

#### Why Choose WAF?

Medianova WAF combines **ease of use**, **robust protection**, and **edge-level performance** to keep your web applications secure. Unlike standard firewalls, WAF protects against both **network** and **application-layer** attacks.

* **Edge-level protection** – All traffic is filtered at Medianova’s global CDN edge before it reaches your origin.
* **Managed Rules** – Constantly updated rulesets by Medianova’s Security Team, including OWASP Top 10 protections.
* **Custom Rules** – Define your own rules to block, allow, or log specific requests.
* **Real-time defense** – Detect and mitigate attacks instantly without affecting legitimate traffic.
* **Actionable analytics** – Gain visibility into threats, attack sources, and triggered rules through the Control Panel.

#### Key Features

* **OWASP Top 10 Protection** – Shields against SQL Injection, XSS, and other common web vulnerabilities.
* **Custom Rule Engine** – Create granular policies based on IP, URI, headers, or user agents.
* **Monitoring Mode** – Observe how rules behave before full activation.
* **Instant Mitigation** – Block or log attacks in real time with no latency impact.
* **Integrated Analytics** – Visual dashboards for traffic and threat insights.
* **False Positive Control** – Fine-tune rules to balance protection and accessibility.

#### Use Cases

* **Web Application Security** – Protect public websites and portals from injection and XSS attacks.
* **API Protection** – Filter and control requests to your backend APIs.
* **E-commerce Security** – Prevent data breaches, bot abuse, and checkout exploitation attempts.

#### Built for Modern Web Security

Medianova WAF delivers **enterprise-grade web protection** that’s easy to deploy and manage through the [**Medianova Control Panel**](https://cloud.medianova.com).\
It helps you stay secure without adding complexity — protecting your applications from the edge, in real time.


# How to Activate WAF

Learn how to activate and configure the Web Application Firewall (WAF) for your CDN Resources in the Medianova Control Panel.

**WAF (Web Application Firewall)** enhances your website’s security by inspecting and filtering incoming HTTP/HTTPS traffic.\
You can enable it for any **Dynamic CDN Resource**, select the protection mode, and create **Custom Rules** to detect and block malicious requests.

{% hint style="info" %}
WAF is available only for **Dynamic CDN Resources**. Ensure your resource is active before proceeding.
{% endhint %}

{% stepper %}
{% step %}
**Access the WAF**

To begin configuration, log in to the [**Medianova Control Panel**](https://cloud.medianova.com) and navigate to the WAF settings.

* Go to **Security → WAF** in the left-hand menu.
* Select the Dynamic CDN Resource where you want to activate WAF.
* The WAF configuration page will open.

<figure><img src="/files/pKotubUtzKxispA0YVtK" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="info" %}
If you haven’t created a Dynamic CDN Resource yet, go to **CDN → Create CDN Resource** first, then return to this section.
{% endhint %}
{% endstep %}

{% step %}
**Choose WAF Mode**

Select how the firewall will operate for your CDN Resource.

* **Monitoring Only:** Logs all requests but does not block them. Recommended for initial setup and rule tuning.
* **On:** Fully active mode that filters and blocks malicious traffic in real time.

After selecting a mode, click **Save** to apply the change.

<figure><img src="/files/1hFmvYzyxNfluhUI7eSx" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Start with **Monitoring Only** mode to observe your application’s normal request patterns before enabling full protection.
{% endhint %}
{% endstep %}

{% step %}
**Create Your First Rule**

After activation, you can define custom rules to control how WAF handles requests.\
For example, you can block requests from specific IP ranges or allow trusted user agents.

To create or manage rules, go to [Managing Rules & Actions](/products/security/web-application-firewall-waf/manage-rules-and-actions).

{% hint style="info" %}
Rule configuration is optional at activation. WAF includes predefined Managed Rules that are enabled by default.
{% endhint %}
{% endstep %}

{% step %}
**Verify WAF Activation**

Once WAF is enabled, the **Status** indicator on your resource page will show “Active.”\
Incoming requests are now analyzed by the firewall and logged in real time.

You can monitor activity in the **Analytics → WAF Dashboard** section.

{% hint style="info" %}
WAF logs and metrics may take up to a few minutes to appear after initial activation.
{% endhint %}
{% endstep %}
{% endstepper %}

#### Best Practices

* Always start with **Monitoring Only** mode for new configurations.
* Combine **Managed Rules** and **Custom Rules** for optimal coverage.
* Review your WAF Analytics regularly to track threats and rule behavior.
* Avoid creating overly broad rules to minimize false positives.


# Manage Rules & Actions

The **Web Application Firewall (WAF)** allows you to define **Custom Rules** that specify how incoming traffic is evaluated.\
Each rule can match certain request attributes and apply an action — such as **Block**, **Allow**, or **Log Only** — when conditions are met.

{% hint style="info" %}
Managed Rules are automatically maintained by Medianova’s Security Team.\
Custom Rules are created manually to adapt the WAF to your specific application needs.
{% endhint %}

{% stepper %}
{% step %}
**Access the Rule Management**

To manage rules, log in to the [**Medianova Control Panel**](https://cloud.medianova.com):

1. Go to **Security → WAF**.
2. Select your **Dynamic CDN Resource**.
3. Open the **Rules & Actions** tab.

You’ll see a list of existing Custom Rules and the option to create new ones.

{% hint style="info" %}
Managed Rules are always active by default. You can combine both Managed and Custom Rules for layered protection.
{% endhint %}
{% endstep %}

{% step %}
**Create a New Custom Rule**

Follow these steps to add a new rule:

1. Click **Add Rule**.
2. Enter a **Rule Name** for easy identification.
3. Select a **Field** (parameter) from the dropdown — such as:
   * Request Method (GET, POST, etc.)
   * Client IP
   * Request URI
   * User Agent
   * Referrer
4. Choose an **Operator**, such as *equals*, *contains*, or *matches*.
5. Enter the **Value** to match.
6. (Optional) Add additional conditions using the **And** operator.
7. Select an **Action** to perform when the rule conditions are met:
   * **Block** – Reject the request and log the event.
   * **Allow** – Permit the request to proceed to origin.
   * **Log Only** – Record the request for review without blocking.
8. Click **Save** to apply the rule.

{% hint style="info" %}
You can chain up to **three conditions** in a single rule. Complex logic combinations are not supported.
{% endhint %}

{% hint style="info" %}
Use “Log Only” for testing before switching to “Block” to minimize false positives.
{% endhint %}
{% endstep %}

{% step %}
**Edit or Delete Existing Rules**

You can modify or remove existing rules at any time:

* **Edit:** Click the **Edit** icon next to a rule, adjust the fields or actions, and click **Save**.
* **Delete:** Click the **Delete** icon to permanently remove the rule.
* **Reorder (if supported):** Drag and drop to change rule evaluation priority.

{% hint style="info" %}
Review logs frequently to ensure that new or modified rules behave as expected.
{% endhint %}
{% endstep %}
{% endstepper %}

#### Understand Rule Actions

Each action defines how WAF handles a matched request:

| Action       | Behavior                                                 |
| ------------ | -------------------------------------------------------- |
| **Block**    | Immediately rejects the request with an error response.  |
| **Allow**    | Lets the request pass to the origin server.              |
| **Log Only** | Records the event for analysis without blocking traffic. |

> **Note:** “Log Only” is ideal for testing or monitoring potential issues before applying stricter blocking rules.


# Handle False Positives

Learn how to identify, analyze, and minimize false positives in the Web Application Firewall (WAF) to ensure accurate protection without disrupting legitimate traffic.

A **false positive** occurs when the WAF blocks or flags a legitimate request as malicious.\
This can happen due to aggressive rule patterns or incomplete exceptions.\
Proper handling of false positives helps maintain both **security** and **availability** of your applications.

{% hint style="info" %}
False positives are common during initial WAF configuration.\
Always start in **Monitoring Only** mode to observe behavior before activating full protection.
{% endhint %}

{% stepper %}
{% step %}
Identify False Positives

Use WAF logs and analytics to locate requests that were incorrectly blocked or flagged.

1. Open the [**Medianova Control Panel**](https://cloud.medianova.com).
2. Go to **Analytics → WAF Dashboard**.
3. Review blocked requests and event logs.
4. Look for requests that match normal user or API behavior but are classified as threats.

{% hint style="info" %}
Pay special attention to repetitive blocks from trusted IPs or common API endpoints — they are typical indicators of false positives.
{% endhint %}
{% endstep %}

{% step %}
Analyze Rule Behavior

Determine which rule caused the false detection.\
You can identify the **Rule ID** or **Rule Name** responsible by inspecting the event details in the WAF dashboard.

<table><thead><tr><th width="286">Common Cause</th><th>Example</th></tr></thead><tbody><tr><td>Overly broad request URI match</td><td>Blocking <code>/api/v1/</code> instead of <code>/api/v1/admin</code></td></tr><tr><td>Strict User Agent filtering</td><td>Blocking “curl” used in automated internal scripts</td></tr><tr><td>Missing whitelist entry</td><td>Internal monitoring IPs not excluded</td></tr><tr><td>Outdated rule condition</td><td>Old regex pattern still matching new endpoint</td></tr></tbody></table>

{% hint style="info" %}
Custom Rules take precedence over Managed Rules.\
If both apply, the Custom Rule’s action will execute.
{% endhint %}
{% endstep %}

{% step %}
Adjust Rules or Add Exceptions

After identifying the cause, fine-tune your rules to allow legitimate traffic while keeping protection active.

You can:

* **Modify an existing rule**
  * Adjust the **Field**, **Operator**, or **Value** for more precise matching.
  * Example: Change “contains `/api`” to “equals `/api/admin`”.
* **Change the rule action**
  * Temporarily switch from **Block** to **Log Only** to monitor.
* **Add an exception rule**
  * Allow requests from a specific **IP**, **URI**, or **User Agent**.
* **Whitelist internal services**
  * Add known internal IPs (monitoring tools, API clients) to an allowlist.

{% hint style="info" %}
Apply changes incrementally and review logs after each update to confirm resolution.
{% endhint %}
{% endstep %}

{% step %}
Validate After Adjustments

Once changes are made, monitor the WAF dashboard again:

1. Keep the affected rule in **Log Only** mode for several hours or days.
2. Check if the same requests are still flagged.
3. If no false alerts occur, switch the rule back to **Block** mode.

{% hint style="info" %}
Do not disable Managed Rules globally to avoid temporary false positives.\
Always isolate and fix the specific rule causing the issue.
{% endhint %}
{% endstep %}
{% endstepper %}


# WAF Analytics

Learn how to interpret the Web Application Firewall (WAF) dashboard and key analytics metrics in the Medianova Control Panel.

The **WAF Analytics Dashboard** provides visibility into malicious traffic, rule performance, and blocked requests detected by the **Web Application Firewall (WAF)**.\
You can monitor attacks in real time, identify their sources, and adjust your rules to improve detection accuracy.

{% hint style="info" %}
Analytics data is available when WAF is active in either **On** or **Monitoring Only** mode.
{% endhint %}

### Accessing the Dashboard

You can access the WAF analytics from the [**Medianova Control Panel**](https://cloud.medianova.com).\
Navigate to **Analytics → WAF**, then select the CDN Resource for which WAF is enabled.\
The dashboard displays real-time charts, tables, and logs that visualize threat activity, blocked requests, and triggered rules.

<figure><img src="/files/vjEnIIkpv5lD0LRRGA0q" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="info" %}
Metrics update automatically at short intervals, though the refresh rate may vary depending on your resource’s traffic volume.
{% endhint %}

### Key Metrics and Visualizations

**1. Attack Histogram**

Shows the **number of attacks over time**, helping you detect spikes or recurring patterns.\
You can filter by **URL** to analyze specific endpoints under attack.

**Use it for:** spotting attack trends and determining peak hours of malicious traffic.

<figure><img src="/files/vjEnIIkpv5lD0LRRGA0q" alt="" width="563"><figcaption></figcaption></figure>

**2. Threats**

Displays the total number of **requests that triggered WAF rules** versus total incoming requests.\
Includes summary values such as:

* **Total:** All detected threats since activation
* **Today:** Threats detected in the last 24 hours
* **This Month / Last Month:** Periodic comparison

**Use it for:** measuring overall WAF effectiveness and identifying sudden spikes that may signal an attack.

**3. Top Client IPs**

Lists the **IP addresses triggering the most WAF rules**.\
A pie chart provides a quick visual overview of threat sources.

**Use it for:** detecting potential attackers or regions generating malicious traffic.

{% hint style="info" %}
Repeated offenders can be blocked or rate-limited via Custom Rules.
{% endhint %}

<figure><img src="/files/W2xyOU1Z1YuzxWiWL8Ql" alt="" width="563"><figcaption></figcaption></figure>

**4. Top Request URIs**

Shows the **URLs most frequently targeted** by suspicious or blocked requests.

**Use it for:** identifying vulnerable endpoints or popular attack targets.\
If a specific path (e.g., `/login`, `/api/v1/auth`) appears repeatedly, consider applying additional rule protections.

<figure><img src="/files/xENCg7oJD9ocO8U1lZDJ" alt="" width="563"><figcaption></figcaption></figure>

**5. Top User Agents**

Lists browsers, bots, or automated clients generating flagged requests.

**Use it for:** distinguishing legitimate traffic from malicious bots.\
Unusual or outdated User Agents may indicate automated attack tools.

**6. Rule Activity**

Displays which **WAF rules are triggered most often**, showing their frequency and relative impact.

| Column             | Description                                         |
| ------------------ | --------------------------------------------------- |
| **Rule ID / Name** | Identifier of the triggered rule.                   |
| **Triggers**       | Number of times the rule matched incoming requests. |
| **Last Triggered** | Most recent occurrence time.                        |

**Use it for:** assessing rule efficiency and identifying potential false positives.\
Frequently triggered rules may need refinement or condition adjustments.

<figure><img src="/files/MYKZ1kUtWvvHg2XgwEop" alt="" width="563"><figcaption></figcaption></figure>

**7. Activity Log (Last 300 Requests)**

Shows detailed information about the **most recent flagged requests**, including:

* Timestamp
* IP address
* Request URI
* User Agent
* Triggered Rule

**Use it for:** investigating incidents and validating rule accuracy.\
Regular review helps fine-tune your security posture.

<figure><img src="/files/6LQER3Rd7V28sCOZaAYy" alt="" width="563"><figcaption></figcaption></figure>

#### Best Practices

* Review WAF analytics at least weekly to identify trends.
* Watch for repeated attacks from the same IPs or regions.
* Use the **Threats** and **Rule Activity** metrics to detect false positives or over-triggered rules.
* Adjust or refine rules based on recurring attack patterns.
* Combine analytics data with logs from your origin server for deeper context.

[<br>](https://clients.medianova.com/docs/web-application-firewall)


# Rate Limiting

Control traffic flow, protect resources, and ensure fair usage across your CDN resources with Medianova’s intelligent Rate Limiting feature.

## Rate Limiting

**Rate Limiting** helps protect your applications and origin infrastructure by controlling the rate at which clients can send requests to your CDN resource.

Rate limits are enforced at the **CDN edge**, before requests reach your origin servers. This helps reduce excessive traffic caused by high-frequency requests, abusive clients, automated traffic, or unexpected traffic spikes.

{% hint style="info" %}
Rate Limiting is available for **Dynamic CDN Resources** through the [**Medianova Control Panel**](https://cloud.medianova.com).
{% endhint %}

## **Why Use Rate Limiting?**

Rate Limiting helps you:

* Protect **origin servers and APIs** from excessive request traffic.
* Reduce the impact of **automated or abusive request patterns**.
* Protect sensitive endpoints such as **login and authentication services**.
* Prevent excessive requests from consuming unnecessary origin compute or database resources.
* Define request rates appropriate for different application workloads.

## **How Rate Limiting Works**

Rate Limiting evaluates incoming requests against a configured **request rate**.

You define the number of requests and a time unit, such as **Per Second** or **Per Minute**. The configured limit is evaluated continuously as a request rate rather than as a fixed request count that resets at the end of the selected time period.

For example, a limit of **100 requests per minute** is distributed over time and enforced continuously. It does not allow all 100 requests to be sent at once at any point during the minute.

You can use burst options when your application needs to tolerate short traffic spikes above the configured request rate.

## **Rate Limit Options**

Rate Limit Options determine how temporary traffic spikes above the configured request rate are handled:

* **None** – Enforces the configured request rate without additional burst capacity. Requests exceeding the permitted rate are subject to the configured action.
* **Burst** – Allows additional requests above the configured rate within the defined burst capacity. Requests within the burst capacity may be delayed and processed according to the configured rate.
* **Burst + No Delay** – Allows requests within the defined burst capacity to pass immediately without delay.

{% hint style="info" %}
Burst capacity does not increase the configured request rate. It provides temporary tolerance for short traffic spikes above the normal rate.
{% endhint %}

## **Key Features**

* **Configurable Request Rates** – Define request rates per second or minute based on your application requirements.
* **Edge-Level Enforcement** – Apply rate limits at the CDN edge before excessive traffic reaches your origin.
* **Burst Control** – Control how temporary traffic spikes above the configured request rate are handled.
* **IP Whitelisting** – Exclude trusted IP addresses or networks from rate enforcement.
* **Configurable Actions** – Define how requests are handled when the permitted rate is exceeded.
* **Configurable Response Codes** – Select the HTTP response code returned for blocked requests.
* **Path & Extension Based Rate Limiting** – Apply separate rate limiting rules to specific URL paths or file extensions through Page Rules.

## **Use Cases**

* **API Protection** – Control high-frequency API requests and reduce excessive origin traffic.
* **Authentication Endpoints** – Limit request rates for login and authentication services.
* **Traffic Spike Management** – Control short increases in request traffic based on your application requirements.
* **Bot and Scraper Control** – Reduce excessive requests generated by automated clients.
* **Origin Protection** – Prevent high request rates from unnecessarily consuming origin compute, application, or database resources.

## **Resource-Level and Path-Based Rate Limiting**

Resource-level Rate Limiting for **Dynamic CDN Resources** is configured under **Security → Rate Limiting** in the [Medianova Control Panel](https://cloud.medianova.com).

{% hint style="info" %}
For more granular control, **Path & Extension Based Rate Limiting** can be configured through **Page Rules** to apply separate limits to specific URL paths or file extensions.
{% endhint %}

For example, you can apply different rate limits to:

* `/login`
* `/api/`
* `/checkout`
* `.pdf`
* `.mp4`

See [Path & Extension Based Rate Limiting](/products/performance-cdn/static-content-delivery/advanced-configuration/page-rules/page-rules-settings/path-and-extension-based-rate-limiting) for more information.

{% hint style="info" %}
Start with moderate request rates and adjust them based on your application's normal traffic patterns. Limits that are too restrictive may affect legitimate users or API traffic.
{% endhint %}


# Configure Rate Limiting

**Rate Limiting** controls the rate at which clients can send requests to your CDN resource. The configured request rate is enforced at the **CDN edge**, helping prevent excessive traffic from reaching your origin servers.

This guide explains how to configure resource-level Rate Limiting and control how temporary traffic spikes above the configured rate are handled.

{% hint style="info" %}
Rate Limiting is available only for **Dynamic CDN Resources** under **Security → Rate Limiting** in the [**Medianova Control Panel**](https://cloud.medianova.com).
{% endhint %}

{% stepper %}
{% step %}

## **Access Rate Limiting**

The Rate Limiting settings for the selected resource are displayed.
{% endstep %}

{% step %}

### **Enable Rate Limiting**

Enable **Rate Limit Status** to activate Rate Limiting for the selected resource.

Once enabled, you can configure the request rate, burst behavior, IP whitelisting, and the action applied when the permitted rate is exceeded.
{% endstep %}

{% step %}

### **Set the Request Limit**

In **Request Limit**, specify the request limit value and select the time unit, such as **Per Second** or **Per Minute**.

The configured limit is evaluated continuously as a request rate rather than as a fixed request count that resets at the end of the selected time period.

For example, a limit of **100 requests per minute** is distributed over time and enforced continuously. It does not allow all 100 requests to be sent at once at any point during the minute.

{% hint style="info" %}
Start with moderate request rates and adjust them based on your application's normal traffic patterns. Limits that are too restrictive may affect legitimate users or API traffic.
{% endhint %}
{% endstep %}

{% step %}

### **Choose a Rate Limit Option**

Use **Rate Limit Options** to define how temporary traffic spikes above the configured request rate are handled.

Select one of the following options:

* **None** — Enforces the configured request rate without additional burst capacity. Requests exceeding the permitted rate are subject to the configured action.
* **Burst** — Allows additional requests above the configured rate within the defined burst capacity. Requests within the burst capacity may be delayed and processed according to the configured rate.
* **Burst + No Delay** — Allows requests within the defined burst capacity to pass immediately without delay.

When a burst option is selected, configure the **Burst Value** to define the additional capacity available for temporary traffic spikes.

{% hint style="info" %}
Burst capacity does not increase the configured request rate. It provides temporary tolerance for short traffic spikes above the normal rate.
{% endhint %}
{% endstep %}

{% step %}

### **Configure IP Whitelisting (Optional)**

Enable **Whitelist IP Status** if trusted IP addresses or networks should bypass Rate Limiting.

Add the IP addresses or networks that should be excluded from rate enforcement.

{% hint style="info" %}
Use IP whitelisting for trusted traffic sources such as internal monitoring systems or administrative services that should not be rate limited.
{% endhint %}
{% endstep %}

{% step %}

### **Define the Action**

Use **Actions** to define what happens when requests exceed the permitted request rate or available burst capacity.

For example, select **Block** to reject requests that exceed the configured limits.

Then select the **Status Code** returned for blocked requests, such as:

* `429` — Too Many Requests
  {% endstep %}

{% step %}

### **Submit the Configuration**

Review your Rate Limiting settings and click **Submit**.

The Rate Limiting configuration is then applied to the selected Dynamic CDN Resource.

{% hint style="info" %}
After applying the configuration, test it against representative traffic patterns to verify that legitimate traffic is handled as expected.
{% endhint %}
{% endstep %}
{% endstepper %}

## Path & Extension Based Rate Limiting

In addition to resource-level Rate Limiting, you can configure rate limiting rules for specific **URL paths** or **file extensions** through **Page Rules**.

Use Path & Extension Based Rate Limiting when different parts of your application require different request rates. For example, you can apply separate limits to:

* Sensitive routes such as `/auth/`, `/checkout`, or `/login`.
* API paths such as `/api/`.
* Specific file types such as `.pdf`, `.jpg`, or `.mp4`.

Path- and extension-based rules use the same rate limiting behavior, including continuous rate enforcement and burst handling, but are configured separately under [**Page Rules**](/products/performance-cdn/static-content-delivery/advanced-configuration/page-rules).

{% hint style="info" %}
IP whitelisting is not available for Page Rule-based Rate Limiting.
{% endhint %}

{% hint style="success" %}
**Learn more:** See [Path & Extension Based Rate Limiting](/products/performance-cdn/static-content-delivery/advanced-configuration/page-rules/page-rules-settings/path-and-extension-based-rate-limiting) for configuration steps and examples.
{% endhint %}


# Network Rate Limit

Network Rate Limit controls how quickly content is delivered to clients by applying a transfer speed limit after a configurable amount of data has been transferred.

{% hint style="success" %}
This feature can be used alongside [Rate Limiting](/products/security/rate-limiting) to control both request volume and content delivery speed.
{% endhint %}

This feature can be used to manage bandwidth consumption and control the delivery rate of large files or streaming content.

### How Network Rate Limit Works

Network Rate Limit is configured using two parameters:

<table data-header-hidden><thead><tr><th width="236.4000244140625"></th><th></th></tr></thead><tbody><tr><td>Parameter</td><td>Description</td></tr><tr><td>Rate Limit</td><td>Maximum transfer speed applied after the threshold is reached.</td></tr><tr><td>Threshold</td><td>Amount of data transferred before the rate limit is enforced.</td></tr></tbody></table>

Content is delivered at normal speed until the configured threshold is reached. Once the threshold is exceeded, the CDN limits the transfer rate according to the configured value.

### Configuration

Enable **Network Rate Limit** and configure the following settings:

#### Rate Limit

Defines the maximum transfer speed applied to content delivery after throttling begins.

Supported units:

* KB/s
* MB/s

#### Threshold

Defines how much data can be transferred before the configured rate limit takes effect.

Supported units:

* KB
* MB

### Example

The following configuration:

* Rate Limit: **1 MB/s**
* Threshold: **512 MB**

Allows the first 512 MB of content to be delivered without restriction. After 512 MB has been transferred, the CDN limits delivery speed to 1 MB/s.

### Common Use Cases

{% hint style="info" %}
Network Rate Limit can also be combined with [Geo Blocking](/products/security/geoblocking), [IP Restriction](/products/security/ip-restriction), and Security Token to apply bandwidth controls only to specific audiences or protected content.
{% endhint %}

#### Large File Delivery

Prevent excessive bandwidth consumption when distributing large software packages, backups, or downloadable assets.

#### Media Distribution

Allow video playback or file downloads to start quickly while controlling sustained transfer rates for long-running sessions.

#### Bandwidth Management

Reduce the impact of high-volume transfers on overall resource consumption.

### Important Notes

* Rate limiting is enforced at the CDN edge.
* Content is delivered at full speed until the configured threshold is reached.
* Lower rate limits may increase download completion times.
* Threshold values should be configured carefully to balance user experience and bandwidth control.


# Origin Basic Authentication

Authenticate CDN requests to your origin using HTTP Basic Authentication.

Origin Basic Authentication allows the CDN to authenticate requests to your origin server using HTTP Basic Authentication credentials.

When enabled, the CDN includes the configured username and password in every origin request. This allows access to origins protected by HTTP Basic Authentication without exposing credentials to clients.

{% hint style="info" %}
Origin Basic Authentication affects only requests sent from the CDN to your origin server. It does not change viewer requests or responses.
{% endhint %}

### Configure Origin Basic Authentication

In the [Medianova Control Panel](https://cloud.medinaova.com), select your Dynamic CDN Resource and open the **Security** tab

<figure><img src="/files/GDirLWRX7by7bZSiMWl9" alt=""><figcaption></figcaption></figure>

See: [API Reference](/api-documentation/security/origin-basic-authentication) – Origin Basic Authentication

{% stepper %}
{% step %}

### Enable the Feature

Enable the **Status** toggle.
{% endstep %}

{% step %}

### Enter Origin Credentials

Provide the username and password configured on your origin server for HTTP Basic Authentication.
{% endstep %}

{% step %}

### Save the Configuration

Click **Submit** to deploy the updated configuration.
{% endstep %}
{% endstepper %}

### How It Works

When Origin Basic Authentication is enabled:

* The CDN authenticates to your origin using the configured HTTP Basic Authentication credentials.
* Authentication is performed for origin requests only.
* Clients never receive or see the configured credentials.
* Every origin fetch uses the configured username and password until the feature is disabled or the credentials are updated.

### Important Notes

* The configured username and password must match the credentials expected by your origin server.
* Incorrect credentials may cause origin requests to fail with authentication errors.
* Viewer requests are not modified.
* Credentials are used only for communication between the CDN and the origin server.


# User Agent ACL

Control access to content by allowing or blocking requests based on User-Agent header values.

User Agent ACL allows you to control access to content by evaluating the User-Agent header of incoming requests.

You can create whitelist or blacklist rules using full or partial User-Agent values to allow or deny access for specific browsers, applications, crawlers, or automated clients.

### Configure User Agent ACL

#### Enable the Feature

Turn **Status** to **On**.

<figure><img src="/files/Lf5y4i9n6yLzfd6NFYrb" alt=""><figcaption></figcaption></figure>

#### Select the Rule Mode

Choose one of the following modes:

* **Whitelist** — Only matching User-Agent values are allowed.
* **Blacklist** — Matching User-Agent values are blocked.

#### Select the Match Type

Choose how User-Agent values should be evaluated:

* **Contains** — Matches any User-Agent containing the specified value.
* **Exact Match** — Requires the entire User-Agent value to match exactly.

#### Add User-Agent Rules

Enter the User-Agent value and click **+** to add the rule.

#### Save the Configuration

Click **Submit** to apply the changes.

### How It Works

The CDN evaluates the User-Agent request header against the configured rules.

Depending on the selected mode:

* Matching requests may be allowed.
* Matching requests may be blocked.

Requests that do not match the configured rules follow the behavior defined by the selected whitelist or blacklist mode.

### Common Use Cases

* Block known crawlers or scraping tools
* Restrict access to specific client applications
* Allow access only to approved applications
* Filter unwanted automated traffic

### Important Notes

* User-Agent values are supplied by the client and can be modified or spoofed.
* User Agent ACL should not be used as the sole security mechanism for protecting sensitive content.
* Consider combining User Agent ACL with Rate Limiting, WAF, Security Token, or IP Restriction for stronger protection.


# Geoblocking

Restrict or allow access to your CDN Resources based on geographic location by configuring country-based whitelists and blacklists.

**Geoblocking** allows you to control which countries can access your content through the [Medianova Control Panel](https://cloud.medianova.com).\
By enabling this feature, you can restrict or allow requests based on the visitor’s geographic origin, helping you comply with regional policies and protect your digital assets.

{% hint style="warning" %}
Geoblocking operates at the CDN edge, preventing unauthorized access before requests reach your origin server.
{% endhint %}

#### Why Use Geoblocking?

Use **Geoblocking** to manage access and enforce content distribution policies efficiently:

* **Compliance and licensing** – Restrict access to regions where content rights do not apply.
* **Dynamic pricing models** – Apply different pricing or service availability by country.
* **Security enhancement** – Block known high-risk regions or malicious traffic.
* **Content optimization** – Focus delivery to target markets, reducing unnecessary traffic.

{% hint style="warning" %}
Combine Geoblocking with **IP Restriction** for granular, IP-based exceptions within approved countries.
{% endhint %}

### How to Configure Geoblocking

{% stepper %}
{% step %}
Log in to the **Medianova Control Panel**.
{% endstep %}

{% step %}
Go to **CDN → CDN Resources** and select the resource you want to manage.
{% endstep %}

{% step %}
Open the **Security** tab.
{% endstep %}

{% step %}
Enable the **Geoblocking** toggle.
{% endstep %}

{% step %}
From the country list:

* Drag or select countries to the **Whitelist** (allowed).
* Drag or select countries to the **Blacklist** (blocked).
  {% endstep %}

{% step %}
Click **Save Changes** to apply your configuration.
{% endstep %}

{% step %}
(Optional) Add specific IP exceptions under **IP Restriction** for fine-tuned control.

{% hint style="info" %}
You cannot whitelist and blacklist the same country simultaneously.
{% endhint %}
{% endstep %}
{% endstepper %}


# FAQs

<details>

<summary>How does Medianova’s DDoS protection work?</summary>

Medianova’s DDoS protection works through integrated strategies like rate limiting, IP blocking, geoblocking, Anycast DNS, Origin Shield, and WAF integration to prevent overload, block threats, and protect your origin server.

</details>

<details>

<summary>Does CDN Reduce DDoS Attacks?</summary>

Yes, a CDN reduces DDoS attacks by distributing traffic across multiple servers, using Anycast DNS, rate limiting, and shielding the origin server. It minimizes the attack impact and improves resilience.

</details>

<details>

<summary>Do I need to manually activate DDoS protection on Medianova?</summary>

Medianova’s Always-On DDoS Protection is active by default, providing automatic protection for your web assets against common DDoS attack types, including DNS Query Floods, SlowLoris, HTTPS GET requests, and HTTPS POST requests. No additional activation or manual configuration is required.

</details>

<details>

<summary>What types of SSL certificates are supported by Medianova CDN?</summary>

Medianova CDN supports a wide range of SSL certificates, including:

* Wildcard SSL Certificates
* SAN-supported SSL Certificates
* Code Signing SSL Certificates
* Domain SSL, Organization Validated SSL, and Extended SSL Certificates

</details>

<details>

<summary>How can I upload and manage SSL Certificates?</summary>

Yes, it is possible. For detailed instructions, please refer to the **"How to Upload and Manage SSL Certificates"** documentation.

</details>

<details>

<summary>What file formats are supported for SSL certificates?</summary>

Medianova supports standard SSL certificate formats, including `.crt` for certificates and `.key` for private keys.

</details>

<details>

<summary>Can I add multiple SSL certificates to my organization?</summary>

Yes, you can add multiple SSL certificates to your organization. Each certificate can be associated with different resources or domains.

</details>

<details>

<summary>How can I use Free SSL?</summary>

Yes, you can use Free SSL. For detailed steps, please refer to the **"How Can I Use Free SSL?"** documentation.

</details>

<details>

<summary>Does Medianova support TLS 1.3?</summary>

Yes, Medianova CDN supports TLS 1.3, the latest version of the TLS protocol, which offers enhanced security and faster performance compared to its predecessors.

</details>

<details>

<summary>What are the differences between “SNI” and “Shared SSL”?</summary>

**SNI (Server Name Indication)**: This option allows you to use your **own SSL certificate** uploaded via the panel for a specific CDN Resource.

**Shared SSL**: If you don’t have your own SSL certificate, Medianova provides a shared SSL option that can be used for secure connection

</details>

<details>

<summary>Can I edit an uploaded SSL certificate?</summary>

You can only **rename** an SSL certificate in the **SSL Management** menu. Other edits, such as updating the certificate or private key, are not allowed. If changes are needed, delete the existing certificate and upload a new one.

</details>

<details>

<summary>How do I delete an SSL certificate?</summary>

To delete an SSL certificate:

1. Go to **“CDN → SSL Management”**.
2. Click on the **“Delete”** option next to the certificate.
3. Confirm the action in the pop-up window that appears.

</details>

<details>

<summary>What is a Private Key, and why is it important?</summary>

The **Private Key** is a critical part of the SSL certificate that ensures secure communication. It is based on asymmetric encryption and must be **kept secret**:

* The **Private Key** stays on the web server and is never shared.
* The **Public Key** is shared openly to establish secure communication.

</details>

<details>

<summary>What happens if I don’t own an SSL certificate?</summary>

If you don’t have your own SSL certificate, you can:

* Use the **“Shared SSL”** option provided by Medianova.
* Utilize the **“Free SSL”** option, which generates a certificate through **Let’s Encrypt**.

</details>

<details>

<summary>What is the difference between "Monitoring Only" and "On" modes in WAF?</summary>

* **Monitoring Only**: In this mode, WAF monitors all incoming traffic for potential threats without blocking any traffic. It provides insights into your security posture and allows you to fine-tune rules before enforcing them.
* **On**: In this mode, WAF actively filters and blocks malicious traffic, providing full protection for your web assets.

</details>

<details>

<summary>Can I view real-time threats blocked by WAF?</summary>

Yes, the WAF service provides real-time monitoring and logging of blocked threats, which can be viewed under **Analytics → WAF** in the panel.

</details>

<details>

<summary>Can I configure WAF for Dynamic CDN Resources?</summary>

Yes, you can configure the WAF for Dynamic CDN Resources. When creating a Dynamic CDN Resource, follow the steps to activate and configure the WAF as per your security requirements.

</details>

<details>

<summary>How do I create a custom rule in WAF?</summary>

To create a custom rule in WAF, please refer to the **"How to Activate WAF"** documentation for detailed guidance.

</details>

<details>

<summary>How can I handle false positives in WAF?</summary>

To handle false positives in WAF, enable Monitoring-Only mode to analyze traffic. Disable the specific rule causing the issue or create custom rules to prevent it, ensuring security remains intact.

</details>

<details>

<summary>Can I edit or delete a custom rule in WAF?</summary>

Yes, you can edit or delete custom rules by clicking the Edit or Delete icons and submitting the changes.

</details>

<details>

<summary>How can I configure Rate Limiting?</summary>

To configure Rate Limiting, please refer to the **"Rate Limiting"** documentation for detailed steps, where you will find instructions on how to log in, select resources, and configure settings in the Security tab.

</details>

<details>

<summary>How do I set the request limits?</summary>

Under the **Request Limit** section, specify the maximum number of requests allowed per second or minute.

Adjust the values based on your traffic volume and server capacity.

</details>

<details>

<summary>What is the difference between the "Burst" and "Burst + No Delay" options?</summary>

**Burst** allows a burst of requests but applies throttling once the threshold is exceeded.

**Burst + No Delay** allows a burst of requests without any initial delay, providing quicker responsiveness before applying throttling.

</details>

<details>

<summary>What is the "Burst Value" and how is it used?</summary>

The **Burst Value** defines the threshold for the burst limit when the **Burst** or **Burst + No Delay** option is selected. It specifies how many requests are allowed in a burst before throttling is applied.

</details>

<details>

<summary>What HTTP status codes can be configured for Rate Limiting?</summary>

You can choose one of the following HTTP status codes to return when the rate limit is exceeded:

* **429 Too Many Requests**: Indicates that the client has exceeded the allowed number of requests within the specified time window.
* **529 Site Overloaded**: Used when the server is overloaded and unable to process requests due to excessive traffic.

</details>

<details>

<summary>How can I define actions for excessive requests?</summary>

* **Block**: Deny requests that exceed the rate limit.
* **Challenge**: Present a CAPTCHA to validate the request.

</details>

<details>

<summary>How can I enable Hotlink Protection for my CDN Resource?</summary>

To enable Hotlink Protection, please refer to the **"Hotlink Protection"** documentation for detailed instructions on configuring it in the [Medianova Control Panel](https://cloud.medianova.com).

</details>

<details>

<summary>How do I whitelist domains for Hotlink Protection?</summary>

In the **Hotlink Protection** section, you can add **whitelisted domains** that are allowed to access your CDN resources.

These domains will be granted permission to link to or embed your resources.

</details>

<details>

<summary>What happens if a request comes from a non-whitelisted domain?</summary>

If a request comes from a non-whitelisted domain (i.e., a blacklisted or unauthorized source), the server will:

* Block access to the resource.
* Optionally, you can configure the server to redirect the request to a specific page or serve a placeholder image.

</details>

<details>

<summary>How can I disable Hotlink Protection?</summary>

If you want to disable Hotlink Protection, simply toggle the **Hotlink Protection** option to **Off** in the **Security** menu of your selected CDN Resource.

</details>

<details>

<summary>What is the difference between Whitelist and Blacklist?</summary>

**Whitelist**: Only devices with IP addresses listed in the whitelist are allowed access to the designated resources. All other IP addresses are denied access.

**Blacklist**: Devices with IP addresses listed in the blacklist are denied access to the resources. All other devices are allowed access.

</details>

<details>

<summary>What happens if an IP address is not in the Whitelist or Blacklist?</summary>

If **Whitelist** is selected, only the listed IP addresses will have access, and all other IP addresses will be denied.

If **Blacklist** is selected, all IP addresses except those in the blacklist will have access to the resources

</details>

<details>

<summary>Why would I use the Whitelist option?</summary>

You would use the **Whitelist** option if you want to grant access to specific, trusted IP addresses (e.g., business partners, internal network) and deny all other requests.

</details>

<details>

<summary>Why would I use the Blacklist option?</summary>

The **Blacklist** option is useful if you want to block specific IP addresses that are known for malicious activity or unwanted access, while allowing all other devices to access the resources.

</details>

<details>

<summary>What happens if I make changes to the IP Restriction ACL settings?</summary>

After making changes to the IP Restriction ACL settings, click **Save Changes** to apply the new access control policy. The changes will immediately take effect.

</details>

<details>

<summary>How do I enable Geoblocking on Medianova Control Panel?</summary>

To enable Geoblocking, please refer to the **"Geoblocking"** documentation for detailed steps on configuring country-based restrictions in the Medianova Control Panel.

</details>

<details>

<summary>Can I update my Geoblocking settings after enabling it?</summary>

Yes, you can update your whitelist and blacklist at any time. Simply move the countries between the whitelist and blacklist boxes, and click **Save Changes** to apply the updates.

</details>

<details>

<summary>Can I block or allow specific IP addresses using Geoblocking?</summary>

Yes, in addition to country-based restrictions, you can also manage IP-based restrictions. Scroll to the **IP Restriction** section at the bottom of the page to whitelist or blacklist specific IP addresses.

</details>

<details>

<summary>How do I add or remove countries from the whitelist or blacklist?</summary>

To **add** a country, drag it from the country list on the left to either the **Whitelist** or **Blacklist** pane.

To **remove** a country, simply drag it out of the whitelist or blacklist pane and into the country list.

</details>

<details>

<summary>Can I apply Geoblocking to a specific CDN resource?</summary>

Yes, Geoblocking can be applied to individual CDN resources. You can configure the settings for each CDN resource separately.

</details>

<details>

<summary>Can I enable Geoblocking without using the IP Restriction section?</summary>

Yes, you can enable Geoblocking without using the IP Restriction section. The IP Restriction section is optional and can be used for more granular control over access.

</details>


# Performance / CDN


# Static Content Delivery

Deliver images, scripts, and other static assets faster and more reliably across the globe with Medianova’s Static CDN service.

**Static Content Delivery** enables organizations to deliver cacheable content efficiently through Medianova’s globally distributed CDN network. By caching static assets at edge locations, content is served from the nearest available Point of Presence (PoP), reducing latency, minimizing origin traffic, and improving application performance.

This category includes multiple CDN resource types designed for different content delivery requirements, including **Small CDN**, **Large CDN**, and **Video on Demand (VOD)**.

{% hint style="info" %}
Choose the resource type that best matches your content. Small CDN is optimized for static web assets, Large CDN for large file delivery and live streaming, and VOD for on-demand video streaming.
{% endhint %}

## Why Use Static Content Delivery?

Medianova's Static Content Delivery services provide a scalable and secure platform for delivering cacheable content.

* **Lower Latency** – Serve content from the nearest edge location.
* **Reduced Origin Load** – Cache frequently requested content at the edge.
* **Global Availability** – Deliver content consistently across geographically distributed PoPs.
* **High Scalability** – Handle traffic spikes without additional origin capacity.
* **Secure Delivery** – Protect content using HTTPS and SSL/TLS.
* **Performance Optimization** – Support compression, caching, and intelligent content delivery.

<figure><img src="/files/bmh9nXXkaZiQmKUFK8nZ" alt=""><figcaption><p>Medianova Static Content Delivery Architecture</p></figcaption></figure>

## Available Resource Types

### Small CDN

Optimized for websites and web applications that primarily deliver static assets such as images, CSS, JavaScript, and fonts.

Typical use cases include:

* Websites
* Corporate portals
* E-commerce storefronts
* Static web applications

### Large CDN

Designed for distributing large downloadable files and supporting live streaming workflows.

Typical use cases include:

* Software downloads
* Game patches
* Archives
* Large media files
* Live streaming (RTMP Push)

### Video on Demand (VOD)

Designed for delivering pre-recorded video using adaptive streaming technologies.

Typical use cases include:

* Video libraries
* Online education
* OTT platforms
* Media portals

Supports adaptive streaming formats including **HLS** and **MPEG-DASH**.

## Common Features

All Static Content Delivery resource types provide:

* Edge caching
* Custom domains (CNAME)
* HTTPS and SSL/TLS support
* Compression
* Global Anycast delivery
* Analytics and monitoring
* High availability

### Related Resources

* [Small CDN](/products/performance-cdn/static-content-delivery/create-small-cdn-resource)
* [Large CDN](/products/performance-cdn/static-content-delivery/create-large-cdn-resource)
* [Video on Demand](/products/performance-cdn/static-content-delivery/create-vod-resource)
* [Dynamic CDN](/products/performance-cdn/dynamic-content-acceleration)
* [Image Optimization](/products/performance-cdn/image-optimization-and-webp)


# Create Small CDN Resource

Learn how to create a Small CDN Resource in the Medianova Control Panel for static content delivery.

A Small CDN Resource is designed for delivering static web assets such as images, CSS, JavaScript, and web fonts.

Content is cached and served from Medianova's global edge network to reduce latency, improve website performance, and offload requests from your origin infrastructure.

You can configure a Small CDN Resource to:

* Fetch content from your own infrastructure (**Customer Origin**)
* Serve content stored in [**Stook Object Storage**](/products/object-storage-stook/stook-cloud-object-storage) (**Origin Push**)

{% hint style="info" %}
The Create CDN wizard provides a guided workflow for selecting the resource type, configuring the source and SSL settings, reviewing the configuration, and deploying the resource.

Configuration is saved automatically as a draft until the resource is created or discarded.
{% endhint %}

### When to use a Small CDN Resource

Use a Small CDN Resource for static website assets, including:

* Images
* CSS files
* JavaScript files
* Web fonts
* Other static website resources

{% hint style="info" %}
If your content includes any of these extensions, create a [**Large CDN Resource**](/products/performance-cdn/static-content-delivery/create-large-cdn-resource) (for large downloads or live streaming) or a [**VOD Resource**](/products/performance-cdn/static-content-delivery/create-vod-resource) (for on-demand video) instead.
{% endhint %}

{% hint style="warning" %}
**Unsupported file extensions**\
Small CDN Resources do **not** support the following file extensions.\
Requests for these file types return **HTTP** **403 Forbidden** responses.\
`3gp, 3gpp, aac, asf, asx, avi, f4v, flv, m2p, m4a, m4v, midi, mov, mp3, mp4, mpeg, mpg, ogg, ogv, wav, wm`
{% endhint %}

## Create a Small CDN Resource

Create and manage **Small CDN Resources** from the [**Medianova Control Panel**](https://cloud.medianova.com).

Navigate to **CDN** and select **Create CDN Resource** to launch the resource creation wizard.

<figure><img src="/files/DV2Car2mD1B59kiXPMO2" alt=""><figcaption></figcaption></figure>

The Create CDN wizard opens as an overlay without leaving the current page.

{% stepper %}
{% step %}

### Select the Resource Type

Navigate to **CDN** and click **Create CDN Resource**.

The **Create CDN** wizard opens.

<figure><img src="/files/Xmihid45FOOVNI3Knoys" alt=""><figcaption></figcaption></figure>

Select **Small CDN**, then click **Create** to continue.
{% endstep %}

{% step %}

### Enter the Resource Name

Provide the information required to identify the CDN Resource.

**Resource Name**

Enter a unique resource name.

The resource name is used to generate the default CDN hostname.

Example:

```c
example.sm.mncdn.com
```

**Internal Label (Optional)**

Enter an internal label to help identify the resource.

{% hint style="info" %}
Optionally assign a private label to help your team identify and manage the resource. Internal labels are used only within the Control Panel and API filtering and do not affect the public hostname.
{% endhint %}

Click **Next**.
{% endstep %}

{% step %}

### Configure Your Source

Select where the CDN should retrieve content from. You can use your own origin infrastructure or content stored in Medianova Stook Object Storage.

**Customer Origin**

Select **Customer Origin** to use your own web server, application server, load balancer, or storage endpoint as the origin.

Click **Add Origin**.

The **Add Origin** dialog opens.

Configure the following fields:

<table><thead><tr><th width="271">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Protocol</strong></td><td>Select the protocol used for connections from the CDN to the origin. Available options are <strong>HTTP</strong>, <strong>HTTPS</strong>, and <strong>Same as Request</strong>. <strong>Same as Request</strong> uses the protocol of the incoming client request.</td></tr><tr><td><strong>Domain or IP Address</strong></td><td>Enter the hostname or IP address of the origin server. Do not include the protocol or a URL path.</td></tr><tr><td><strong>HTTP Port</strong></td><td>Enter the port used for HTTP origin connections. The default value is <code>80</code>.</td></tr><tr><td><strong>HTTPS Port</strong></td><td>Enter the port used for HTTPS origin connections. The default value is <code>443</code>.</td></tr><tr><td><strong>Host Header</strong> <em>(Optional)</em></td><td>Specify the value sent in the HTTP <code>Host</code> request header. Leave this field blank to use the configured origin domain.</td></tr><tr><td><strong>Origin SNI Request</strong> <em>(Optional)</em></td><td>Specify the hostname sent through Server Name Indication during the TLS handshake with an HTTPS origin. Leave this field blank to use the configured origin domain.</td></tr><tr><td><strong>Priority</strong></td><td>Set the origin priority. Select <strong>Primary</strong> for an origin that should actively receive requests.</td></tr><tr><td><strong>Weight</strong></td><td>Define how traffic is distributed between origins with the same priority. Supported values range from <code>1</code> to <code>100</code>; a higher value receives a larger proportion of traffic.</td></tr><tr><td><strong>S3 Presigned Authentication</strong></td><td>Enable this option when the origin requires S3 presigned authentication for CDN-to-origin requests.</td></tr></tbody></table>

{% hint style="info" %}
The **Host Header** and **Origin SNI Request** fields serve different purposes:

* **Host Header** identifies the virtual host in the HTTP request.
* **Origin SNI Request** identifies the requested hostname during the TLS handshake.

For HTTPS origins, ensure that the Origin SNI hostname matches a domain covered by the origin server's SSL certificate.
{% endhint %}

Click **Save Origin**.

The configured origin is added to the resource. Repeat this process to configure additional origin servers.

Click **Add Origin** to configure one or more origin servers.

#### Stook Object Storage

Select [**Stook Object Storage**](/products/object-storage-stook/stook-cloud-object-storage) to use an existing Stook bucket as the origin for this CDN resource.

Configure the following fields:

<table><thead><tr><th width="189.666748046875">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Storage Bucket</strong></td><td>Select the <a href="/pages/BzTgMnccJHHvwcxByFcS">Stook bucket</a> that contains the content to be served through the CDN.</td></tr><tr><td><strong>Subfolder</strong> <em>(Optional)</em></td><td>Restrict the origin to a specific folder within the selected bucket. Only objects under this path are served by the CDN.</td></tr></tbody></table>
{% endstep %}

{% step %}

### Configure SSL/TLS

Choose how HTTPS should be configured for your CDN resource.

Select one of the following certificate options:

* Use Existing SSL
* Add Own SSL
* Free SSL
* Skip for Now

#### Use Existing SSL

Assign an SSL certificate that already exists in your account.

#### Configuration

* Select a certificate from the list.
* Continue to the next step.

{% hint style="info" %}
Only certificates available in your account are listed. To create a new certificate, select [**Add Own SSL**](/products/performance-cdn/static-content-delivery/advanced-configuration/cname-and-ssl) or [**Free SSL**](/products/security/ssl-tls-encryption/use-free-ssl-certificates).
{% endhint %}

#### Add Own SSL

Create a new certificate by uploading your own certificate files.

For detailed certificate upload instructions, see [**CNAME & SSL**.](/api-documentation/performance-cdn/cname-and-ssl)

#### Required fields

* SSL Certificate Name
* Certificate format
* Domain

Supported formats:

* Domain SSL
* Paste `.crt` / `.key`
* Upload Files
* `.pfx` / PKCS#12

#### Free SSL

Provision a free Let's Encrypt certificate. See [**Use Free SSL Certificates**](/products/security/ssl-tls-encryption/use-free-ssl-certificates)

#### Required fields

* SSL Certificate Name
* Domain
* Coverage
  * Single Domain
  * Wildcard

{% hint style="info" %}
Wildcard certificates require DNS (CNAME) validation.
{% endhint %}

#### Skip for Now

Continue without assigning a dedicated certificate.

The CDN is created using Medianova's shared SSL certificate for the default MNCDN hostname.

{% hint style="info" %}
If you later configure a custom domain, you can assign a dedicated certificate from **Settings →** [**SSL & TLS**](/products/security/ssl-tls-encryption).
{% endhint %}
{% endstep %}

{% step %}

### Review & Activate

Review your resource configuration before creating the CDN resource. All settings can be modified later from the Control Panel.

The summary includes:

<table><thead><tr><th width="137.6666259765625">Section</th><th>Description</th></tr></thead><tbody><tr><td><strong>Resource</strong></td><td>Displays the selected resource type, CDN hostname, and internal label.</td></tr><tr><td><strong>Source</strong></td><td>Shows the selected origin type, primary origin, and origin protocol.</td></tr><tr><td><strong>SSL / TLS</strong></td><td>Displays the selected certificate method and assigned certificate, if applicable.</td></tr><tr><td><strong>Propagation</strong></td><td>Shows the CDN hostname that will be provisioned and the protocol that will be served.</td></tr></tbody></table>

If the configuration is valid, a confirmation message indicates that the resource is ready to deploy.

Click **Create Resource** to provision the CDN resource.

{% hint style="success" %}
New CDN resources are typically provisioned within **30 seconds**.
{% endhint %}
{% endstep %}
{% endstepper %}

## Validate CDN Delivery

After the resource is created, verify that the CDN is serving content.

```bash
curl -svo /dev/null "https://example.mncdn.com/" --compressed
```

Replace `example.mncdn.com` with your CDN hostname or custom CNAME.

The requested URL should return **HTTP 200 OK**.

This command:

* Sends an HTTP GET request to the CDN endpoint.
* Displays the remote IP address.
* Displays the HTTP request and response headers.
* Discards the response body.

If validation fails:

* Verify that the origin server is reachable.
* Verify that the configured origin port is accessible.
* Verify that the requested path exists on the origin.

## Troubleshooting

* Verify that the origin server is reachable from the CDN.
* Confirm that the configured origin port is open.
* Ensure DNS changes have propagated before testing a custom CNAME.
* Verify that the assigned SSL certificate matches the requested hostname.
* Confirm that the origin serves the requested content and returns the expected response.


# Create Large CDN Resource

Learn how to create a Large CDN Resource for large-file delivery, packaged live streams, or RTMP ingest.

A Large CDN Resource is designed for large downloadable objects and live streaming workloads. It supports static large-file delivery from a customer origin or Stook Object Storage, as well as live stream delivery through an existing streaming origin or RTMP Push.

## When to Use a Large CDN Resource

Use a Large CDN Resource for:

* Large downloadable files such as video, audio, `.zip`, and `.exe` files
* Archives and software packages
* Existing HLS or DASH streams
* Live streams published through RTMP Push

{% hint style="info" %}
For images, CSS, JavaScript, web fonts, and other small static assets, use a [Small CDN Resource](/products/performance-cdn/static-content-delivery/create-small-cdn-resource).
{% endhint %}

{% hint style="info" %}
For prerecorded video that requires automatic adaptive bitrate packaging, use a [VOD Resource](/products/performance-cdn/static-content-delivery/create-vod-resource).
{% endhint %}

{% hint style="warning" %}
Large CDN Resources do **not** support the following file extensions.\
Requests for these file types return **HTTP** **403 Forbidden** responses.

`ashx, aspx, bmp, css, cur, eot, gif, htm, html, ico, jpeg, jpg, jpr, js, otf, pdf, php, png, psb, psd, svg, swf, swz, tif, tiff, ttf, txt, webp, woff, xml`
{% endhint %}

## Create a Large CDN Resource

Create and manage **Large CDN Resources** from the [**Medianova Control Panel**](https://cloud.medianova.com).

Navigate to **CDN** and select **Create CDN Resource** to launch the **Create CDN** wizard.

{% stepper %}
{% step %}

### Select the Resource Type

Navigate to **CDN** and click **Create CDN Resource**.

The **Create CDN** wizard opens.

<figure><img src="/files/Xmihid45FOOVNI3Knoys" alt=""><figcaption></figcaption></figure>

Select **Large CDN**, then click **Create** to continue.
{% endstep %}

{% step %}

### Select the Delivery Mode and Enter the Resource Name

Choose the delivery mode that matches your workload.

#### **Static Large Files**

Use **Static Large Files** for software packages, archives, downloads, audio files, video files, and other large objects that do not require transcoding.

#### **Live Streaming**

Use **Live Streaming** for RTMP ingest or for packaged live streams retrieved from an existing origin.

#### **Resource Name**

Enter a unique resource name.

The resource name becomes part of the default CDN hostname.

For example:

```
example.lg.mncdn.com
```

#### **Internal Label**

Optionally assign a private label to help your team identify and manage the resource.

Internal labels are used only within the Control Panel and for API filtering. They do not affect the public CDN hostname.

Click **Next**.
{% endstep %}

{% step %}

### Configure Your Source

Select where Medianova should retrieve or receive the content.

The available source options depend on the delivery mode selected in the previous step.

**Static Large Files**

Choose one of the following source types.

**Customer Origin**

Select **Customer Origin** to retrieve content from your own web server, application server, storage endpoint, or load balancer.

Click **Add Origin** to configure one or more origin servers.

The origin list displays:

<table><thead><tr><th width="175">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Host</strong></td><td>Hostname or IP address of the origin server.</td></tr><tr><td><strong>Protocol</strong></td><td>HTTP or HTTPS used for CDN-to-origin connections.</td></tr><tr><td><strong>Priority</strong></td><td>Determines the order in which configured origins are selected.</td></tr><tr><td><strong>Weight</strong></td><td>Distributes requests between origins with the same priority.</td></tr></tbody></table>

Multiple origins can be configured with priority and weight settings for availability and traffic distribution.

**Stook Object Storage**

Select **Stook Object Storage** to retrieve content from an existing Stook Bucket.

Configure the following fields:

<table><thead><tr><th width="172.333251953125">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Storage Bucket</strong></td><td>Select the Stook Bucket containing the files to be delivered.</td></tr><tr><td><strong>Subfolder</strong></td><td>Optionally restrict the source to a specific path within the selected bucket.</td></tr></tbody></table>

**Live Streaming**

Choose one of the following source types.

**Customer Origin**

Select **Customer Origin** to retrieve packaged live streaming content from your own origin server.

This option is suitable for existing HLS or DASH streaming origins.

Click **Add Origin** to configure one or more origin servers.

**RTMP Push**

Select **RTMP Push** to publish live streams directly to Medianova through RTMP ingest.

Configure the following credentials:

<table><thead><tr><th width="127">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Username</strong></td><td>Username used by the streaming encoder to authenticate the RTMP publishing connection.</td></tr><tr><td><strong>Password</strong></td><td>Password used by the streaming encoder to authenticate the RTMP publishing connection.</td></tr></tbody></table>

Configure these credentials in your streaming encoder, such as OBS Studio, Wirecast, or FFmpeg.

After creating the resource, use [Stream Management](/products/performance-cdn/static-content-delivery/stream-management) to configure SMIL streams and quality profiles.

Click **Next**.
{% endstep %}

{% step %}

### Configure SSL/TLS

Choose how HTTPS should be configured for the Large CDN Resource.

Available options are:

* **Use Existing SSL**
* **Add Own SSL**
* **Free SSL**
* **Skip for Now**

**Use Existing SSL**

Assign an SSL certificate that already exists in your account.

Only certificates available in the current account are listed. To create a certificate during this workflow, select **Add Own SSL** or **Free SSL**.

**Add Own SSL**

Upload or paste your own certificate and private key.

Configure the following fields:

* **SSL Certificate Name**
* **Certificate Format**
* **Domain**

Supported certificate input methods include:

* Domain SSL
* Paste `.crt` / `.key`
* `.pfx` / PKCS#12
* Upload Files

For certificate upload and domain configuration details, see [**CNAME & SSL**](/products/performance-cdn/static-content-delivery/advanced-configuration/cname-and-ssl).

**Free SSL**

Request a free Let’s Encrypt certificate through DNS validation.

Configure the following fields:

* **SSL Certificate Name**
* **Domain**
* **Coverage**
  * Single Domain
  * Wildcard

Wildcard certificates require CNAME-based domain validation.

For the complete provisioning and validation process, see [**Use Free SSL Certificates**](/products/security/ssl-tls-encryption/use-free-ssl-certificates).

**Skip for Now**

Continue without assigning a dedicated certificate.

Medianova serves the default CDN hostname over HTTPS using its shared SSL certificate. A dedicated certificate can be assigned later from **Settings →** [**SSL & TLS**](/products/security/ssl-tls-encryption) when configuring a custom domain.

Click **Next**.
{% endstep %}

{% step %}

### Review & Activate

Review the configuration before creating the resource.

The summary includes:

* Resource information
* Origin configuration
* SSL/TLS configuration
* CDN endpoint information

When the configuration is valid, click **Create Resource**.

{% hint style="success" %}
New CDN resources are typically provisioned within **30 seconds**.
{% endhint %}
{% endstep %}
{% endstepper %}

## Validate CDN Delivery

After creating the resource, send a request to an existing object through the CDN hostname:

```
curl -svo /dev/null "https://example.lg.mncdn.com/path/to/file.zip" --compressed
```

Replace `example.lg.mncdn.com` with the Large CDN Resource hostname and `/path/to/file.zip` with a valid object path.

For live streaming resources, validate an existing HLS or DASH manifest URL after the stream is available.

```c
curl -svo /dev/null "https://example.lg.mncdn.com/path/to/manifest.m3u8" --compressed
```

The command sends an HTTP `GET` request to the CDN, displays connection details and HTTP request and response headers, and discards the response body.

Use a path that returns **HTTP 200 OK**. If a custom CNAME is configured, test the custom hostname instead of the default MNCDN hostname.

## Troubleshooting

If the resource does not serve content correctly:

* Verify that the origin server is reachable.
* Confirm that the configured origin port is accessible.
* Ensure that the requested object exists in the configured origin path or Stook subfolder.
* Confirm that the selected Stook Bucket is accessible from the current account.
* Verify the RTMP username and password configured in the streaming encoder.
* Confirm that custom CNAME records have propagated before testing the custom hostname.
* Verify that the assigned SSL certificate is active and covers the requested domain.


# Create VOD Resource

Learn how to create a VOD Resource for on-demand video delivery and optional adaptive bitrate packaging.

A VOD Resource is designed for delivering on-demand video content through Medianova's edge network. Content can be retrieved from your own origin infrastructure or from Stook Object Storage.

{% hint style="info" %}
When **Medianova VOD Packaging** is enabled, compatible source video files are automatically transcoded into adaptive bitrate HLS and DASH renditions after upload.
{% endhint %}

## When to Use a VOD Resource

Use a VOD Resource for:

* On-demand video libraries
* Prerecorded video content
* Adaptive HLS or DASH delivery
* Video files that require automatic packaging
* Video content stored on your origin server or in [Stook Object Storage](/products/object-storage-stook/stook-cloud-object-storage)

{% hint style="info" %}
Medianova VOD Packaging is available only when [**Stook Object Storage**](/products/object-storage-stook/stook-cloud-object-storage) is selected as the content source.
{% endhint %}

{% hint style="info" %}
For large files that do not require video packaging, use a **Large CDN Resource**. For live RTMP ingest, create a [**Large CDN Resource**](/products/performance-cdn/static-content-delivery/create-large-cdn-resource) and select **Live Streaming**.
{% endhint %}

## Important Notes

* VOD Resources are intended for prerecorded video content, not live RTMP ingest.
* Medianova VOD Packaging is available when **Stook Object Storage** is selected as the source.
* Enabling VOD Packaging transcodes compatible source files into adaptive bitrate HLS and DASH renditions.
* The source bucket must exist before you create a VOD Resource from [Stook Object Storage](/products/object-storage-stook).

## Create a VOD Resource

Create and manage **VOD Resources** from the [**Medianova Control Panel**](https://cloud.medianova.com).

Navigate to **CDN** and select **Create CDN Resource** to launch the **Create CDN** wizard.

{% stepper %}
{% step %}

### Select the Resource Type

Navigate to **CDN** and click **Create CDN Resource**.

The **Create CDN** wizard opens.

<figure><img src="/files/Xmihid45FOOVNI3Knoys" alt=""><figcaption></figcaption></figure>

Select **VOD**, then click **Create** to continue.
{% endstep %}

{% step %}

### Enter the Resource Name

Provide the information used to identify the VOD Resource.

**Resource Name**

Enter a unique resource name.

The resource name becomes part of the default CDN hostname.

For example:

```
example.mncdn.com
```

**Internal Label**

Optionally enter a private label to help your team search for and identify the resource.

The internal label is used only in the Control Panel and for API filtering. It does not affect the public CDN hostname.

Click **Next**.
{% endstep %}

{% step %}

### Configure the Source

Select where Medianova should retrieve the video content from.

**Customer Origin**

Select **Customer Origin** to retrieve content from your own server, load balancer, or storage endpoint.

Click **Add Origin** and configure at least one origin server.

The origin list displays the following information:

<table><thead><tr><th width="183">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Host</strong></td><td>Hostname or IP address of the origin server.</td></tr><tr><td><strong>Protocol</strong></td><td>Protocol used for CDN-to-origin connections.</td></tr><tr><td><strong>Priority</strong></td><td>Determines the order in which configured origins are selected.</td></tr><tr><td><strong>Weight</strong></td><td>Distributes requests between origins with the same priority.</td></tr></tbody></table>

Multiple origins can be configured to provide automatic failover.

**Stook Object Storage**

Select **Stook Object Storage** to retrieve content from an existing Stook Bucket.

Configure the following fields:

<table><thead><tr><th width="156.333251953125">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Storage Bucket</strong></td><td>Select the Stook Bucket containing the source video files.</td></tr><tr><td><strong>Subfolder</strong></td><td>Optionally restrict the source to a specific path within the selected bucket.</td></tr></tbody></table>

<figure><img src="/files/t7yDzFRxGvFOQr4bw3fD" alt="" width="563"><figcaption></figcaption></figure>

**Medianova VOD Packaging**

Enable **Medianova VOD Packaging** to automatically transcode source files into adaptive bitrate HLS and DASH renditions after upload.

Leave this setting disabled when the source files are already prepared for the required delivery format or do not require Medianova-managed packaging.

Click **Next**.
{% endstep %}

{% step %}

### Configure SSL/TLS

Choose how HTTPS should be configured for the VOD Resource.

Available options are:

* **Use Existing SSL**
* **Add Own SSL**
* **Free SSL**
* **Skip for Now**

**Use Existing SSL**

Assign an SSL certificate that already exists in your account.

1. Select **Use Existing SSL**.
2. Select a certificate from the list.
3. Continue to the next step.

Only certificates available in the current account are listed. To create a certificate during this workflow, select **Add Own SSL** or **Free SSL**.

**Add Own SSL**

Upload or paste your own certificate and private key.

Configure the following fields:

* **SSL Certificate Name**
* **Certificate Format**
* **Domain**

Supported certificate input methods include:

* Domain SSL
* Paste `.crt` and `.key`
* Upload Files
* `.pfx` / PKCS#12

For certificate upload and domain configuration details, see [**CNAME & SSL**](/products/performance-cdn/static-content-delivery/advanced-configuration/cname-and-ssl).

**Free SSL**

Request a free Let’s Encrypt certificate through DNS validation.

Configure the following fields:

* **SSL Certificate Name**
* **Domain**
* **Coverage**

Available coverage options are:

* **Single Domain**
* **Wildcard**

Wildcard certificates require CNAME-based domain validation.

For the complete provisioning and validation process, see [**Use Free SSL Certificates**](/products/security/ssl-tls-encryption/use-free-ssl-certificates).

**Skip for Now**

Continue without assigning a dedicated certificate.

Medianova serves the default CDN hostname over HTTPS by using its shared SSL certificate. A dedicated certificate can be assigned later from **Settings →** [**SSL & TLS**](/products/security/ssl-tls-encryption) when configuring a custom domain.

Click **Next**.
{% endstep %}

{% step %}

### Review & Activate

Review the configuration before creating the resource.

The summary includes:

* Resource information
* Source configuration
* SSL/TLS configuration
* CDN endpoint information

When the configuration is valid, click **Create Resource**.

New VOD Resources are typically provisioned within **30 seconds**.

{% hint style="info" %}
New CDN Resources are typically provisioned within 30 seconds.
{% endhint %}
{% endstep %}
{% endstepper %}

## Validate VOD Delivery

Verify CDN connectivity using:

```
curl -svo /dev/null "https://example.mncdn.com/path/to/video.mp4" --compressed
```

Replace:

* `example.mncdn.com` with your VOD Resource hostname.
* `/path/to/video.mp4` with a valid video file.

This command:

* Sends an HTTP GET request to the CDN.
* Displays the request and response headers.
* Shows the remote edge IP address.
* Discards the response body.

Use a URL that returns **HTTP 200 OK**. If a custom CNAME is configured, validate using the custom hostname.

## Troubleshooting

If the resource does not serve content correctly:

* Verify that the origin server is reachable.
* Confirm that the configured origin ports are accessible.
* Ensure that the requested video exists in the configured origin path or Stook Bucket.
* Allow VOD Packaging to complete before requesting generated HLS or DASH outputs.
* Verify that DNS changes have propagated before testing a custom domain.
* Confirm that the assigned SSL certificate is active and matches the requested hostname.


# Integrating Static CDN Resource

Learn how to integrate your Medianova Small or Large CDN Resource with your website to deliver static assets or large media files through the CDN.

After creating a **Small CDN Resource** or **Large CDN Resource**, you must configure your website or application to deliver static assets through the CDN instead of directly from your origin server.

This guide explains how to update asset references, verify content delivery, and configure your origin environment for successful CDN integration.

{% hint style="info" %}
Before integrating your CDN resource, ensure that it has been created successfully and is in an active state.
{% endhint %}

## Prerequisites

Before you begin, ensure that you have:

* A configured **Small CDN Resource** or **Large CDN Resource**
* Access to your website, application, or CMS configuration
* Permission to modify your origin server configuration
* Permission to update firewall rules if required

## Integrate Your CDN Resource

{% stepper %}
{% step %}

### Identify Cacheable Assets

Determine which resources should be delivered through the CDN.

Typical static assets include:

* Images
* CSS
* JavaScript
* Fonts
* Documents
* Downloadable files
* Video files (Large CDN Resource)
  {% endstep %}

{% step %}

### Update Asset URLs

Replace origin URLs with your CDN hostname.

Example:

**Before**

```
<img src="https://example.com/images/logo.png">
```

**After**

```
<img src="https://cdn.example.com/images/logo.png">
```

Apply the same principle to CSS, JavaScript, fonts, and other static assets.
{% endstep %}

{% step %}

### Update Your Application or CMS

If your website uses a CMS or web framework, configure it to serve static assets from the CDN.

Depending on your platform, this may involve:

* Updating the application's asset URL
* Configuring a CDN plugin
* Changing the static asset host
* Updating environment variables
  {% endstep %}

{% step %}

### Allow CDN Access to Your Origin

If your origin server is protected by a firewall, allow requests from Medianova edge servers.

See [**Medianova IP Blocks**](/products/performance-cdn/static-content-delivery/configuration-basics/medianova-ip-blocks).

{% hint style="info" %}
Blocking CDN edge servers prevents cache misses from reaching your origin.
{% endhint %}
{% endstep %}

{% step %}

### Verify Content Delivery

Open your website and confirm that assets are delivered through the CDN hostname.

Browser Developer Tools can be used to verify:

* Request URL
* Response headers
* HTTP status codes
* Cache headers
  {% endstep %}

{% step %}

### Validate Cache Behavior

Confirm that:

* Static assets are cacheable.
* Responses include the expected cache headers.
* Requests are served from the CDN after the initial origin fetch.
  {% endstep %}

{% step %}

### Test Your Website

Verify that:

* Images load correctly.
* CSS is applied.
* JavaScript functions normally.
* Fonts are accessible.
* Downloadable files remain available.

Perform testing in both staging and production environments whenever possible.
{% endstep %}
{% endstepper %}

## Troubleshooting

If assets are not served through the CDN, verify the following:

* Asset URLs reference the CDN hostname.
* DNS configuration is correct.
* Firewall rules allow CDN edge servers.
* Cache policies permit the content to be cached.
* The origin server responds successfully.

### Related Concepts

* [Create Small CDN Resource](/products/performance-cdn/static-content-delivery/create-small-cdn-resource)
* [Create Large CDN Resource](/products/performance-cdn/static-content-delivery/create-large-cdn-resource)
* [Caching Fundamentals](/api-documentation/performance-cdn/caching)
* [Medianova IP Blocks](/products/performance-cdn/static-content-delivery/configuration-basics/medianova-ip-blocks)
* [Troubleshooting Common Setup Issues](/support-and-troubleshooting/common-issues-and-solutions/troubleshooting-common-setup-issues)


# Configuration Basics

Learn the basic concepts for integrating a CDN Resource with your website or application.

After [creating a CDN Resource](/products/performance-cdn/static-content-delivery/create-small-cdn-resource) in the [Medianova Control Panel](https://cloud.medinova.com), update your application to deliver content through the CDN instead of your origin server. This page introduces the basic concepts required to configure content delivery and verify that requests are routed through the Medianova CDN.

### Understand the resource lifecycle

A newly created CDN Resource progresses through several operational states before it begins serving traffic.

<table><thead><tr><th width="143.3333740234375">Status</th><th>Description</th></tr></thead><tbody><tr><td><strong>Pending</strong></td><td>The resource is being provisioned and is not yet ready to serve traffic.</td></tr><tr><td><strong>Active</strong></td><td>The resource is fully deployed and available to serve requests through the CDN.</td></tr><tr><td><strong>Passive</strong></td><td>The resource is disabled or unavailable and cannot serve traffic.</td></tr></tbody></table>

{% hint style="info" %}
Resource provisioning time depends on the selected product and configuration.
{% endhint %}

### Identify your origin and CDN hostnames

A CDN Resource is identified by two different hostnames.

<table><thead><tr><th width="151.6666259765625">Hostname</th><th width="231.3333740234375">Example</th><th>Purpose</th></tr></thead><tbody><tr><td><strong>Origin URL</strong></td><td><code>https://www.example.com</code></td><td>The source server that stores your content.</td></tr><tr><td><strong>CDN Hostname</strong></td><td><code>yourresource.mncdn.com</code></td><td>The hostname that delivers content through the Medianova CDN.</td></tr></tbody></table>

### Update your application

Replace references to your origin hostname with the CDN hostname for assets that should be delivered through the CDN.

#### Before

```
<img src="https://www.example.com/images/logo.png" alt="Logo">
```

or

```
<img src="/images/logo.png" alt="Logo">
```

#### After

```
<img src="https://yourresource.mncdn.com/images/logo.png" alt="Logo">
```

After updating these references, requests for the selected assets are served through the CDN instead of directly from the origin.

### Allow CDN access to your origin

If your origin server is protected by a firewall or IP allowlist, permit requests from the Medianova CDN.

Use the published list of Medianova edge IP addresses when configuring your firewall.

**Related documentation**

* [Medianova IP Blocks](/products/performance-cdn/static-content-delivery/configuration-basics/medianova-ip-blocks)

### Related guides

Continue with the guide that matches your CDN Resource type:

* [Create Small CDN Resource](/products/performance-cdn/static-content-delivery/create-small-cdn-resource)
* [Create Large CDN Resource](/products/performance-cdn/static-content-delivery/create-large-cdn-resource)
* [Create VOD Resource](/products/performance-cdn/static-content-delivery/create-vod-resource)
* [Create Dynamic CDN Resource](/products/performance-cdn/dynamic-content-acceleration/create-dynamic-resource)
* [Integrate a Dynamic CDN Resource](/products/performance-cdn/dynamic-content-acceleration/integrating-dynamic-cdn-resource)


# Medianova IP Blocks

Obtain Medianova’s CDN IP address ranges for firewall allowlisting.

Medianova’s CDN uses specific IP address ranges to fetch content from your origin servers.\
If your origin server uses a firewall or IP-based access controls, you **must allow all addresses listed below** to ensure reliable access from Medianova edge servers.\
This allows the CDN to retrieve and deliver your content securely and efficiently.

#### Available Formats

<table><thead><tr><th width="109.00006103515625">Format</th><th width="221" align="center">URL</th><th>Description</th></tr></thead><tbody><tr><td><strong>JSON</strong></td><td align="center"><a href="https://cloud.medianova.com/api/v1/ip/blocks-list">Medianova CDN IP ranges (JSON)</a></td><td>Structured format with separate IPv4 and IPv6 lists. Useful for automation and API integrations.</td></tr><tr><td><strong>Plain Text</strong></td><td align="center"><a href="https://cloud.medianova.com/api/v1/ip/addresses-txt">Medianova CDN IP ranges (Text)</a></td><td>Simple text file where each IP block is listed on a separate line. Suitable for manual import or quick reference.</td></tr><tr><td><strong>CSV</strong></td><td align="center"><a href="https://cloud.medianova.com/api/v1/ip/block-list-csv">Medianova CDN IP ranges (CSV)</a></td><td>Comma-separated values file suitable for importing IP blocks into spreadsheets or scripts.</td></tr></tbody></table>

{% hint style="warning" %}
Only allow traffic from Medianova’s IP ranges to reach your origin server (block all other sources). This practice secures your origin by preventing direct attacks and bypass attempts. Also ensure you include every address (both IPv4 and IPv6) in the allowlist. If any Medianova IP is omitted or blocked, the CDN cannot retrieve content from your origin.
{% endhint %}


# Advanced Configuration

Configure origin behavior, caching, headers, and delivery controls for Static CDN Resources.

Fine-tune how your Static CDN Resource connects to the origin and delivers content. Select a configuration area to continue.

<table data-view="cards"><thead><tr><th>Configuration area</th><th data-card-target data-type="content-ref">Learn more</th></tr></thead><tbody><tr><td><strong>Origin Settings</strong><br>Control origin routing, timeouts, redirects, TLS, and compression.</td><td><a href="/pages/BntvinH0iGaTCTRQVMuA">/pages/BntvinH0iGaTCTRQVMuA</a></td></tr><tr><td><strong>CNAME &#x26; SSL</strong><br>Map a custom domain and configure secure HTTPS delivery.</td><td><a href="/pages/WvJfYBrge8zrWsjnwqpQ">/pages/WvJfYBrge8zrWsjnwqpQ</a></td></tr><tr><td><strong>Caching</strong><br>Define cache lifetime, cache keys, and stale-content behavior.</td><td><a href="/pages/Fg9SMt1H1mZWoZVSX2Zc">/pages/Fg9SMt1H1mZWoZVSX2Zc</a></td></tr><tr><td><strong>Headers</strong><br>Manage request and response headers, CORS, HSTS, and browser protections.</td><td><a href="/pages/ePXvhL7SFUjkpewTAob8">/pages/ePXvhL7SFUjkpewTAob8</a></td></tr><tr><td><strong>Purge</strong><br>Invalidate cached content when the origin has updated.</td><td><a href="/pages/2ZMZYHowZDPIJBBAqRy6">/pages/2ZMZYHowZDPIJBBAqRy6</a></td></tr><tr><td><strong>Prefetch</strong><br>Warm edge caches before visitors request content.</td><td><a href="/pages/YGoTzXDhhYS20UPr6wb0">/pages/YGoTzXDhhYS20UPr6wb0</a></td></tr><tr><td><strong>Page Rules</strong><br>Apply targeted caching, redirect, and optimization behavior by URL.</td><td><a href="/pages/BItxBMwGx2d4Ul35pAgO">/pages/BItxBMwGx2d4Ul35pAgO</a></td></tr><tr><td><strong>Custom Error Page</strong><br>Redirect visitors when edge-generated errors occur.</td><td><a href="/pages/VlRkGd8k5U4k74Moqsum">/pages/VlRkGd8k5U4k74Moqsum</a></td></tr><tr><td><strong>Compression</strong><br>Enable Gzip or Brotli to reduce response sizes.</td><td><a href="/pages/RyBcF7IKBwTfJn0m7CAk">/pages/RyBcF7IKBwTfJn0m7CAk</a></td></tr><tr><td><strong>HTTP/2</strong><br>Enable HTTP/2 to improve connection efficiency for supported clients.</td><td><a href="/pages/01W7Yuw91F13Ax5sJuxJ">/pages/01W7Yuw91F13Ax5sJuxJ</a></td></tr></tbody></table>


# Origin Settings


# Advanced Origin Settings

Define advanced origin routing rules by matching requests to specific origins based on URI patterns, protocols, domains, ports, and priority.

Advanced Origin Settings allow you to configure granular origin-routing behavior for specific URIs, file types, or directories. By defining rule-based conditions, you can route selected traffic to different origins, override ports, set custom host headers, or assign priorities for complex routing environments.

You can manage Advanced Origin Settings in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/origin-settings).

Log in to the Medianova Control Panel, select a CDN resource in the CDN section, and navigate to the **Origin Settings** tab.

Advanced Origin Settings use rule-based logic. Each rule defines **what request pattern to match** and **how the CDN should route that traffic**.

## Add an Origin Rule

This workflow creates a new rule for routing selected requests to a specific origin configuration.

{% stepper %}
{% step %}
**Open the Add Rule Dialog**

Select **Add** in the Advanced Origin Settings section to create a new routing rule.
{% endstep %}

{% step %}
**Select the URI Match Mode**

Choose whether the rule should match an **Exact Path**, **Prefix**, **File Extension**, or **Regex** pattern.
{% endstep %}

{% step %}
**Define the URI Match Rule**

Enter the URI, directory, extension, or expression that determines which requests will use this origin rule.
{% endstep %}

{% step %}
**Select the Protocol**

Choose whether the CDN forwards requests using **HTTP**, **HTTPS**, or **Same as Request**.
{% endstep %}

{% step %}
**Enter the Domain or IP**

Specify the origin host that the CDN should forward matched traffic to.
{% endstep %}

{% step %}
**Configure HTTP and HTTPS Ports**

Enter the port numbers the CDN should use when communicating with the origin.
{% endstep %}

{% step %}
**Set the Host Header**

Define a custom **Host** header if the origin requires a different hostname than the request URL.
{% endstep %}

{% step %}
**Assign Priority**

Choose a priority value to control which rule applies if multiple rules match the same request.
{% endstep %}

{% step %}
**Save the Rule**

Select **Add** to save the rule to the rule list.
{% endstep %}

{% step %}
**Submit the Configuration**

Click **Submit** to apply all rule changes to the CDN resource.
{% endstep %}
{% endstepper %}

## Edit an Origin Rule

{% stepper %}
{% step %}
**Select the Rule To Edit**

Choose an existing rule from the list in the Advanced Origin Settings section.
{% endstep %}

{% step %}
**Modify the Required Fields**

Update match conditions, origin host, ports, or priority values.
{% endstep %}

{% step %}
**Save the Updated Rule**

Click **Submit** to apply the updated configuration.
{% endstep %}
{% endstepper %}

## Delete an Origin Rule

{% stepper %}
{% step %}
**Remove the Rule**

Select the delete icon next to the rule you want to remove.
{% endstep %}

{% step %}
**Confirm Deletion**

Submit the change to finalize the removal.
{% endstep %}
{% endstepper %}

## Behaviour

Advanced Origin Settings follow a priority-based evaluation model:

* **Highest priority wins.** Lower numeric values represent higher priority.
* If multiple rules match the incoming request, the CDN applies the rule with the highest priority.
* If no rules match, the CDN uses the default origin configuration.

Routing decisions consider:

* URI match pattern
* Origin protocol selection
* Domain/IP
* Ports
* Host header

This allows precise routing for APIs, media directories, file extensions, or multi-origin deployments.

## FAQ

**What happens if multiple rules match the same request?**

The rule with the **highest priority** (lowest priority number) is applied.

**Do regex or prefix rules impact performance?**

Regex rules are more expensive than prefix or extension matches. Use them only when necessary.

**What if no Advanced Origin rule matches the request?**

The request is sent to the **default origin** defined in the main Origin Settings section.

***

## Streaming Content Caching

For **Streaming Content Caching** resources, Advanced Origin Settings use a different structure based on **Origin Groups** and **URI Match Rules**.

Instead of defining individual origin rules directly, you first create origin groups containing one or more origins, then create URI match rules that route traffic to those groups.

<figure><img src="/files/BbKC2cAjMjCQ1Dy05dwB" alt=""><figcaption><p>Advanced Origin Settings for Streaming Content Caching – Origin Groups and URI Match Rules sections</p></figcaption></figure>

The page has two sections:

* **Origin Groups** – Define groups of origins for load balancing and failover.
* **URI Match Rules** – Assign URI patterns to origin groups to route traffic.

{% hint style="info" %}
You must create at least one origin group before you can add URI match rules.
{% endhint %}

### Create an Origin Group

You can create up to **50 origin groups**, and each group can contain up to **25 origins**.

{% stepper %}
{% step %}
**Open the Add Origin Group Dialog**

Click **Add group** in the **Origin Groups** section.

<figure><img src="/files/bGYz2PGRCazH9vQ4sGy6" alt="" width="563"><figcaption><p>Add Origin Group Settings dialog</p></figcaption></figure>
{% endstep %}

{% step %}
**Configure the Origin Group**

Fill in the following fields:

* **Group Name** – Enter a descriptive name for the group.
* **Protocol** – Choose **HTTP**, **HTTPS**, or **Same as Request**.
* **Domain or IP** – Specify the origin server address.
* **HTTP Port / HTTPS Port** – Enter the port numbers for origin communication.
* **Host Header** – *(Optional)* Define a custom Host header if the origin requires it.
* **Weight** – Set a weight value for traffic distribution within the group.
* **Priority** – Choose **Primary** or **Backup** to define failover behavior.

Click **Add** to add the origin to the group.
{% endstep %}

{% step %}
**Submit Origin Groups**

After adding all origins, click **Submit groups** to save the configuration.

<figure><img src="/files/OFf8eU8cJEl582ZVj8SU" alt=""><figcaption><p>Origin group with added origins – click Submit groups to save</p></figcaption></figure>

You can add more origins to the same group or create additional groups by clicking **Add group** again.
{% endstep %}
{% endstepper %}

### Add a URI Match Rule

After creating origin groups, define URI match rules to route traffic to the appropriate group.

{% stepper %}
{% step %}
**Open the Add Rule Dialog**

Click **Add rule** in the **URI Match Rules** section.

<figure><img src="/files/foY7xXR5einE1D9AVHlj" alt="" width="563"><figcaption><p>Add Rule dialog – select match mode, enter rule, and assign an origin group</p></figcaption></figure>
{% endstep %}

{% step %}
**Configure the Rule**

Fill in the following fields:

* **URI Match Mode** – Choose **File Extension**, **Exact Path**, **Prefix**, or **Regex**.
* **URI Match Rule** – Enter the pattern to match (for example, `.m3h8` for HLS manifest files).
* **Origin Group** – Select the origin group that should handle matched requests.

Click **Add** to create the rule.
{% endstep %}

{% step %}
**Submit URI Match Rules**

You can reorder rules by dragging the handle icon (**≡**) on the left side of each rule — the rule at the top has the highest priority.

Click **Submit rules** to apply the URI match rules to the CDN resource.

<figure><img src="/files/sDn0n1KCBB1Qhsy6CjtD" alt=""><figcaption><p>URI match rules list – drag the ≡ handle to reorder priority, then click Submit rules to apply</p></figcaption></figure>
{% endstep %}
{% endstepper %}


# Rewrite Origin URLs

Learn how to manage Rewrite Origin URLs to modify how request paths are sent to your origin.

**Rewrite Origin URLs** enables you to transform incoming paths before they are forwarded to origin servers. You can configure **Match Mode**, **Origin URI**, **Target URI**, and **Priority** to adjust how paths are rewritten for directory changes, API restructuring, or backend routing needs.

You can manage Rewrite Origin URLs using the [Medianova Control Panel](https://cloud.medianova.com) or [API](https://clients.medianova.com/api-documentation/performance-cdn/origin-settings#put-api-v1-cdn-organization_uuid-resource-resource_uuid-2).

In the Medianova Control Panel, go to **CDN Resources**, select your resource, and navigate to **Origin Settings**

## Manage Rewrite Origin URLs

Follow the steps below to add and manage Rewrite Origin URLs for your CDN Resource.

<figure><img src="/files/bOaWS20IA1Gwywu8P7Pr" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Add a Rewrite Origin URL**

Select **Add** to create a new Rewrite Origin URL.

<figure><img src="/files/P1VRGQgcWrxtHv2u5ddS" alt="" width="563"><figcaption></figcaption></figure>

The Add Rewrite Origin URL popup appears.
{% endstep %}

{% step %}
**Configure Parameters**

Fill in the required fields in the popup:

* **Match Mode** — Choose how the incoming path is matched.\
  Options include:
  * `All files`
  * `Path`
  * `Full Path`
  * `Wildcard`
* **Origin URI** — Enter the incoming request path to match.
* **Target URI** — Enter the new path that requests will be rewritten to.
* **Priority** — Lower values are evaluated first when multiple Rewrite Origin URLs exist.
  {% endstep %}

{% step %}
**Save the Configuration**

Select **Add**, then click **Submit**.\
Your Rewrite Origin URL is added to the list.
{% endstep %}
{% endstepper %}

### **Match Mode Behavior**

* **All files**: Applies to every incoming request.
* **Path**: Matches only the path portion of the request URI.
* **Full Path**: Matches the exact full URL path.
* **Wildcard**: Enables dynamic pattern matching using wildcard symbols.

## **Troubleshooting**

**Issue:** Rewrite Origin URL does not apply.\
**Cause:** Incorrect Match Mode or Origin URI format.\
**Fix:** Verify that the incoming request path matches the defined parameters.

**Issue:** A different Rewrite Origin URL is applied first.\
**Cause:** Priority ordering conflict.\
**Fix:** Assign a lower priority value to the entry you want processed first.

**Issue:** Origin returns 404 after rewrite.\
**Cause:** Target URI does not exist on the origin.\
**Fix:** Confirm that the target path is valid and reachable at the origin server.


# Origin SNI Request

Learn how to configure Origin SNI Request to ensure secure SSL/TLS connections between the CDN and your origin server.

**Origin SNI Request** enables the CDN to send the correct **Server Name Indication (SNI)** value when establishing SSL/TLS connections with your origin. This ensures that the origin server selects the appropriate SSL certificate, especially when hosting multiple domains on the same IP address.

Enabling this feature improves compatibility and prevents certificate mismatch errors during HTTPS communication.

You can manage Origin SNI Request using the [Medianova Control Panel](https://cloud.medianova.com) or [API](https://clients.medianova.com/api-documentation/performance-cdn/origin-settings#put-api-v1-cdn-organization_uuid-resource-resource_uuid-3).

In the Medianova Control Panel, go to **CDN Resources**, select your resource, and navigate to **Origin Settings.**

## Configure Origin SNI Request

Follow the steps below to enable and configure Origin SNI Request for your CDN Resource.

{% stepper %}
{% step %}

### **Enable Origin SNI Request**

Toggle **Origin SNI Request** to **On**.

<figure><img src="/files/PZlnT4FRfIrITvKNw78c" alt="" width="563"><figcaption></figcaption></figure>

The domain input field becomes active.
{% endstep %}

{% step %}

### **Enter the SNI Domain**

Provide the **Origin SNI Request Domain**:

* Enter the domain name to use as the SNI value when establishing an SSL/TLS connection with the origin.
* Ensure this domain corresponds to a valid SSL certificate installed on the origin server.

{% hint style="info" %}
The **Origin SNI Request Domain** is applied only to origins that do not have an SNI value defined in their origin configuration. If an SNI value is already defined for an origin, that origin-specific value is used instead.
{% endhint %}
{% endstep %}

{% step %}

### **Save the Configuration**

Click **Submit** to apply your settings.\
Origin SNI Request is now enabled for the CDN Resource.
{% endstep %}
{% endstepper %}

## **How SNI Works**

During the SSL/TLS handshake with the origin, the CDN includes the configured server name in the **SNI extension**. The origin can use this value to select the appropriate TLS certificate and virtual host.\
This allows the origin server to:

* Select the correct SSL certificate
* Support multiple domains on a shared IP
* Avoid certificate mismatch errors

## **When to Enable Origin SNI Request**

Use this setting when:

* Your origin serves multiple HTTPS domains from the same IP
* The origin requires SNI to present the correct SSL certificate
* You encounter HTTPS 421 or certificate mismatch errors

## **Troubleshooting**

**Issue:** HTTPS requests fail with certificate mismatch.\
**Cause:** The origin returned the default certificate instead of the certificate for the requested domain.\
**Fix:** Enable Origin SNI Request and enter the correct domain.

**Issue:** Origin returns 421 Misdirected Request.\
**Cause:** The origin requires SNI to route the request to the correct virtual host.\
**Fix:** Ensure the SNI domain matches the vhost configuration on the origin.

**Issue:** Requests fail after enabling SNI.\
**Cause:** Incorrect domain entered in the Origin SNI Request Domain field.\
**Fix:** Confirm that the domain matches a valid certificate installed on the origin.


# Redirect Handle From Origin

Learn how to manage Redirect Handle From Origin to control how 3xx redirect responses from your origin are processed by the CDN.

**Redirect Handle From Origin** allows the CDN to modify request or response headers when the origin returns a **3xx redirect**.

You can select which redirect codes to handle and optionally add or modify headers sent during redirection.

This provides greater control over origin-driven redirects and ensures consistent client behavior.

You can manage Redirect Handle From Origin using the [Medianova Control Panel](https://cloud.medianova.com) or the [API](https://clients.medianova.com/api-documentation/performance-cdn/origin-settings#put-api-v1-cdn-organization_uuid-resource-resource_uuid-4).

In the Medianova Control Panel, go to **CDN Resources**, select your resource, and navigate to **Origin Settings**

## Redirect Handle From Origin

Follow the steps below to enable and configure redirect handling for your CDN Resource.

{% stepper %}
{% step %}
**Enable Redirect Handling**

Toggle **Status** to **On**.

<figure><img src="/files/y47I7GS6HAEHPvqG73h3" alt="" width="563"><figcaption></figcaption></figure>

Additional configuration options become active.
{% endstep %}

{% step %}
**Select Redirect Codes to Handle**

Open **Handle Origin Redirection Error** and choose one or more redirect status codes that the CDN should process.

These codes determine **which 3xx responses from your origin will trigger redirect handling logic**. When a selected code is returned by the origin, the CDN applies your configured header settings and processes the redirect instead of simply passing it through unchanged.

Supported redirect codes:

* **301** — Permanent redirect
* **302** — Temporary redirect
* **303** — See Other
* **307** — Temporary redirect (method is preserved)
* **308** — Permanent redirect (method is preserved)

The CDN will apply your redirect-handling configuration **only** to the selected status codes, giving you granular control over how different redirect types are processed.
{% endstep %}

{% step %}
**Configure Request Headers (Optional)**

Enter a **Request Header Key** and **Request Header Value** if you want to include or modify request headers when a redirect occurs.

Examples:

* `Request Header Key`: `User-Agent`
* `Request Header Value`: `Custom-UA`

If you do not need to change request headers, leave these fields empty.
{% endstep %}

{% step %}
**Add Custom Headers (Optional)**

Use **Add Header Key** and **Add Header Value** to specify additional headers that should be appended during redirect handling.

Examples:

* `Add Header Key`: `X-Debug-Redirect`
* `Add Header Value`: `true`

These headers are included in redirected requests or responses depending on your configuration.
{% endstep %}

{% step %}
**Save the Configuration**

Select **Add** to register your header definitions.\
Then click **Submit** to apply the Redirect Handle From Origin settings.\
Redirect handling is now active for your CDN Resource.
{% endstep %}
{% endstepper %}

### **Redirect Handling Logic**

When the origin returns a selected **3xx** status code:

1. CDN intercepts the response.
2. CDN adds or modifies headers based on your configuration.
3. The redirect is returned to the client with the updated headers.

### **Header Processing**

* **Request Header Key / Value** modifies the header sent from CDN → Origin.
* **Add Header Key / Value** appends additional headers in redirection processing.

### **Status Toggle**

* When **On**, CDN evaluates redirect codes and applies your header settings.
* When **Off**, CDN forwards redirect responses without modification.

## **Troubleshooting**

**Issue:** Redirect handling does not apply.\
**Cause:** Status toggle is disabled or no redirect codes are selected.\
**Fix:** Enable **Status** and choose at least one code under **Handle Origin Redirection Error**.

**Issue:** Headers are not appearing in redirected responses.\
**Cause:** Header Key or Value fields are empty.\
**Fix:** Ensure both fields are filled before selecting **Add**.

**Issue:** Redirect behavior is inconsistent.\
**Cause:** Origin and CDN redirect configurations conflict.\
**Fix:** Review origin redirect rules and ensure the CDN's configured headers do not override necessary behavior.


# Origin Response Timeout

Learn how to configure Origin Response Timeout to control how long the CDN waits for your origin to respond.

**Origin Response Timeout** defines the maximum time the CDN waits for an HTTP(S) response from your origin server. If the origin does not respond within the configured duration, the CDN returns a **504 Gateway Timeout**.

Adjusting this timeout helps maintain predictable performance and prevents long wait times caused by slow origin responses.

You can manage Origin Response Timeout using the [Medianova Control Panel](https://cloud.medianova.com) or [API](https://clients.medianova.com/api-documentation/performance-cdn/origin-settings#put-api-v1-cdn-organization_uuid-resource-resource_uuid-5).

In the Medianova Control Panel, go to **CDN Resources**, select your resource, and navigate to **Origin Settings.**

## Configure Origin Response Timeout

Follow the steps below to set the timeout duration.

{% stepper %}
{% step %}
**Set the Timeout Duration**

Enter a timeout value between **5 seconds** and **300 seconds**.

<figure><img src="/files/Lu8btEt2czDYmU6OnBN7" alt=""><figcaption></figcaption></figure>

The CDN will wait for the origin response up to the duration you specify.
{% endstep %}

{% step %}
**Save the Configuration**

Click **Submit** to apply the timeout value.\
The new timeout setting takes effect immediately.
{% endstep %}
{% endstepper %}

### **Timeout Behavior**

* The CDN waits for the origin to respond for the configured duration.
* If the timeout is reached, the CDN returns **504 Gateway Timeout** to the client.
* Lower values improve failover speed; higher values allow slow origins more time to respond.

### **Recommended Settings**

* **5–30 seconds**: Fast origins or latency-sensitive applications
* **30–120 seconds**: Moderate response times or variable workloads
* **120–300 seconds**: Heavy processing at the origin (reports, large queries, image generation)

## **Troubleshooting**

**Issue:** Clients receive 504 responses.\
**Cause:** Origin cannot respond within the configured timeout.\
**Fix:** Increase the timeout value or optimize origin performance.

**Issue:** Requests feel slow before failing.\
**Cause:** Timeout value is set too high.\
**Fix:** Reduce the timeout to a more suitable duration.


# Enable Gzip from Origin

Fetch gzip-compressed text-based content from your origin to improve delivery efficiency.

Enable Gzip From Origin allows the CDN to request text-based files from your origin using the `Accept-Encoding: gzip` header.

{% hint style="info" %}
This feature is available for Small, Large, and Dynamic CDN Resources.
{% endhint %}

If the origin supports gzip, the CDN stores the compressed version in cache; otherwise, it stores the uncompressed response.

{% hint style="info" %}
This feature does not control CDN → client compression.\
For client-side compression, see [How to Configure Gzip and Brotli](/products/performance-cdn/static-content-delivery/advanced-configuration/compression/how-to-configure-gzip-and-brotli).
{% endhint %}

Enable Gzip From Origin instructs the CDN to request text-based files from your origin using:

```
Accept-Encoding: gzip
```

When enabled:

• The CDN requests gzip-compressed content from the origin.\
• If the origin supports gzip, the CDN stores the compressed version in cache.\
• If the origin does not support gzip, the CDN stores the uncompressed response.

This improves performance and reduces bandwidth usage between the **Origin → CDN** path.

### How It Works

<figure><img src="/files/uAC7J1ES9bzEJ3fmH7WT" alt="" width="563"><figcaption><p>CDN requests gzip-compressed content from the origin when this feature is enabled.</p></figcaption></figure>

The CDN sends `Accept-Encoding: gzip` to the origin.\
If the origin supports gzip, compressed content is returned and stored in the cache.\
If the origin does not support gzip, the CDN caches the uncompressed response.

{% hint style="info" %}
Applies only to text-based MIME types (`.js`, `.css`, `.html`, `.txt`, `.xml`, `.json`, …).\
Does not apply to images. Use [Image Optimization](/products/performance-cdn/image-optimization-and-webp) instead.
{% endhint %}

### Enable Gzip from Origin

You can enable this feature via the [Medianova Control Panel](https://cloud.medianova.com)

{% stepper %}
{% step %}
**Open CDN Resources in the left-hand menu.**

This section lists all CDN Resources available in your account.
{% endstep %}

{% step %}
**Select a CDN Resource.**

{% hint style="info" %}
This feature is available for Small, Large, and Dynamic CDN Resources.
{% endhint %}
{% endstep %}

{% step %}
**Go to Advanced Configuration → Origin Settings.**

The tab displays all origin-related configuration options.
{% endstep %}

{% step %}
**Enable Gzip from Origin and click Submit.**

<figure><img src="/files/XpTusRoVOhZFj5vyezrJ" alt=""><figcaption><p>Enable Gzip from Origin</p></figcaption></figure>

This action saves your configuration and activates gzip fetching for text files.
{% endstep %}
{% endstepper %}

Medianova CDN starts sending the `Accept-Encoding: gzip` header to your origin for eligible file types.

## **FAQ**

**Does this feature compress content for end-users?**\
No. It only optimizes the origin → CDN transfer.\
Client-side compression is handled separately by [Gzip Delivery and Brotli Delivery](/products/performance-cdn/static-content-delivery/advanced-configuration/compression/how-to-configure-gzip-and-brotli).

**What if my origin does not support gzip?**\
The CDN will fetch and cache the uncompressed version of the file.

**Does this apply to all file types?**\
No. The feature applies only to text-based MIME types.\
Images are not affected and require Image Optimization.


# CNAME & SSL

Learn how to add and configure a CNAME to map your custom domain and enable secure HTTPS delivery.

The **CNAME & SSL** tab allows you to associate custom domains with a CDN Resource, configure the SSL certificate used for HTTPS connections, define supported TLS versions, and verify that your DNS configuration correctly points to the assigned Medianova hostname.

Before configuring HTTPS, ensure that your custom domain is configured with the required CNAME record and that an appropriate SSL certificate is available in your organization.

{% hint style="info" %}
If you need to create a new SSL certificate, use the **SSL / TLS** page before configuring this resource. For certificate creation and management, see [**Upload and Manage SSL Certificates**](/products/security/ssl-tls-encryption/upload-and-manage-ssl-certificates).
{% endhint %}

## Add a Custom Domain (CNAME)

{% stepper %}
{% step %}

### Open the CDN Resource

Navigate to **CDN → CDN Resources**, then open the resource you want to configure.
{% endstep %}

{% step %}

### Open the CNAME & SSL Tab

<figure><img src="/files/oDlClitgVYuTt6sbbOwr" alt=""><figcaption></figcaption></figure>

Select the **CNAME & SSL** tab.
{% endstep %}

{% step %}

### Add a Custom Domain

Enter the hostname that users will use to access your content.

Example:

```
cdn.example.com
```

Click **Submit** to save the configuration.
{% endstep %}

{% step %}

### Configure DNS

Create a CNAME record with your DNS provider that points your custom domain to the hostname assigned to your CDN Resource.

Example:

```
cdn.example.com    CNAME    your-resource.mncdn.com
```

After DNS propagation completes, requests to your custom domain are routed through the associated CDN Resource.
{% endstep %}
{% endstepper %}

## Configure the SSL Certificate

{% stepper %}
{% step %}

### Select an SSL Certificate

Choose the SSL certificate that will secure HTTPS connections for this resource.

Available options may include:

* **Shared SSL**
* **SNI**
* **Custom SNI**
* **Disabled**

{% hint style="info" %}
Certificates created from the **SSL / TLS** page become available after they have been successfully issued.
{% endhint %}
{% endstep %}

{% step %}

### Save the Configuration

Click **Submit** to apply the selected certificate.

The selected certificate is used for HTTPS connections to every configured custom domain.
{% endstep %}
{% endstepper %}

## Configure Supported TLS Versions

Select the TLS versions that clients are allowed to use.

For most deployments, enable:

* TLS 1.2
* TLS 1.3

Click **Submit** to save your changes.

## CNAME Verification

After the required DNS mapping is configured, Medianova verifies that the configured domain correctly resolves to the assigned CDN Resource. For resource types that use custom domains, this verification is performed against the configured CNAME record.

Verification status is displayed throughout the Control Panel to help identify DNS configuration issues before production traffic is served.

### Verification Status

<table><thead><tr><th width="236.666748046875">Status</th><th>Description</th></tr></thead><tbody><tr><td><strong>CNAME verified</strong></td><td>All configured domains correctly point to the assigned CDN hostname.</td></tr><tr><td><strong>Some CNAMEs incorrect</strong></td><td>Some configured domains are correctly configured, while one or more domains are missing or point to an incorrect target.</td></tr><tr><td><strong>Not verified</strong></td><td>The required DNS mapping is missing or incorrect for the configured domain or domains.</td></tr></tbody></table>

When multiple domains are configured, Medianova verifies each domain independently. The displayed status reflects the overall DNS verification result.

### CDN Resources List

The **CDN URL / CNAME** column displays the current verification status for each resource.

Hover over the verification badge to view the DNS verification result for each configured custom domain.

<figure><img src="/files/dUjp0TE2va2ccuRP8iDR" alt="" width="563"><figcaption></figcaption></figure>

### Resource Overview

If one or more custom domains require attention, the **Overview** page displays an **Action needed** panel describing the affected domains.

The panel includes:

* Host
* Target
* Current DNS status
* Copy-to-clipboard actions
* **Check now**
* **Instructions**

After the required DNS record has been configured and successfully verified, the notification is automatically removed.

<figure><img src="/files/d8nha3DzCUiC37OoIae3" alt=""><figcaption></figcaption></figure>

### During Resource Creation

Depending on the selected **resource type** and **SSL configuration**, the Create CDN workflow displays the DNS configuration required before the resource is activated.

If displayed, the guidance includes the required host name and target hostname needed to configure the CNAME record.

<figure><img src="/files/6dYFWerQ3iRPFLouCa6L" alt=""><figcaption></figcaption></figure>

## Verify the Configuration

{% hint style="success" %}
Use **Check now** from the **Overview** page to trigger a new DNS verification immediately, or wait for the automatic background verification.
{% endhint %}

### Verify DNS Resolution

Run:

```bash
nslookup cdn.example.com
```

The hostname should resolve to the assigned Medianova hostname.

### Verify HTTPS

Run:

```bash
curl -Iv https://cdn.example.com
```

Verify that:

* the HTTPS connection succeeds;
* the expected SSL certificate is presented;
* the negotiated TLS version matches your configuration.

## Troubleshooting

### DNS changes are not visible

DNS propagation depends on your DNS provider and configured TTL values. It may take several minutes before updated records become visible globally.

#### CNAME verification failed

Verify that:

* the required DNS mapping points to the hostname assigned to the CDN Resource;
* the DNS change has propagated;
* the resource is enabled;
* the selected SSL configuration and resource type are correctly configured.

For resource types that use custom domains, verify that the CNAME record points to the assigned CDN hostname. For Dynamic Resources, verify that the configured Website URL resolves correctly to the assigned CDN Resource.

After correcting the DNS configuration, use **Check now** or wait for the next automatic verification.

### HTTPS certificate does not match the domain

Verify that the selected certificate covers every configured custom domain through its Common Name (CN) or Subject Alternative Names (SANs).

### Free SSL certificate is unavailable

If you recently requested a Free SSL certificate, DNS validation may still be in progress.

Complete DNS validation from the **SSL / TLS** page before selecting the certificate for this resource.

## Related Concepts

* [Upload and Manage SSL Certificates](/products/security/ssl-tls-encryption/upload-and-manage-ssl-certificates)
* [Use Free SSL Certificates](/products/security/ssl-tls-encryption/use-free-ssl-certificates)
* [SSL / TLS Encryption](/products/security/ssl-tls-encryption)


# Caching


# Edge Cache Expiration

Learn how to configure how long content remains cached on CDN edge servers.

Edge Cache Expiration controls whether CDN edge servers cache an object and how long the cached content remains valid before it must be refreshed from the origin.

It defines the caching behavior applied at the edge, including modes that disable caching entirely or defer expiration settings to the origin.

You can manage Edge Cache Expiration in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/caching#put-api-v1-cdn-organization_uuid-resource-resource_uuid).

## **Configure Edge Cache Expiration**

Use this workflow to define how the CDN determines cache duration and applies expiration rules on edge servers.

{% stepper %}
{% step %}
**Access the Edge Cache Expiration**

This feature is located under the **Caching** tab in any CDN Resource.\
This section includes the **Cache Type** selector and expiration time fields.
{% endstep %}

{% step %}
**Select the Cache Type**

Choose how the CDN evaluates cache duration:

**Edge** — The CDN applies the expiration time configured in the Panel. A value of `0` disables caching.\
**Origin** — The CDN honors cache headers sent by the origin. If no cache duration is provided, the Panel-defined value applies. A value of `0` disables caching.\
**Dynamic** — The CDN does not cache the content. All requests always forward to the origin regardless of origin headers or Panel settings.

<figure><img src="/files/CeHSLIwaqzzdM5cGkGlu" alt=""><figcaption><p>The Edge Cache Expiration section allows configuration of the Cache Type and duration settings.</p></figcaption></figure>
{% endstep %}

{% step %}
**Enter the expiration time**

Specify how long content should remain cached on edge servers.\
For Origin mode, this value is applied only when the origin provides no cache duration.
{% endstep %}

{% step %}
**Save the configuration**

Click **Submit** to apply the updated caching rules across the CDN network.
{% endstep %}
{% endstepper %}

* A value of `0` disables caching for both **Edge** and **Origin** modes.
* **Dynamic** mode always bypasses caching on edge servers.
* These settings do not impact browser caching; use [Browser Cache Rule](/products/performance-cdn/static-content-delivery/advanced-configuration/caching/browser-cache-rule) for client-side caching behavior.

## **Best Practices**

* Apply long TTL values for static assets such as images, fonts, CSS, and JavaScript.
* Use shorter TTL values for frequently updated or dynamic endpoints.
* Monitor edge cache hit ratios to optimize performance and origin load.


# Browser Cache Rule

Configure browser-side caching behavior for different resource types using Browser Cache Rules.

Browser Cache Rule allows you to control how long different resource types remain cached in the visitor’s browser.

This improves performance by reducing repeated network requests for static or frequently accessed files.

You can manage Browser Cache Rules in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/caching#put-api-v1-cdn-organization_uuid-resource-resource_uuid-1).

## **Configure Browser Cache Rules**

Log in to the Medianova Control Panel, select a CDN resource in the CDN section, and navigate to the Caching tab.

<figure><img src="/files/StgGrfU4VJ7GJN2lGHrA" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}

### **Add a Browser Cache Rule**

A dialog opens for creating a new Browser Cache Rule.

<figure><img src="/files/wQRUeFs4aGFyIybzHJbp" alt=""><figcaption><p>The 'Add Browser Cache Rule' dialog box appears after clicking Add.</p></figcaption></figure>
{% endstep %}

{% step %}

### **Select the Type for the rule.**

Choose how the rule matches content:

* **All Files** — Applies rule to all content.
* **Full Path** — Applies to an exact URL path.
* **Directory** — Applies to all content under a directory (for example: `/images/`).
* **File Extension** — Applies to file types (for example: `.jpg`, `.css`, `.js`).
  {% endstep %}

{% step %}

### **Set the Priority**

Set the **Priority** value.&#x20;

Rules with higher Priority values are evaluated before rules with lower Priority values.

{% hint style="info" %}
If a request matches multiple Browser Cache Rules, the first matching rule is applied.
{% endhint %}
{% endstep %}

{% step %}

### **Select the Cache Mode.**

* **Origin** — Uses caching headers from the origin.
* **No Cache** — Disables browser caching.
* **Cache** — Forces caching for a defined duration.
  {% endstep %}

{% step %}

### **Select Add**&#x20;

{% endstep %}

{% step %}

### **Configure HTML/JSON Application**

Enable or disable **Apply the HTML/JSON files** to define whether rules also apply to `.html` and `.json` responses.
{% endstep %}

{% step %}

### **Select Submit**&#x20;

{% endstep %}
{% endstepper %}

## Edit a Browser Cache Rule

{% stepper %}
{% step %}
Open the options menu for the rule and select **Edit**.
{% endstep %}

{% step %}
Modify **Type**, **Priority**, or **Cache Mode** as required.
{% endstep %}

{% step %}
Select **Submit** to save the changes.
{% endstep %}
{% endstepper %}

## Delete a Browser Cache Rule

{% stepper %}
{% step %}
Open the options menu for the rule and select **Delete**.
{% endstep %}

{% step %}
Confirm the deletion to remove the rule.
{% endstep %}

{% step %}
Select **Submit** to apply the update.
{% endstep %}
{% endstepper %}

* Rules with higher **Priority** values are evaluated first. If a request matches multiple rules, the first matching rule is applied.
* Browser Cache Rules control **browser-side caching only**, not CDN edge caching.
* The **Apply the HTML/JSON files** toggle affects all rules globally.
* When **Cache Mode = Origin**, browser caching behavior follows origin headers; **No Cache** forces revalidation; **Cache** overrides browser behavior with a fixed duration.

## Best Practices

* Use **file extension** rules to cache static assets like `.js`, `.css`, and `.png` for long durations.
* Use **no cache** mode for frequently updated resources (e.g., `.html`, `.json` APIs).
* Assign a higher **Priority** value to specific Full Path or Directory rules that must be evaluated before broader rules.


# Query String Caching

Control how query strings affect CDN cache behavior for dynamic or parameterized URLs.

Query String Caching defines how URLs containing query parameters are interpreted by the CDN cache. You can cache each query string variant separately, ignore selected query strings, or build the cache key using only specific parameters.

You can manage Query String Caching in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/caching#put-api-v1-cdn-organization_uuid-resource-resource_uuid-2).

Log in to the Medianova Control Panel, select a CDN resource in the CDN section, and navigate to the **Query String Caching** section under the **Caching** tab.

## Configure Query String Caching

This workflow defines the primary caching behavior for URLs containing query strings.

<figure><img src="/files/x9EfpZRtbpkOKyWMBC0h" alt="" width="560"><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Select the Query String Caching Mode**

Choose one of the following options under **Query String Caching**:

* **On** — Cache each query string variant separately.
* **Off** — Ignore all query strings; all variations map to a single cached object.
* **Request URI** — Cache based on the full request URI, including query parameters exactly as received. This option is typically used for edge cases where the exact request format must be preserved.
  {% endstep %}

{% step %}
**Submit the Configuration**

Click **Submit** to apply the selected caching mode.
{% endstep %}
{% endstepper %}

### Configure Ignore Specific Query Strings

Exclude selected query string parameters so they do not create separate cached variants.

{% stepper %}
{% step %}
**Enable Ignore Specific Query Strings**

Toggle **Ignore Specific Query Strings** to On.
{% endstep %}

{% step %}
**Enter Query Strings to Ignore**

Add one or more parameters that should not affect the cache key.
{% endstep %}

{% step %}
**Submit the Configuration**

Click **Submit** to save the changes.
{% endstep %}
{% endstepper %}

### **Cache Specific Query Strings Only**

Build the cache key using only selected parameters and ignore all others.

{% stepper %}
{% step %}
**Enable Cache Specific Query Strings Only**

Toggle **Cache Specific Query Strings Only** to On.
{% endstep %}

{% step %}
**Enter Query Strings to Cache**

Add parameters that should be included in the cache key.
{% endstep %}

{% step %}
**Submit the Configuration**

Click **Submit** to apply the rule.
{% endstep %}
{% endstepper %}

## **Behaviour**

* **On**: The CDN caches each unique query string as a separate variant.
* **Off**: Query strings are ignored; all variants map to a single cached object.
* **Request URI**: The full request URI is used as the cache key. This mode is generally intended for edge-case scenarios requiring exact URI preservation.
* **Ignore Specific Query Strings**: Excluded parameters do not contribute to the cache key.
* **Cache Specific Query Strings Only**: Only the selected parameters contribute to the cache key; all others are ignored.

## **FAQ**

**Do ignored parameters count toward the cache key?**\
No. Ignored parameters never create new cache variants.

**Can both Ignore and Cache Specific modes be enabled together?**\
No. Only one mode can be active.

**When should Request URI mode be used?**\
Request URI mode is generally intended for edge-case scenarios where the exact request format must be preserved, such as URLs containing special or non-standard characters.

**Does enabling On increase cache fragmentation?**\
Yes. Each query combination creates a separate cached object.


# ETag Verification

Validate cached content using the ETag response header so the CDN can detect when the origin object has changed.

**ETag Verification** ensures that cached objects remain synchronized with the origin after cache expiration.

When enabled, the CDN stores the **ETag** header returned by the origin and performs conditional validation after the cache TTL expires. If the ETag value has changed, the cached object is refreshed; otherwise, the existing cached version continues to be served. This helps reduce unnecessary data transfer while maintaining content consistency.

You can manage ETag Verification in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/caching#put-api-v1-cdn-organization_uuid-resource-resource_uuid-3).

Select a CDN resource in the CDN section, and navigate to the **Caching** tab.

## Configure ETag Verification

Enable or disable ETag validation to ensure cached content remains synchronized with the origin.

<figure><img src="/files/c7mtreazyBf6lnodUwPt" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Access the ETag Verification Section**

Open the **ETag Verification** section under the **Caching** tab of the selected CDN resource.
{% endstep %}

{% step %}
**Toggle ETag Verification**

Enable or disable ETag validation using the **ETag Verification** toggle.
{% endstep %}

{% step %}
**Submit the Configuration**

Click **Submit** to apply the updated validation behavior.
{% endstep %}
{% endstepper %}

## **Behaviour**

* When **enabled**, the CDN serves cached content directly from the edge until the cache TTL expires. After expiration, the CDN sends a conditional request using the stored ETag value to determine whether the cached object must be refreshed.
* When **disabled**, cached objects are served without ETag-based validation.
* ETag validation improves consistency but may result in more origin requests depending on header behavior.

## **FAQ**

**Does ETag Verification guarantee that the CDN always serves the latest version?**\
ETag Verification helps ensure content consistency after cache expiration. Cached content is served directly from the edge until the cache TTL expires.

**Does enabling ETag Verification increase origin traffic?**\
It can. Validation requires comparing ETag values, which may trigger additional revalidation requests depending on origin behavior.

**What happens if the origin does not send an ETag header?**\
The CDN cannot perform ETag-based validation. Normal cache expiration and revalidation rules apply.


# Error Status Code Cache Expiration

Configure how long specific HTTP error responses remain cached on CDN edge servers.

Error Status Code Cache Expiration defines how long selected HTTP error responses (such as 404 or 500) stay valid in the CDN cache. This reduces repeated requests to the origin when the same error occurs frequently.

You can manage Error Status Code Cache Expiration in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/caching#put-api-v1-cdn-organization_uuid-resource-resource_uuid-4).

Select a CDN resource in the CDN section, and navigate to the **Caching** tab.

## Configure Error Status Code Cache Expiration

### **Add an Error Status Code Definition**

Define a cache duration for specific HTTP error codes.

{% stepper %}
{% step %}
**Click Add to Create a New Definition**
{% endstep %}

{% step %}
**Enter the Cache Time**

Enter the duration (in seconds) for how long the selected error code should remain cached.
{% endstep %}

{% step %}
**Enter the Status Code**

Specify one or more HTTP status codes such as **404**, **500**, or **502**.
{% endstep %}

{% step %}
**Submit the Configuration**

Click **Submit** to save the definition.
{% endstep %}
{% endstepper %}

### **Edit an Error Status Code Definition**

Modify the cache time or status code.

{% stepper %}
{% step %}
**Click the Edit Icon Next to the Definition**
{% endstep %}

{% step %}
**Update the Cache Time or Status Code**
{% endstep %}

{% step %}
**Submit the Changes**

Click **Submit** to apply updates.
{% endstep %}
{% endstepper %}

### **Delete an Error Status Code Definition**

Remove a cache rule so that future error responses bypass CDN cache.

## **Behaviour**

* Cached error responses remain valid until the configured cache time expires.
* Deleting a definition does not immediately remove already cached error objects; existing cached content remains until expiration.
* Setting a low cache duration minimizes the risk of serving error responses for extended periods.
* If no definition exists for a status code, the CDN forwards all such responses to the origin without caching.

## **FAQ**

**Does removing a definition purge already cached error responses?**\
No. Existing cached content remains until it expires.

**Can I cache multiple error codes with different durations?**\
Yes. Each status code can have its own cache time.

**What happens if I set the cache time to zero?**\
A value of zero disables caching for that error status code.


# Shared Cache

Define whether a CDN resource uses its own cache or shares a common cache structure across multiple accounts using the Domain Cache Key.

Shared Cache allows multiple accounts or domains to use the same cache structure by applying a Domain Cache Key. When set to **Share**, identical content is cached only once and served across participating accounts, improving efficiency and reducing redundant origin requests.\
When set to **Default**, each account maintains its own isolated cache.

You can manage Shared Cache in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/caching#put-api-v1-cdn-organization_uuid-resource-resource_uuid-5).

Log in to the Medianova Control Panel, select a CDN resource in the CDN section, and navigate to the **Caching** tab.

## Configure Shared Cache

{% stepper %}
{% step %}
**Select the Cache Status**

Choose one of the following options:

* **Default** — Each account maintains a separate cache structure.
* **Share** — Cache is shared across accounts using the Domain Cache Key.
  {% endstep %}

{% step %}
**Submit the Configuration**

Click **Submit** to apply the selected cache status.
{% endstep %}
{% endstepper %}

## **Behaviour**

* When set to **Share**, CDN edge nodes use the same cache namespace for resources that match the Domain Cache Key.
* Cache hits increase across accounts that serve identical content.
* Changing the status does not purge existing cache; behavior changes apply to future caching operations.
* When set to **Default**, each account's cache becomes isolated again.

## **FAQ**

**Does enabling Shared Cache expose content from one customer to another?**\
No. Shared Cache only applies where explicit Domain Cache Key alignment exists and is intentionally configured.

**Does switching from Default to Share purge existing cache?**\
No. Existing cached content expires naturally according to its TTL.

**When should Shared Cache be enabled?**\
It is beneficial when multiple accounts deliver the same static assets (e.g., white-label platforms, partner domains).


# Stale Cache

Serve stale cached content when the origin returns specific HTTP error responses or enters an Updating state

Stale Cache allows CDN edge servers to deliver the last cached version of an object when the origin becomes temporarily unavailable. This includes conditions such as 500–504 errors, invalid headers, timeouts, forbidden responses, or an Updating status. Enabling Stale Cache helps maintain availability and ensures continuity of service during short-term origin instability.

You can manage Stale Cache in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/caching#put-api-v1-cdn-organization_uuid-resource-resource_uuid-6).

Log in to the Medianova Control Panel, select a CDN resource in the CDN section, and navigate to the Stale Cache.

## Configure Stale Cache

This workflow defines which origin responses allow the CDN to serve stale cached content.

<figure><img src="/files/GhEbDsmHtVCrEp09HtJG" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Select stale cache triggers**

Choose one or more conditions from the trigger list. Stale content will be served when **any** selected condition occurs.

Supported triggers in the Medianova Control Panel:

* **error** — Generic error indicator returned by the origin system.
* **timeout** — The CDN did not receive a timely response from the origin.
* **invalid\_header** — The origin returned malformed or unexpected HTTP headers.
* **http\_500** — Internal Server Error.
* **http\_502** — Bad Gateway.
* **http\_503** — Service Unavailable.
* **http\_504** — Gateway Timeout.
* **http\_403** — Forbidden.
* **http\_404** — Not Found.
* **http\_429** — Too Many Requests (rate limit).
* **updating** — The origin is in an update/maintenance state.
  {% endstep %}

{% step %}
**Save the configuration**

Select **Submit** to apply all changes.
{% endstep %}
{% endstepper %}

* Stale content is served **only if** a cached version already exists at the edge.
* Any selected trigger can activate stale delivery.
* When the origin becomes healthy again, normal cache rules resume automatically.
* Stale Cache does not refresh or regenerate content; it only delivers the most recent cached copy.
* This feature is intended for **temporary** failures, not extended outages.

## **FAQ**

**What happens if no triggers are selected?**\
Stale content is never served.

**Will Stale Cache fetch new content?**\
No. It serves only what is already cached.

**Does enabling all triggers hide origin problems?**\
It may delay visibility of backend issues. Select triggers based on operational strategy.

**Does TTL affect stale delivery?**\
TTL defines freshness; stale delivery allows fallback after TTL when origin issues occur.


# Robots.txt File

Define how the CDN serves the robots.txt file to control how search engines crawl and index your content.

The **Robots.txt File** feature determines whether search engines receive a robots.txt file from the CDN and which source the file is taken from. This allows you to enable crawling for all files or defer crawling rules to your origin.

You can manage **Robots.txt File** settings in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/caching#put-api-v1-cdn-organization_uuid-resource-resource_uuid-7).

Log in to the Medianova Control Panel, select a CDN resource in the CDN section, and navigate to the **Caching** tab.

## Configure Robots.txt File

Choose how the CDN should provide the robots.txt file for the selected resource.

{% stepper %}
{% step %}
**Select the Robots.txt File Mode**

Choose **Disabled**, **Enabled**, or **Origin** from the dropdown.

**Mode Behaviors**

**Disabled** — No robots.txt file is served.\
**Enabled** — MN CDN serves its default robots.txt file, allowing crawlers to index all content.\
**Origin** — CDN fetches and serves the robots.txt file from your origin.
{% endstep %}

{% step %}
**Save the Configuration**

Click **Submit** to apply the selected robots.txt behavior.
{% endstep %}
{% endstepper %}

<figure><img src="https://clients.medianova.com/__attachments/2515111014/image%20(5).png?inst-v=b951364f-998c-42f5-99c8-65d87945d391" alt=""><figcaption></figcaption></figure>

* **Enabled** mode always serves MN CDN’s default robots.txt content.\
  Customers cannot upload or configure a custom robots.txt file through the Panel.
* **Origin** mode delegates full control to your origin server.
* Changes propagate immediately but may take a short time to be reflected across all PoPs.

## FAQ

**Does Medianova allow uploading a custom robots.txt file?**\
No. In **Enabled** mode, the CDN serves a predefined robots.txt file that allows all crawling. To use a custom file, select **Origin** mode and host the file on your origin.

**What happens if my origin has no robots.txt file but I choose Origin mode?**\
The CDN will return `404 Not Found`, and search engines will proceed as if no robots.txt file exists.

**Does robots.txt affect CDN caching?**\
No. It only controls search engine bot behavior and does not interact with cache rules.

[<br>](https://clients.medianova.com/docs/how-can-i-change-my-medianovas-panel-password)


# Range Based Caching

Cache partial content based on byte ranges so the CDN can serve only the requested portions of large files.

Range Based Caching allows the CDN to cache and deliver content in byte-range segments rather than requiring the entire file to be fetched or cached. This improves performance for large files such as videos, archives, or software downloads by serving only the requested portions.

You can manage Range Based Caching in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/caching#put-api-v1-cdn-organization_uuid-resource-resource_uuid-8).

Select a CDN resource in the CDN section, and navigate to the **Caching** tab.

## Configure Range Based Caching

{% stepper %}
{% step %}
**Enable Range Based Caching**

Toggle **Range Based Caching** to **On** to allow the CDN to cache partial byte-range segments.

<figure><img src="/files/uLB9xmMFPKVJMaaIcPrb" alt="" width="563"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Select Segment Size**

Choose a **Segment Size** value to define how large each cached byte-range segment should be.\
This determines how the CDN partitions and stores partial content.
{% endstep %}

{% step %}
**Save the Configuration**

Click **Submit** to apply the Range Based Caching settings.
{% endstep %}
{% endstepper %}

## Behaviour

* The CDN caches content in fixed-size byte segments defined by **Segment Size**.
* Requests for ranges within the same segment are served directly from cache.
* Useful for video playback, downloads, and large binary files where clients request only parts of a resource.
* A smaller segment size increases cache precision but may increase the number of stored segments.

## FAQ

**Does Range Based Caching improve video streaming performance?**\
Yes. It prevents the CDN from fetching the entire file when only a portion is requested, improving responsiveness.

**What happens if I change the Segment Size?**\
New segment size applies only to future cached segments. Existing segments remain until evicted.

**Is this feature required for byte-range requests to work?**\
Byte-range requests work regardless, but enabling Range Based Caching ensures partial responses can come from cache instead of the origin.


# Mobile Device Cache

Define device-based caching behavior to create separate cached versions for mobile, tablet, and desktop clients.

Mobile Device Cache allows the CDN to generate different cache entries based on the detected device type. This ensures that each device category receives appropriately formatted content without cache conflicts.

The feature also forwards device information to your origin using the **X-DEVICE** and **X-MOBILE** headers.

You can manage Mobile Device Cache in the [Medianova Control Panel](https://cloud.medianova.com)

Log in to the [Medianova Control Panel](https://cloud.medianova.com), select a CDN resource in the CDN section, and navigate to the **Caching** tab.

## Enable Mobile Device Cache

{% stepper %}
{% step %}
**Enable the Setting**

Switch **Mobile Device Cache** to **On** to create separate cached versions for mobile, tablet, and desktop.
{% endstep %}

{% step %}
**Submit the Configuration**

Click **Submit** to apply the updated caching behavior.
{% endstep %}
{% endstepper %}

## **Behaviour**

Mobile Device Cache changes how cache keys are generated and what information is forwarded to the origin.

#### **Device Classification**

The CDN classifies each request using the User-Agent header:

* **mobile**
* **tablet**
* **desktop**

#### **Cache Key Variation**

A unique cache entry is created per device type, for example:

```
/index.html | mobile
/index.html | desktop
```

#### **Forwarded Headers**

<table><thead><tr><th width="154">Header</th><th width="323.0001220703125">Description</th><th>Example</th></tr></thead><tbody><tr><td><strong>X-DEVICE</strong></td><td>Device category detected by the CDN</td><td><code>mobile</code> / <code>tablet</code> / <code>desktop</code></td></tr><tr><td><strong>X-MOBILE</strong></td><td>Whether the device is mobile</td><td><code>true</code> / <code>false</code></td></tr></tbody></table>

These headers allow your origin to serve tailored content if needed.

* Device detection is based on User-Agent parsing and may not be accurate for all custom or rare device signatures.
* The feature does not provide per-resolution caching (e.g., based on screen width).
* Use this feature only if your mobile/tablet/desktop content differs meaningfully.

## **FAQ**

#### **Does Mobile Device Cache change how requests are routed to the origin?**

No. This feature affects only cache segmentation and forwards device headers. Origin routing remains unchanged.

#### **What happens if the CDN cannot identify the device type from the User-Agent?**

The request is classified as **desktop** by default, and the cache key is generated accordingly.

#### **Will enabling this feature create separate cached versions for each device type?**

Yes. Mobile, tablet, and desktop clients each receive their own cached version, preventing cross-device content mismatches.


# Headers


# CORS Header

Learn about the CORS Header and how to enable and configure this feature.

Cross-origin resource sharing (CORS) is a browser security mechanism that determines whether a web page can load resources from a different origin. While browsers allow cross-origin images, CSS files, scripts, iframes, and videos without restrictions, other request types — such as Ajax calls and web fonts — are blocked by default under the same-origin policy.

CORS defines how browsers and servers evaluate cross-origin requests. Medianova CDN can send the `access-control-allow-origin` header in HTML responses to enable controlled cross-origin access.

By default, Medianova CDN forwards any CORS-related headers sent by your origin. You only need to enable CORS Header if you want CDN edges to set or override this header.

{% hint style="info" %}
If your origin already sends a correct CORS header with HTML responses and you do not see CORS errors, you can keep CORS Header disabled.

By default, Medianova CDN forwards the CORS header in HTML responses from your origin to browsers.
{% endhint %}

You can configure CORS Header in the [Medianova Control Panel ](https://cloud.medianova.com)or via the [API](https://clients.medianova.com/api-documentation/performance-cdn/headers#put-api-v1-cdn-organization_uuid-resource-resource_uuid).

## Enable CORS Header

{% stepper %}
{% step %}
**Access CORS Header**

Go to **CDN → CDN Resources** and select a CDN Resource.\
Open the **Headers** tab.
{% endstep %}

{% step %}
**Enable CORS Header**

By default, CORS Header is disabled.\
Toggle **Status** to enable the feature.

Confirm that configuration fields are now active
{% endstep %}
{% endstepper %}

### Configure CORS Header

After enabling the feature, Medianova CDN edge servers add the `access-control-allow-origin` header to HTML responses based on your configuration.

#### Allow all origins (Wildcard)

If no domains are defined in the allow list, CDN edges return the following header:

```
access-control-allow-origin: *
```

The wildcard `*` allows any origin to load cross-origin resources from the CDN.

#### Allow specific domains

Add domains to restrict cross-origin access to only approved origins.

For example, if `https://www.shop.com` loads web fonts from `https://fonts.shop.com` and you want to prevent external sites from using these fonts, add `fonts.shop.com` to the allow list.

When a domain is added, CDN edges respond with:

```
access-control-allow-origin: https://fonts.shop.com
```

{% stepper %}
{% step %}
Enter a domain into the **Allowed Domains** field.\
Examples: `fonts.shop.com`, `https://fonts.shop.com`
{% endstep %}

{% step %}
Select **Add** to include the domain in the allow list.
{% endstep %}
{% endstepper %}

### Troubleshooting

* CORS Header applies only to **HTML responses**.
* If your origin also sets `access-control-allow-origin`, CDN behavior depends on your Header Override configuration.
* Browser console messages provide the most accurate diagnostics for CORS failures.
* If you use credentials or custom headers in your requests, additional CORS headers may be required at the origin level.


# Custom Header

Learn how to configure Custom Header rules for a CDN Resource.

The Custom Header feature allows you to add, modify, or remove HTTP headers for both origin requests and CDN responses. This configuration enables fine-grained control over how headers are passed, overwritten, or stripped at different stages of the delivery flow.

When Custom Header is enabled, you can define multiple header actions, each with a specific key–value pair and rule type. All rules are executed by CDN edge servers for the selected CDN Resource.

You can configure Custom Header in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/headers#put-api-v1-cdn-organization_uuid-resource-resource_uuid-1)

## Configure Custom Header

{% stepper %}
{% step %}
**Access Custom Header**

Go to **CDN → CDN Resources** and select a CDN Resource.\
Scroll to the **Custom Header** section.
{% endstep %}

{% step %}
**Enable Custom Header**

<figure><img src="/files/E7hRVG9PjEupvcp7Otll" alt="" width="563"><figcaption><p>Custom Header configuration interface in the Headers tab</p></figcaption></figure>

Toggle **Status** to enable the Custom Header feature.\
Verify that the rule configuration area becomes active.
{% endstep %}

{% step %}
**Create Custom Header Rules**

Select a header action from the dropdown.

**Available Header Actions**\
You can create header rules using the Add dropdown.\
Each option applies to a different stage of the request/response flow.\
**Add Origin Request Header**\
Adds a custom header to the request sent from CDN edge to the origin server.\
**Add CDN Response Header**\
Adds a custom header to responses delivered from CDN edge to the viewer.\
**Remove CDN Response Header**\
Removes a header from the response before it is sent to the viewer.\
**Raw Header**\
Creates a raw header rule with a custom directive, without binding it to request or response type logic. (Use only if you require fully custom header behavior.)\
**Remove Origin Request Header**\
Removes a header before the request is forwarded to the origin server.

Enter the **Key** and **Value** for the header, if the selected action requires one.<br>
{% endstep %}

{% step %}
**Select Submit to save**
{% endstep %}
{% endstepper %}

## Best Practices

* Header keys and values must follow valid HTTP header formatting rules.
* If the same header is modified by multiple rules, CDN edge behavior follows the order of applied rules.
* Removing headers may affect origin authentication, CORS behavior, or cache control logic.
* Use **Raw Header** only when standard rule types do not fit your use case.


# X-CDN Header

Learn how the X-CDN Header adds CDN-specific information to origin requests in the Medianova Control Panel.

The X-CDN Header feature adds an `X-CDN` header to requests that are forwarded from the CDN to your origin. This allows your origin to identify that the request is coming through Medianova CDN, which can be useful for logging, routing decisions, and origin-side analytics.

{% hint style="info" %}
This feature does not modify the response returned to the viewer and does not affect caching or delivery logic.
{% endhint %}

### How X-CDN Header Works

You can configure X-CDN Header in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/headers#put-api-v1-cdn-organization_uuid-resource-resource_uuid-2)

When the X-CDN Header toggle is enabled:

* The CDN adds the `X-CDN` header to the **origin request** during the fetch operation.
* Your origin receives every request with this header included.
* The header allows your origin to distinguish CDN-proxied traffic from direct client traffic.
* The behavior applies to all request types because insertion occurs before the origin fetch.

This feature is passive and does not alter cache decisions, TTL behavior, Page Rules, or viewer-facing responses.

<figure><img src="/files/poHLvRgbgReYEyhCZeew" alt=""><figcaption><p>X-CDN Header configuration area inside the Headers tab</p></figcaption></figure>

## Use Cases

#### Origin-side analytics

Log whether a request came through the CDN layer by checking for the `X-CDN` header.

#### Conditional behavior at the origin

Apply specific logic (e.g., rate limits, routing decisions, request tagging) based on the presence of this header.

#### Debugging origin fetches

Verify that requests are reaching your origin through the CDN, especially when diagnosing caching or routing flows.

### Notes

* The header is inserted only on the origin request.
* It is not visible to clients and does not appear in viewer-facing responses.
* Header values may differ based on internal CDN configuration.
* Enabling the header does not change caching rules, request normalization, or delivery performance.


# Google Tag Gateway

Configure Google Tag Gateway to serve supported Google tag and measurement requests through your website domain using your CDN Resource.

Google Tag Gateway allows you to serve supported Google tag and measurement requests through your website domain instead of sending them directly to Google domains.

When enabled, the CDN routes requests matching the configured Measurement Path to the appropriate Google service. This allows Google tag requests to be served through your own domain without requiring a manually maintained custom routing configuration.

{% hint style="info" %}
Google Tag Gateway configures request routing only. It does not install or modify the Google tag in your website source code.
{% endhint %}

Before enabling this feature:

* Configure your Google tag according to Google's documentation.
* Choose a Measurement Path that is not already used by your application or existing routing rules.
* Ensure your CDN Resource is correctly configured to serve the target domain.

## Configuration

To configure Google Tag Gateway:

{% stepper %}
{% step %}

### Enable Google Tag Gateway

Navigate to **CDN Resource → Headers → Google Tag Gateway**.

<figure><img src="/files/ifJNbm01CzjCGfZDGKJZ" alt=""><figcaption></figcaption></figure>

Toggle **Status** to **On**.
{% endstep %}

{% step %}

### Enter the Google Tag ID

Provide the Google Tag ID associated with your website.
{% endstep %}

{% step %}

### Specify the Measurement Path

Enter a Measurement Path that is not already used by existing content or routing rules.
{% endstep %}

{% step %}

### Apply the Configuration

Click **Submit** to save the configuration.

Medianova automatically applies the required routing configuration.
{% endstep %}
{% endstepper %}

## Verification

After enabling the feature:

* Verify that requests are sent to the configured Measurement Path.
* Confirm that Google tag functionality continues to operate as expected.
* Review your browser's developer tools or Google Tag debugging tools if further verification is required.

## Related Concepts

* [Headers](/products/performance-cdn/static-content-delivery/advanced-configuration/headers)
* [Custom Header](/products/performance-cdn/static-content-delivery/advanced-configuration/headers/custom-header)
* [Origin Host Header](/products/performance-cdn/static-content-delivery/advanced-configuration/headers/origin-host-header)


# Origin Host Header

Learn how to configure a custom Host header for origin requests in the Medianova Control Panel.

The Origin Host Header feature allows you to define a custom domain to be sent in the `Host` header of requests forwarded to your origin. Many origin servers rely on the `Host` header for routing, virtual hosting, or tenant identification.\
When this option is enabled and a domain is provided, the CDN replaces the default host value with the one you specify.

The feature does not modify viewer-facing responses and does not affect caching behavior.

## How Origin Host Header Works

You can configure X-CDN Header in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/headers#put-api-v1-cdn-organization_uuid-resource-resource_uuid-3)

When the feature is active:

* The CDN overwrites the `Host` header in the **origin request** with the domain you provide.
* The domain must be entered **without** `http://` or `https://`.
* The configured value is applied to all origin fetches for the selected CDN Resource.
* The behavior supports any valid domain that your origin server expects for routing or validation.

The purpose of this feature is to ensure compatibility with origins that require a specific hostname, especially in environments where multiple sites share the same origin infrastructure.

<figure><img src="/files/exSCwtL3paiLtcfxo1Ol" alt="" width="563"><figcaption><p>Origin Host Header field enabled with sample domain</p></figcaption></figure>

### Use Cases

#### Virtual hosting environments

Ensure the correct site is selected when multiple hostnames share the same origin.

#### Multi-tenant systems

Send a tenant-specific domain in the Host header for proper routing.

#### Origin behavior validation

Match the exact hostname your origin expects for SSL/SNI evaluation or application routing logic (when applicable to host header usage).

### Notes

* Enter only the domain name (e.g., `subdomain.example.com`).
* Do **not** include URL schemes such as `http://` or `https://`.
* This feature modifies only the **origin-bound request** and does not impact the viewer response.
* Incorrect domain entries may cause the origin to respond with errors or unexpected routing behavior.


# HTTP Strict Transport (HSTS) Protection

Learn how HSTS Protection enforces HTTPS-only access for your CDN Resource.

HTTP Strict Transport Security (HSTS) instructs browsers to connect to your domain **only over HTTPS** for a defined period of time. When enabled, the CDN adds the `Strict-Transport-Security` header to HTTPS responses, preventing protocol downgrade attacks and reducing the risk of session or cookie interception.

HSTS can also extend enforcement to subdomains and optionally request inclusion in browser preload lists.

### How HSTS Protection Works

You can configure **Headers section** in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/headers#put-api-v1-cdn-organization_uuid-resource-resource_uuid-4)

When HSTS Protection is enabled:

* The CDN adds a `Strict-Transport-Security` header to HTTPS responses.
* Browsers cache the policy for the duration specified in the `max-age` parameter.
* HTTP requests are redirected to HTTPS before the HSTS header is evaluated.
* Optional parameters allow extending enforcement to subdomains and requesting preload inclusion.
* The policy remains active in the browser until the max-age period expires.

<figure><img src="/files/ftlbaeXa0HMkLZcsc2EZ" alt=""><figcaption><p>HSTS Protection configuration options in the Headers tab</p></figcaption></figure>

#### HSTS Response Header Format

Depending on your configuration, the header may include:

```
Strict-Transport-Security: max-age=<seconds>
Strict-Transport-Security: max-age=<seconds>; includeSubDomains
Strict-Transport-Security: max-age=<seconds>; preload
Strict-Transport-Security: max-age=<seconds>; includeSubDomains; preload
```

### Configuration Options

#### Max Age (Seconds)

Defines how long the browser must enforce HTTPS for your domain.\
Common values:

* `31536000` (1 year)
* `63072000` (2 years)

#### Include Subdomains

When enabled, HSTS applies to **all subdomains**, not only the primary domain.

#### Preload

Requests inclusion in browser preload lists.\
(Preload requires `max-age â‰¥ 31536000` and `includeSubDomains` to be enabled.)

### Use Cases

* Enforce HTTPS-only access for compliance or security policies.
* Reduce risk of downgrade/MiTM attacks.
* Strengthen browser-side enforcement for high-value applications.
* Ensure all subdomains—including those without valid HTTP → HTTPS redirects—are protected.

### Notes

* HSTS applies only to **HTTPS responses**; the header is not sent over HTTP.
* Incorrect configuration may block HTTP fallback paths if subdomains or legacy systems depend on them.
* Preload inclusion requires submitting your domain to the global HSTS preload list.
* Changing the HSTS max-age does not immediately remove the policy from browsers; they follow previously cached durations.


# X-Frame Options

Learn how the X-Frame Options feature controls which sites are allowed to frame your content.

The X-Frame Options feature adds the `X-Frame-Options` HTTP response header to prevent unauthorized framing of your website. This header is commonly used to mitigate clickjacking attacks by restricting how and where your content can be embedded inside an `<iframe>`.

When enabled, the CDN includes the header in responses according to the configuration you provide.

### How X-Frame Options Works

You can configure X-CDN Header in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/headers#put-api-v1-cdn-organization_uuid-resource-resource_uuid-5)

When the feature is active:

* The CDN adds an `X-Frame-Options` header to viewer responses.
* If **no domain** is configured, the CDN sets:

  ```
  X-Frame-Options: SAMEORIGIN
  ```

  which allows framing only from the same domain.
* If **one or more domains** are provided, the CDN applies:

  ```
  X-Frame-Options: ALLOW-FROM <domain>
  ```

  for each allowed domain, enabling selective embedding.
* The browser enforces the framing policy and blocks disallowed attempts.

<figure><img src="/files/nqxozfSKnN5hSVwK4j0M" alt=""><figcaption><p>X-Frame Options configuration area inside the Headers tab</p></figcaption></figure>

### Use Cases

#### Prevent clickjacking

Block external sites from embedding your pages to protect users from UI redress attacks.

#### Allow trusted partners

Permit framing only from specific domains that require embedded content (e.g., partner dashboards, internal tools).

#### Enforce controlled embedding behavior

Define clear, browser-enforced restrictions on how your content is presented in external applications.

### Notes

* `ALLOW-FROM` is not supported by all browsers. Modern security policies often prefer CSP `frame-ancestors`.
* `X-Frame-Options` does not affect API endpoints or non-HTML content.
* If multiple allowed domains are configured, behavior may vary by browser due to varying support levels.
* This header has no effect on origin requests; it is applied only to viewer-facing responses.


# X-XSS Protection

Learn how the X-XSS Protection header controls browser-side filtering of reflected Cross-Site Scripting (XSS) attacks.

The X-XSS Protection feature adds the `X-XSS-Protection` header to viewer responses. This header instructs compatible browsers to enable their built-in XSS filtering mechanisms. While most modern browsers now ignore this header, the setting can still provide protection for legacy browsers that rely on it.

The feature does not modify origin requests or affect CDN caching behavior.

## How X-XSS Protection Works

You can configure X-CDN Header in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/headers#put-api-v1-cdn-organization_uuid-resource-resource_uuid-6)

When enabled:

* The CDN adds the following header to viewer-facing responses:

  ```
  X-XSS-Protection: 1; mode=block
  ```
* Browsers that still support the header will block pages that trigger reflected XSS heuristics.
* If disabled, the CDN does not include the header, and browsers revert to their default behavior.

This feature is primarily relevant for environments that depend on legacy browser compatibility.

<figure><img src="/files/S5XiLBJU5RLi7AdvT2Wc" alt=""><figcaption><p>X-XSS Protection toggle inside the Headers tab</p></figcaption></figure>

### Use Cases

#### Legacy browser support

Provide reflected-XSS filtering for older browsers that still honor the header.

#### Controlled security posture

Ensure consistent browser behavior across mixed device environments or corporate networks with outdated browser fleets.

### Notes

* Modern browsers (Chrome, Edge, Safari) ignore `X-XSS-Protection` and instead rely on CSP (`Content-Security-Policy`) for XSS mitigation.
* This feature affects only **viewer responses**, not origin requests.
* Enabling the header does not prevent stored or DOM-based XSS attacks.


# X-Content Type Options

Learn how the X-Content-Type-Options header prevents MIME sniffing and enforces strict content-type handling in the browser.

The X-Content-Type-Options feature adds the `X-Content-Type-Options` header to viewer responses. This header instructs compatible browsers not to perform MIME sniffing and to rely strictly on the `Content-Type` declared by the server. Disabling MIME sniffing helps reduce exposure to certain injection and cross-site scripting (XSS) vectors.

{% hint style="info" %}
The feature does not modify origin requests or CDN caching behavior.
{% endhint %}

### How X-Content-Type-Options Works

You can configure X-CDN Header in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/headers#put-api-v1-cdn-organization_uuid-resource-resource_uuid-6)

When enabled:

* The CDN adds the following header to viewer-facing responses:

  ```
  X-Content-Type-Options: nosniff
  ```
* Browsers that support this header will not attempt to infer content types and will instead enforce the value provided by the origin.
* MIME sniffing is disabled for resources such as scripts, stylesheets, and other content types that could be misinterpreted.

<figure><img src="/files/ykKBKRnf3sDafgEZfoMH" alt=""><figcaption><p>X-Content-Type-Options toggle inside the Headers tab</p></figcaption></figure>

### Use Cases

#### Prevent MIME sniffing

Ensure the browser does not guess content types, avoiding scenarios where a file may be interpreted as executable code.

#### Improve XSS resilience

Reduce attack surfaces where incorrect content-type interpretation could lead to script execution.

#### Enforce strict content handling

Guarantee consistent behavior across browsers by ensuring content is processed exactly as declared.

### Notes

* The header is applied only to **viewer responses**, not to origin-bound requests.
* Modern browsers widely support `nosniff`, but legacy browsers may behave inconsistently.
* Enabling this header does not alter your CDN caching logic.
* Correct MIME types must still be set by your origin; this header does not correct misconfigured content types.


# Purge

Instantly invalidate outdated cache entries across all Medianova CDN cache layers to ensure the latest content is delivered globally without waiting for TTL expiration.

**Purge** invalidates cached content across the Medianova CDN before its cache lifetime (TTL) expires.\
It ensures that updated content from your origin is immediately reflected and consistently served from all cache layers worldwide.

When a purge is executed, the Medianova purge system distributes invalidation commands across the CDN’s cache hierarchy. Cached objects are marked as expired and fetched again from your origin upon the next user request.

You can trigger a purge from the [Medianova Control Panel](https://cloud.medianova.com) or via [API](/api-documentation/performance-cdn/purge) .

### When to Purge Cached Content

Use purge whenever:

* Updated HTML, CSS, JS, images, or video files must be reflected immediately.
* Outdated or sensitive content needs to be removed from CDN caches.
* New deployments or configuration changes require instant cache refresh.
* Consistency across all cache layers is required after a content update.

{% hint style="info" %}
Combine purge operations with **shorter TTL values** for dynamic or frequently changing content.
{% endhint %}

### Types of Purge

Medianova supports multiple purge methods to give you flexibility and control:

<table><thead><tr><th width="180">Type</th><th width="384.0001220703125">Description</th><th>Example</th></tr></thead><tbody><tr><td><strong>Single File Purge</strong></td><td>Removes one specific file from all CDN caches.</td><td><code>/images/banner.jpg</code></td></tr><tr><td><strong>Wildcard Purge</strong></td><td>Removes multiple files using pattern matching.</td><td><code>/images/*</code></td></tr><tr><td><strong>Full CDN Resource Purge</strong></td><td>Clears all cached files for a specific CDN Resource.</td><td><code>/*</code></td></tr></tbody></table>

{% hint style="info" %}
Wildcard purge operations are recursive and affect all subdirectories.\
To use wildcard patterns, the **Wildcard Purge Suffix** option must be enabled under **CDN Settings**.
{% endhint %}

### How Purge Works

1. A purge request is initiated via the Medianova Control Panel or [API](/api-documentation/performance-cdn/purge).
2. Medianova’s purge system distributes invalidation commands to all cache layers.
3. Cached objects matching the path are **marked as invalid** and no longer served.
4. On the next user request, the CDN retrieves the fresh content from the origin and re-caches it.

{% hint style="info" %}
Cache propagation completes rapidly, depending on node density, region count, and network conditions.
{% endhint %}

### Purge Propagation & Behavior

Purge requests propagate through all layers of Medianova’s caching infrastructure extremely quickly – typically completing across our global network in under 5 seconds – ensuring that outdated content is swiftly replaced with fresh content worldwide.

<table><thead><tr><th width="238">Behavior</th><th>Description</th></tr></thead><tbody><tr><td><strong>Instant Global Invalidation</strong></td><td>Cache invalidations propagate rapidly across all CDN cache layers.</td></tr><tr><td><strong>Parallel Distribution</strong></td><td>Purge commands are broadcast concurrently to all cache nodes for faster execution.</td></tr><tr><td><strong>Independent Caches</strong></td><td>Each CDN node manages its local cache separately; purge ensures global synchronization.</td></tr><tr><td><strong>Auto Revalidation</strong></td><td>After purge, next requests trigger fresh pulls from the origin.</td></tr></tbody></table>

{% hint style="info" %}
A full purge (`/*`) removes **all cached files** for that resource and should be used only when necessary.
{% endhint %}

### Best Practices

* **Purge only what’s needed.** Avoid full purges to reduce cache refill load.
* **Use specific paths** instead of broad wildcard patterns whenever possible.
* **Automate with API purge** to clear cache after deployments or content updates.
* **Monitor purge logs** to verify completion (see Manage Purge).
* **Coordinate with TTL strategy.** If content changes often, use shorter cache durations.


# How to Purge

Learn how to invalidate cached content instantly across all Medianova CDN

You can manage Purge operations in the [Medianova Control Panel](https://cloud.medianova.com) or via [API](/api-documentation/performance-cdn/purge).

Log in to the Medianova Control Panel, select a CDN Resource in the **CDN** section, and navigate to the **Purge** tab.

### Purge Cached Files

Purge instantly invalidates cached content across all Medianova CDN cache layers.\
Use this feature when updated content is not yet reflected or when outdated assets need to be refreshed.

{% stepper %}
{% step %}
**Enter File Path**

In the **Path** field, type the exact file or directory path you want to purge.\
You can specify multiple paths by entering one per line.

**Example:**

```
/myimages/subfolder/image.png
/assets/css/*
```

{% endstep %}

{% step %}
**Use Wildcards**

You can use the `*` symbol to purge multiple files within a directory.

**Examples:**

* `/images/*` — removes all files and subdirectories inside `/images/`
* `/images/im*` — removes files starting with “im”
  {% endstep %}

{% step %}
**Execute the Purge**

Click **Purge Files** to start the invalidation.\
Medianova CDN will distribute the purge request to all cache layers and mark the specified objects as expired.\
The next request will automatically fetch the latest version from your origin.
{% endstep %}
{% endstepper %}

Medianova’s purge mechanism rapidly invalidates content across every cache layer (from edge nodes to core caches), usually finishing propagation within seconds under normal conditions. This near-immediate purge completion means users around the world see the updated content almost instantly after you purge.

### **Monitor Purge Requests**

All recent purge operations are listed in the **Purge Log** table below.\
Use this view to track the status of your requests.

<table><thead><tr><th width="284">Column</th><th>Description</th></tr></thead><tbody><tr><td><strong>Status</strong></td><td>Shows whether the purge is <em>Running</em>, <em>Successful</em>, or <em>Failed</em>.</td></tr><tr><td><strong>Task ID</strong></td><td>A unique identifier for each purge operation.</td></tr><tr><td><strong>File Type</strong></td><td>Type of purge</td></tr><tr><td><strong>Created At</strong></td><td>Time the purge was initiated.</td></tr><tr><td><strong>URLs</strong></td><td>Number of URLs affected.</td></tr><tr><td><strong>Running / Successful / Failed</strong></td><td>Summary of the operation result.</td></tr></tbody></table>

{% hint style="info" %}
Click the **refresh icon** to reload the log and check the latest results.
{% endhint %}


# Prefetch

Proactively warm up CDN caches by fetching files from your origin before user access, ensuring fast delivery and avoiding cache misses.

**Prefetch** refers to the process of proactively fetching and caching specific files from your origin before any user request occurs.\
It warms up CDN caches so that the **first users receive content instantly**, avoiding slow cache misses and offloading your origin server.\
When you initiate a Prefetch, the CDN pulls the file from your origin and caches it across all CDN POPs.\
This is especially effective for the delivery of large static or media files.

{% hint style="info" %}
Prefetch does **not** override existing cache entries. If the file is already cached, a prefetch request will not re-fetch it from origin.

To force a refresh, perform a **Purge** first, followed by **Prefetch**.
{% endhint %}

You can initiate Prefetch operations from the [Medianova Control Panel](https://cloud.medianova.com) or via the [API](/api-documentation/performance-cdn/prefetch).

### **When to Use Prefetch**

Use Prefetch to:

* Preload content before a scheduled event, campaign, or content release
* Ensure large static files (e.g., videos, software downloads) load instantly
* Avoid cache-miss latency for the first user(s)
* Offload your origin by serving assets from CDN edge locations

### **How Prefetch Works**

1. You submit one or more file paths via the Medianova Control Panel or [API](https://clients.medianova.com/api-documentation/performance-cdn/prefetch).
2. Medianova CDN initiates an HTTP GET request to your origin for each file.
3. If the file is not already cached, it is fetched and stored across CDN edge locations.
4. The file is then available to be served instantly to users from cache.

{% hint style="info" %}
Prefetch attempts to populate the file across all CDN edge caches to reduce latency globally.
{% endhint %}

### **Prefetch Propagation & Behavior**

When you initiate a Prefetch, the CDN issues an HTTP GET request to your origin and stores the file in cache across all CDN POPs (Points of Presence).\
This ensures that the file is readily available globally, without waiting for actual user traffic to trigger cache population.

Unlike **Purge**, which invalidates cached content, **Prefetch only populates caches if the file is not already cached**. If the file already exists in cache, Prefetch will not re-fetch it from origin.

<table data-header-hidden><thead><tr><th width="256"></th><th></th></tr></thead><tbody><tr><td><strong>Behavior</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Single-file fetching</strong></td><td>Each Prefetch request targets one specific file path</td></tr><tr><td><strong>CDN-wide propagation</strong></td><td>Files are cached across all POPs</td></tr><tr><td><strong>TTL adherence</strong></td><td>Cache duration respects the file's Cache-Control or configured TTL settings</td></tr><tr><td><strong>Origin-safe</strong></td><td>No effect if the file is already cached unless purged first</td></tr></tbody></table>

**Prefetch Type**

Medianova supports **single-file Prefetch**, which allows fetching and caching a specific file from your origin.

<table data-header-hidden><thead><tr><th width="178"></th><th width="373"></th><th></th></tr></thead><tbody><tr><td><strong>Type</strong></td><td><strong>Description</strong></td><td><strong>Example</strong></td></tr><tr><td><strong>Single File Prefetch</strong></td><td>Fetches and caches one specific file from your origin.</td><td><code>/videos/intro.mp4</code></td></tr></tbody></table>

{% hint style="info" %}
Wildcard operations are not supported.\
Each Prefetch request must target a single file path.
{% endhint %}

#### **Best Practice Highlights**

* Prefetch only frequently accessed static files, such as videos, images, or large downloads.
* Use **Purge + Prefetch** together to refresh caches after file updates.
* Schedule Prefetch operations during **off-peak hours** to minimize origin load.
* Avoid prefetching non-cacheable or dynamic resources.
* Verify operation results in the **Prefetch Logs** section.

{% hint style="info" %}
Monitor your Prefetch efficiency using [Edgesight Analytics](/products/logz/mn-logz-analytics).
{% endhint %}


# How to Prefetch

Perform Prefetch operations through the Control Panel or API to proactively cache files and deliver them instantly to end-users.

**Prefetch** allows you to pull specific files from your origin into the CDN cache before any user requests them.\
Use this feature to eliminate cache misses, reduce origin load, and ensure fast delivery to the first users.

You can initiate Prefetch via the [Medianova Control Panel](https://cloud.medianova.com) or [Prefetch API](/api-documentation/performance-cdn/prefetch).

{% hint style="info" %}
Prefetch does not overwrite existing cached content.\
To update a file that is already cached, you must first **Purge** it and then **Prefetch**.
{% endhint %}

### Prefetch via [Control Panel](https://cloud.medianova.com)

{% stepper %}
{% step %}
**Enter File Path**

In the **Path** field, enter one file path per line.\
Each line must point to a specific file you want to prefetch.

**Examples:**

```
/videos/product_launch.mp4  
/assets/images/banner.jpg  
/css/style.css
```

{% hint style="info" %}
Wildcard paths (e.g. `/images/*`) are not supported.
{% endhint %}
{% endstep %}

{% step %}
**Execute the Prefetch**

Click **Prefetch Files** to initiate the operation.\
Medianova will send an HTTP GET request to your origin for each file and cache the response.

Once complete, those files will be ready for instant delivery from the CDN cache.
{% endstep %}
{% endstepper %}

Medianova’s Prefetch mechanism performs **controlled fetch operations** that proactively warm up cache layers.\
This eliminates the delay caused by a first-time cache miss and reduces origin load during peak demand.

### **Monitor Prefetch Requests**

All Prefetch operations are listed in the **Prefetch Log** table below.\
Use this view to track the status and results of your Prefetch actions.

<table data-header-hidden><thead><tr><th width="173"></th><th></th></tr></thead><tbody><tr><td><strong>Column</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Status</strong></td><td>Indicates whether the Prefetch operation is <em>Running</em>, <em>Successful</em>, or <em>Failed</em>.</td></tr><tr><td><strong>Task ID</strong></td><td>A unique identifier assigned to each Prefetch request.</td></tr><tr><td><strong>File Path</strong></td><td>Type of Prefetch</td></tr><tr><td><strong>Created At</strong></td><td>Time when the Prefetch was initiated.</td></tr><tr><td><strong>Duration</strong></td><td>Total time the operation took to complete.</td></tr><tr><td><strong>Result</strong></td><td>Summary of the Prefetch</td></tr></tbody></table>

{% hint style="info" %}
Click the **refresh icon** to reload the Prefetch Log and check the latest results.
{% endhint %}


# Page Rules

Learn about Page Rules, how to manage Page Rules and the available settings.

Page Rules trigger one or more actions on an incoming request to Medianova CDN whenever a defined URL pattern is matched.

Page Rules are available in the [Medianova Panel](https://cloud.medianova.com/) for any CDN resource in the Page Rules tab.

Available [settings for Page Rules](/products/performance-cdn/static-content-delivery/advanced-configuration/page-rules/page-rules-settings) include Cache Type, Custom Header, Geoblocking and more.

### Availability

Page Rules can be configured foror CDN resources of type Small, Dynamic, Large & VOD.

The default number of allowed page rules depends on the package as shown below.

|                 | Free | Pro | Business | Enterprise |
| --------------- | ---- | --- | -------- | ---------- |
| Availability    | Yes  | Yes | Yes      | Yes        |
| Number of rules | 5    | 30  | 50       | 125        |

### Priority Order Matters

Only one Page Rule will trigger per URL, that is the the matching page rule with the highest priority.

In the Medianova Panel, Page Rules are sorted top-to-bottom from highest priority to lowest priority. For this reason, we recommend ordering your rules from most specific to least specific.


# Manage Page Rules

Learn how to add, edit, clone and delete page rules in the Medianova Panel.

You can manage Page Rules in the [Medianova Panel](https://cloud.medianova.com/) or via [API](https://clients.medianova.com/api-documentation/performance-cdn/page-rule).

Log in to the [Medianova Panel](https://cloud.medianova.com/), select a CDN resource in the **CDN** section and navigate to the **Page Rules** tab.

### Turn on Page Rules

By default, Page Rules is disabled. Click the **Status** toggle to turn on Page Rules.

<figure><img src="/files/MAgbk3pRIb3dh4vpf8vF" alt=""><figcaption><p>Page Rules start screen</p></figcaption></figure>

The screen now shows a **Create Page Rule** button, enabling you to get started with your first page rule.

### File Path and File Extension

Page Rules match on a combination of file path and file extension.

| Field           | Available options                     |
| --------------- | ------------------------------------- |
| File Path       | Directory, wildcard and regex pattern |
| File Extensions | Any, one or more                      |

Directory is recursive (unless using the [Exact Match](/products/performance-cdn/static-content-delivery/advanced-configuration/page-rules/page-rules-settings) setting), meaning `/dir/` matches all URLs for files in the `/dir/` directory and its subdirectories.

Wildcard is for example `*` to match on any URL path and `/*/images/` matches URLs in any second-level `images` directory.

When using regex pattern, only the `* . / () [] $` symbols are supported. You cannot use other symbols, including `? ! + ^`.

### Add a Page Rule

{% stepper %}
{% step %}
**Click the Create Page Rule button**

A new window appears containing a form to create a page rule. The form requires specifying a [File Path and one or more File Extension](#file-path-and-file-extension) entries, and allows for selecting and configuring [Page Rules settings](/products/performance-cdn/static-content-delivery/advanced-configuration/page-rules/page-rules-settings).

<figure><img src="/files/jwWoJhcQdfr1YcFIQePU" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Set the File Path and File Extensions**
{% endstep %}

{% step %}
**Select and Configure Settings**

From the drop down menu, select a setting and click the **Add a Setting** button. Configure the setting using the options that appear below the drop down menu.

Repeat this step if you want the page rule to trigger multiple actions.
{% endstep %}

{% step %}
**Deploy to CDN**

Push the page rule to the CDN by clicking the **Create** button.
{% endstep %}
{% endstepper %}

### View Rule Summary

Find the page rule in the table, click on the rule and view Rule Summary. The new window shows the status of every setting and details for each setting.

<figure><img src="/files/r3xZdaVaUXLRCkyTg8Ik" alt=""><figcaption></figcaption></figure>

### Clone a Page Rule

If you want to create a new page rule that is very similar to an existing rule, the easiest way is to clone the existing rule, and then apply changes to the clone.

{% stepper %}
{% step %}
**Select the Page Rule to Clone**

Find the page rule in the table, click the three dots and select **Clone Page Rule**. A new window appears for editing the cloned rule:

<figure><img src="/files/EtNFGUi15MU1WMZoJqys" alt="" width="563"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Set the File Path and File Extensions**

Set a combination of file path and file extensions that is different from the rule you just cloned.
{% endstep %}

{% step %}
**Deploy to CDN**

Push the new page rule to the CDN by clicking the **Clone** button.
{% endstep %}
{% endstepper %}

### Edit a Page Rule

Change the page rule in three steps:

{% stepper %}
{% step %}
**Select the Page Rule to Edit**

Find the page rule in the table, click the three dots and select **Edit Page Rule**. A new window appears for editing the rule.

<figure><img src="/files/a8BI5PhWIFl1wiBdaeFs" alt="" width="563"><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Change the File Path and File Extensions**

{% hint style="info" %}
If you only want to change page rule settings, do not edit the file path and file extensions
{% endhint %}
{% endstep %}

{% step %}
**Change Page Rule Settings**

From the drop down menu, select a setting you want to change and click the **Add a Setting** button. Configure the setting using the options that appear below the drop down menu.

Repeat this step if you want to change another setting.
{% endstep %}

{% step %}
**Deploy to CDN**

Push the page rule to the CDN by clicking the **Update** button.
{% endstep %}
{% endstepper %}

### Delete a Page Rule

Find the page rule in the table, click the three dots, select **Delete Page Rule** and click **Yes, Delete** in the confirmation window. This triggers an immediate update to CDN servers.


# Page Rules Settings

Learn about the actions Medianova CDN can take based on a page rule, and the configuration options for each setting.

Settings control the actions Medianova CDN takes once a request matches the URL pattern defined in a page rule.

The table below outlines all settings available in Page Rules from the [Medianova Control Panel](https://cloud.medianova.com).

{% hint style="info" %}
Medianova can implement custom page rule configuration at your request, for example network rate limit and security headers.
{% endhint %}

| Setting                                                               | Description                                     | Packages                    |
| --------------------------------------------------------------------- | ----------------------------------------------- | --------------------------- |
| [Cache Type](#cache-type)                                             | Configure edge caching behaviour and TTL        | All                         |
| [CORS](#cors)                                                         | Configure cross-origin resource sharing headers | All                         |
| [Custom Header](#custom-header)                                       | Add or remove request and response headers      | All                         |
| [Downloadable Query String Header](#downloadable-query-string-header) | Trigger browser to download file                | All                         |
| [Exact Match](#exact-match)                                           | Disable recursive URL matching                  | All                         |
| [Hotlink Protection](#hotlink-protection)                             | Configure specific hotlink protection           | Starter, Growth, Enterprise |
| [Options Request](#options-request)                                   | Enable OPTIONS requests                         | All                         |
| [Query String Caching](#query-string-caching)                         | Configure specific query string caching         | All                         |
| [Range Based Caching](#range-based-caching)                           | Disable range based caching                     | All                         |

### Cache Type

Use the Cache Type setting to control CDN caching.

Select **Edge** to specify how long the CDN may cache responses.

Select **Origin** to instruct the CDN to determine the maximum cache duration from origin response headers `cache-control` or `expires` .

Select **Dynamic** to disallow the CDN to cache responses for matching URLs.

### CORS

The CORS setting controls the cross-origin resource sharing (CORS) header `access-control-allow-origin` in responses served by Medianova CDN edge servers.

<table><thead><tr><th width="279.3651123046875">Option</th><th>Description</th></tr></thead><tbody><tr><td>On</td><td>Edge servers use the settings of the <a href="/pages/WxKtutJ3ZyXWr063sD76">Cors Header</a> feature</td></tr><tr><td>Off</td><td>Edge servers forward the CORS header from origin</td></tr><tr><td>Dynamic</td><td>Outgoing CDN responses have the <code>access-control-allow-origin: &#x3C;origin></code> CORS header, where <code>&#x3C;origin></code> is the value of the <code>Origin</code> header in the incoming request</td></tr></tbody></table>

### Custom Header

Set the **Custom Header Type** to **Default** to have the CDN inherit the parent settings, as configured in the Headers tab in the Medianova Panel.

Set the **Custom Header Type** to **Custom** to disable parent setting inheritance and customize the headers.\
Configure the CDN to manipulate headers in requests to origin, or to manipulate headers in responses the CDN sends to clients/browsers.

<table><thead><tr><th width="279.3651123046875">Option</th><th>Description</th></tr></thead><tbody><tr><td>Add Origin Request Header</td><td>Add header to requests to origin</td></tr><tr><td>Remove Origin Request Header</td><td>Remove header from requests to origin</td></tr><tr><td>Add CDN Response Header</td><td>Add header to outgoing CDN responses</td></tr><tr><td>Remove CDN Response Header</td><td>Remove header from outgoing CDN responses</td></tr></tbody></table>

### Downloadable Query String Header

Use the Downloadable Query String Header setting to trigger browsers to download a file instead of displaying it.

In the page rule, toggle the setting on and specify a **Downloadable Query String Header Key** and a **Downloadable Query String Header Value**. For example, set the key to `download` and the value to `yes` to trigger a browser to download the file when it loads a URL with query string `?download=yes` (and the URL matches on File Path and File Extension as configured in the page rule).

The CDN will send the `content-disposition` response header with in its value the `attachment` attribute and the path to the file. For example, `content-disposition: attachment; filename="manual.pdf"`

### Exact Match

Turn on Exact Match to disable recursive directory processing.\
For example, if the page rule has File Path `/dir/` and Exact Match is enabled, only URLs for files in that exact directory will match, while with Exact Match off (default) the page rule would also take action for files in subdirectories like `/dir/subdir/` .

### Hotlink Protection

If Hotlink Protection is turned on in the parent setting in the Security tab, a new page rule will inherit its status and configuration. The Update a Page Rule screen then shows the **Hotlink Protection** toggle in the active state and the **Hotlink Protection Type** is set to **Default**.

Change the **Hotlink Protection Type** to **Custom** to and confgure the **Hotlink Protections** that must apply to matching URLs.

<figure><img src="/files/nb5Fm3NhmcUKX0lyfD8G" alt=""><figcaption><p>Hotlink Protection screen in Page Rules</p></figcaption></figure>

### Options Request

Turn on Options Request to have the CDN send edge-generated responses to requests with the OPTION method in case the origin does not respond to OPTION requests.

### [Query String Caching](/products/performance-cdn/static-content-delivery/advanced-configuration/caching/query-string-caching)

While a new page rule inherits the parent setting for [Query String Caching](/products/performance-cdn/static-content-delivery/advanced-configuration/caching/query-string-caching) (as configured in the Caching tab in the [Medianova Control Panel](https://cloud.medianova.com)), you can customize the CDN query string caching behavior for matching URLs.

Query String Caching in Page Rules has four options:

<table><thead><tr><th width="191.5028076171875">Option</th><th>Description</th></tr></thead><tbody><tr><td>Retain All</td><td>Query string is part of the cache key. <code>/image.jpg?123</code> is cached separately from <code>/image.jpg?456</code></td></tr><tr><td>Ignore All</td><td>All query string parameters are ignored. <code>/image.jpg?123</code> and <code>/image.jpg?456</code> are considered the same response</td></tr><tr><td>Retain Specific</td><td>Only the specified query string parameters are included in the cache key</td></tr><tr><td>Ignore Specific</td><td>The specified query string parameters are ignored when determining the cache key</td></tr></tbody></table>

### [Range Based Caching](/products/performance-cdn/static-content-delivery/advanced-configuration/caching/range-based-caching)

Page Rules allows you to enable/disable Range Based Caching for matching URLs, regardless of the parent setting for Range Based Caching

(as configured in the Caching tab in the [Medianova Control Panel](https://cloud.medianova.com)).


# Path & Extension Based Rate Limiting

Apply request rate limits and IP whitelist exceptions to traffic matching specific URL paths or file extensions using Page Rules.

Path & Extension Based Rate Limiting allows you to apply request rate limits to traffic matching specific URL paths and/or file extensions, such as `/api`, `/login`, `.pdf`, or `.jpg`.

This provides granular control over specific endpoints or file types without applying the same rate limit to all traffic.

Path & Extension Based Rate Limiting is available under **Page Rules** for **Small, Large, and Dynamic CDN Resources**. It is **Off by default** and must be explicitly enabled for each Page Rule.

{% hint style="info" %}
Resource-level **Rate Limiting must be enabled** before a Rate Limiting configuration in a Page Rule can take effect.
{% endhint %}

## How Rate Limiting Works in Page Rules

Path & Extension Based Rate Limiting uses the same continuous rate enforcement behavior as resource-level Rate Limiting but applies it only to traffic matching the Page Rule.

The configured limit is evaluated continuously as a request rate rather than as a fixed request count that resets at the end of the selected time period.

For example, a configuration of **100 requests per minute** is distributed over time and enforced continuously. It does not allow all 100 requests to be sent at once at any point during the minute.

When the permitted request rate is exceeded, the configured **Burst Mode** determines how temporary traffic spikes are handled.

### IP Whitelist

Each Page Rule can define its own **IP Whitelist** for Rate Limiting.

Requests from whitelisted IP addresses are excluded from the Rate Limit configured for that Page Rule. Other requests matching the Page Rule remain subject to the configured rate limit.

IP whitelists are configured independently for each Page Rule. This allows different paths or endpoints to exclude different trusted IP addresses from Rate Limiting.

### Burst Modes

You can select one of the following Burst Modes:

* **None** — Enforces the configured request rate without additional burst capacity.
* **Burst** — Allows requests above the configured rate within the defined burst capacity. Requests within this capacity may be delayed and processed according to the configured rate.
* **Burst + No Delay** — Allows requests within the defined burst capacity to pass immediately without delay.

{% hint style="info" %}
Burst capacity does not increase the configured request rate. It provides temporary tolerance for short traffic spikes above the normal rate.
{% endhint %}

When requests exceed the permitted rate and available burst capacity, they are blocked with an **HTTP 429 Too Many Requests** response.

## Configuration Fields

<table><thead><tr><th width="176.6666259765625">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Path</strong></td><td>Defines the URL path matched by the Page Rule, such as <code>/api/login</code>.</td></tr><tr><td><strong>File Extensions</strong></td><td>Defines the file extensions matched by the Page Rule, such as <code>.html</code>, <code>.jpg</code>, or <code>.pdf</code>.</td></tr><tr><td><strong>Rate Limiting</strong></td><td>Enables or disables Rate Limiting for the Page Rule.</td></tr><tr><td><strong>Request Limit</strong></td><td>Defines the request rate applied to traffic matching the Page Rule.</td></tr><tr><td><strong>Per</strong></td><td>Defines the time unit for the request rate: <strong>Per Second</strong> or <strong>Per Minute</strong>.</td></tr><tr><td><strong>Burst Mode</strong></td><td>Determines how temporary traffic spikes above the configured request rate are handled: <strong>None</strong>, <strong>Burst</strong>, or <strong>Burst + No Delay</strong>.</td></tr><tr><td><strong>Burst Value</strong></td><td>Defines the burst capacity when <strong>Burst</strong> or <strong>Burst + No Delay</strong> is selected.</td></tr><tr><td><strong>IP Whitelist</strong></td><td>Enables or disables the IP whitelist for the Page Rule's Rate Limiting configuration.</td></tr></tbody></table>

{% hint style="info" %}
If the resource's default Cache Type is **dynamic** or **edge**, you must explicitly define the same **Cache Type** in the Page Rule when applying Path & Extension Based Rate Limiting. Otherwise, caching for that path or extension falls back to **origin**, and response behavior relies on origin headers.
{% endhint %}

## Configure Path & Extension Based Rate Limiting

{% stepper %}
{% step %}

### Access Page Rules

Navigate to the **Page Rules** tab in your CDN Resource in the [Medianova Control Panel](https://cloud.medianova.com).
{% endstep %}

{% step %}

### **Click Add Rule**

Select **Add Rule** to create a new Page Rule.
{% endstep %}

{% step %}

### Define the Traffic

Define the traffic that the Page Rule should match:

* Enter a **Path**, such as `/login`.
* Enter one or more **File Extensions**, such as `.jpg` or `.pdf`, when required.
  {% endstep %}

{% step %}

### **Select Rate Limiting**

Select **Rate Limiting** from the Page Rule settings.
{% endstep %}

{% step %}

### Enable Rate Limiting

Enable the **Rate Limiting** toggle.
{% endstep %}

{% step %}

### Configure the Rate

Configure the request rate:

* **Request Limit** — Select the request limit.
* **Per** — Select **Per Second** or **Per Minute**.
* **Burst Mode** — Select **None**, **Burst**, or **Burst + No Delay**.
* **Burst Value** — Define the burst capacity when **Burst** or **Burst + No Delay** is selected.

{% hint style="info" %}
If the resource's default **Cache Type** is `dynamic` or `edge`, explicitly add the same **Cache Type** to the Page Rule.
{% endhint %}
{% endstep %}

{% step %}

### Configure the IP Whitelist

To exclude trusted IP addresses from Rate Limiting for this Page Rule:

1. Enable **IP Whitelist**.
2. Enter an IP address in the **Add IP...** field.
3. Select **+** to add the IP address.
4. Repeat the process to add additional IP addresses when required.

Added addresses appear under **Whitelisted IPs**.

Whitelisted IP addresses bypass the Rate Limit configured for this Page Rule. Other matching requests remain subject to the configured rate limit.
{% endstep %}

{% step %}

### Save the Rule

Select **Save Rule** to apply the Page Rule configuration.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
With **None**, the configured request rate is enforced without additional burst capacity. Select **Burst** or **Burst + No Delay** when the targeted traffic needs to tolerate short spikes above the configured request rate.
{% endhint %}

{% hint style="info" %}
Page Rules are processed **in order**, from top to bottom. If multiple rules match the same request, **only the first matching rule is applied**. Place more specific rules before broader rules that could match the same traffic.
{% endhint %}

## Example

The following example applies Rate Limiting to `/api/v2` while excluding a trusted service IP from the Page Rule's rate limit:

```
Path: /api/v2
Request Limit: 100
Per: Per Minute
Burst Mode: Burst + No Delay
Burst Value: 20
IP Whitelist: On
Whitelisted IPs:  
  - 203.0.113.5
```

In this example, the configured rate of **100 requests per minute** is enforced continuously for requests matching `/api/v2`.

With **Burst + No Delay**, temporary traffic above the configured rate can use the defined burst capacity, and requests within that capacity can pass immediately without delay.

Requests from `203.0.113.5` bypass the Rate Limit configured for this Page Rule.

{% hint style="info" %}
The Burst Value is not added to the Request Limit as a separate request quota. Burst capacity provides temporary tolerance above the configured rate, and the number of requests accepted during a traffic spike can vary depending on request timing.
{% endhint %}

## Use Cases

* **Protect API endpoints** — Apply specific request rates to paths such as `/api/auth`, `/api/login`, or `/checkout`.
* **Exclude trusted service traffic** — Whitelist trusted service IP addresses that must access a rate-limited endpoint without being subject to the Page Rule's request rate.
* **Control file downloads** — Apply rate limits to file extensions such as `.jpg`, `.pdf`, or `.zip`.
* **Combine path and extension matching** — Apply Rate Limiting to specific file types under paths such as `/reports` or `/downloads`.
* **Control access to static resources** — Apply request rates to resources under `/media/` or `/static/`.
* **Reduce automated traffic** — Apply rate limits to product, category, search, or filter endpoints that may receive excessive automated requests.

## Limitations

* Path & Extension Based Rate Limiting is **Off by default** and must be enabled separately for each Page Rule.
* Resource-level **Rate Limiting must be enabled** before Rate Limiting in a Page Rule can take effect.
* The supported **Request Limit** range is **100–1000**.
* Requests exceeding the permitted rate and available burst capacity are blocked with an **HTTP 429 Too Many Requests** response.


# Custom Error Page

Redirect users to custom pages when specific edge-generated HTTP error responses occur.

Custom Error Page allows you to redirect users to a custom URL when specific HTTP error codes are generated by the CDN edge.

This feature is commonly used to display branded error pages, access restriction notices, or custom user guidance instead of the default CDN error response.

{% hint style="info" %}
Custom Error Page applies only to edge-generated error responses. Errors returned directly by your origin server are not affected.
{% endhint %}

## How It Works

When the CDN generates a configured HTTP error response, it returns a redirect to the specified Error Page URL instead of displaying the default error page.

Each rule consists of three parameters:

| Parameter            | Description                                               |
| -------------------- | --------------------------------------------------------- |
| Status Code          | The HTTP error code that triggers the redirect (400–599). |
| Error Page URL       | The destination URL users are redirected to.              |
| Redirect Status Code | The HTTP redirect status code returned to the browser.    |

Multiple rules can be configured for different HTTP status codes.

## Configure Custom Error Page

In the [Medianova Control Panel](https://cloud.medianova.com), navigate to the CDN Resource and open the **Page Rules** tab.

{% stepper %}
{% step %}

### **Enable Custom Error Page**

Enable the **Status** toggle to activate custom error page handling.

<figure><img src="/files/uwnECRyrZvmXf8IJQ6iY" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### **Specify the Status Code**

Enter the HTTP error code that should trigger the redirect.

Supported values range from `400` to `599`.
{% endstep %}

{% step %}

### **Configure the Error Page URL**

Enter the URL users should be redirected to when the configured error occurs.

Example:

```
https://www.example.com/access-denied.html
```

{% endstep %}

{% step %}

### **Select the Redirect Status Code**

Choose the HTTP redirect code returned to the browser.

Common values include:

* 301 (Permanent Redirect)
* 302 (Temporary Redirect)
  {% endstep %}

{% step %}

### **Save the Configuration**

Click **Submit** to deploy the updated configuration.
{% endstep %}
{% endstepper %}

## Configuration

### Status Code

Defines the edge-generated HTTP status code that triggers the redirect.

Supported values range from `400` to `599`.

### Error Page URL

Defines the URL users are redirected to when the configured status code occurs.

The URL should be publicly accessible and return a valid response.

### Redirect Status Code

Defines the redirect response returned to the client.

Common values include:

| Code | Description        |
| ---- | ------------------ |
| 301  | Permanent redirect |
| 302  | Temporary redirect |

For additional details about redirect responses, see the HTTP Response Codes documentation.

### Example

The following configuration:

* Status Code: `403`
* Error Page URL: `https://www.example.com/access-denied.html`
* Redirect Status Code: `302`

redirects users to a custom access-denied page whenever the CDN generates a 403 response.

## Common Use Cases

### Geo Blocking

Display a custom message when access is restricted based on visitor location.

### IP Restriction

Provide additional information when requests are denied by access control policies.

### Security Controls

Present branded error pages instead of generic CDN error responses generated by edge-level security features.

## Important Notes

* This feature applies only to edge-generated error responses.
* Origin-generated error pages are not affected.
* The Error Page URL must remain accessible to users.
* Redirect loops should be avoided when hosting custom error pages on protected resources.
* Multiple status codes can be mapped to different error pages.


# Compression

Learn all about Gzip and Brotli compression at Medianova, including which content types are compressed by default and compression of error responses.

Gzip and Brotli compression reduces file sizes by up to 80% for common content types like HTML, CSS and JavaScript, leading to faster load times and improved user experience. This not only enhances website performance and improves SEO / Core Web Vitals, but also decreases bandwidth usage, saving CDN costs and ensuring efficient content delivery.

<figure><img src="/files/ZoRUVXIQTUsqKuTmwpNQ" alt=""><figcaption><p>Request/response compression at Medianova</p></figcaption></figure>

### Compression at the Edge

Gzip compression happens at Medianova Midcache servers, which is then passed on to the Edge servers. Both the Midcache and Edge servers may cache the Gzip compressed content for faster delivery of next responses. Edge servers perform Brotli compression on-the-fly when requested by the client.

Medianova delivers content with Gzip compression, Brotli compression or no compression depending on:

* Values of the `Accept-Encoding` header in the request coming into Medianova
* Your Medianova configuration (learn how to configure Gzip and Brotli)

#### Content types

You can customize which content types Medianova serves compressed for Gzip and Brotli, except for content of type `text/html` : this is always compressed.By default, Medianova compresses the following content types:

```
text/html
text/plain
text/css
text/x-component
text/javascript
application/javascript
application/x-javascript
application/json
text/xml
application/xml
application/rss+xml
application/atom+xml
application/rdf+xml
application/xhtml+xml
application/vnd.ms-fontobject
application/x-font
application/x-font-opentype,
application/x-font-otf
application/x-font-truetype
application/x-font-ttf
font/opentype
font/otf
font/ttf
font/woff
font/woff2
image/svg+xml
image/x-icon
application/x-www-form-urlencoded
application/dash+xml
application/x-mpegURL
application/octet-stream
```

#### Status Codes

For responses coming from customer origin server or CDN cache, Medianova performs compression for any status code.Some MN features like Geoblocking may cause MN CDN to serve lightweight, edge-generated error responses and these are always served uncompressed.

#### Minimum response size for compression

If compression is enabled for the requested content type, Medianova applies compression to responses with a minimum size of 400 bytes.

#### Content-Length and No-Transform

Medianova sends compressed responses without the `Content-Length` header to prevent browsers receiving possibly incorrect length information as a result of dynamic transformation.

Sending `Cache-Control: no-transform` on the response from origin has no effect on compression.

### Compression at Origin

Medianova always requests uncompressed content from the customer origin server. The CDN sends no `Accept-Encoding` header to the origin and expects to receive the response uncompressed and without a `Content-Encoding` header.

### FAQ

#### Which compression level does Medianova use for Gzip and Brotli?

MN uses compression level 6 for Gzip and 5 for Brotli. These compression levels provide an optimal balance between compression efficiency and server CPU consumption.

#### After I disable compression, does Medianova continue to serve compressed from cache?

Yes. When a request is first made, Medianova servers cache the content Gzip compressed. If Gzip is later disabled, the already cached Gzip version will still be served unless a purge is performed or the cached object expires.

#### When will Medianova support Zstandard (ZSTD) compression?

Currently, Medianova has no plans for supporting Zstandard-encoded content.


# How to Configure Gzip and Brotli

Step-by-step instructions for how to enable and configure Gzip compression and Brotli compression.

{% hint style="info" %}
We recommend to always turn on Gzip and Brotli compression for small object delivery and dynamic content acceleration. All modern browsers support these content encodings and clients not supporting compression will receive the uncompressed version. Learn more about [compression at Medianova](/products/performance-cdn/static-content-delivery/advanced-configuration/compression).
{% endhint %}

In the [Medianova Panel](https://cloud.medianova.com/), select the appropriate CDN resource, navigate to the **Optimization** tab and select **Text Optimization**.

The page shows two content blocks, one for Brotli Compression and one for Gzip Compression:

<figure><img src="/files/Qfnb9065QZzCzB6C54g9" alt="" width="563"><figcaption></figcaption></figure>

The following steps apply to both Brotli Compression and Gzip Compression.

{% stepper %}
{% step %}
**Toggle the Status to ON**

Click the Status toggle to turn on compression.

{% hint style="info" %}
Changing the toggle does not *immediately* change the CDN's behavior. You need to click **Submit** to push the updated config to the CDN
{% endhint %}
{% endstep %}

{% step %}
**Update the content types (optional)**

The page now shows a list of content types (or: [MIME types](https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/MIME_types)) that are served compressed by default. You can add content types by typing the content-type in the **Add Content Type** field and clicking the **+** button.

Remove a content type by clicking the small **x** icon to the right of the content-type.
{% endstep %}

{% step %}
**Submit the changes**

Click the **Submit** button to push the updated config to the CDN.
{% endstep %}
{% endstepper %}


# HTTP/2

Configure HTTP/2 support to improve connection efficiency and reduce latency for supported clients.

**HTTP/2** improves content delivery performance by allowing multiple requests and responses to be multiplexed over a single connection. This reduces latency, minimizes connection overhead, and improves page load efficiency for supported clients.

You can manage HTTP/2 in the [Medianova Control Panel](https://cloud.medianova.com).

Navigate to the relevant CDN Resource and open the **Protocol Optimization** section.

### Configure HTTP/2

{% stepper %}
{% step %}

### Enable HTTP/2

<figure><img src="/files/VZh0ejXxWFEkQLex4QJ0" alt=""><figcaption></figcaption></figure>

Toggle **HTTP/2** to **On.**
{% endstep %}
{% endstepper %}

### Behaviour

* HTTP/2 is used automatically when supported by the client.
* Multiple requests can be transferred over a single connection.
* Clients that do not support HTTP/2 automatically fall back to earlier HTTP versions.
* This setting affects client-to-CDN communication only.
* Origin communication behavior is not modified by this setting.

### Benefits

* Reduces connection overhead.
* Improves page load performance.
* Reduces latency for websites with many assets.
* Improves network efficiency through multiplexing.

### FAQ

**Do all browsers support HTTP/2?**\
Most modern browsers support HTTP/2. Unsupported clients automatically use an earlier HTTP version

**Does enabling HTTP/2 require application changes?**\
No. HTTP/2 is negotiated automatically between the client and the CDN.

**Does this setting affect communication with the origin server?**\
No. It only controls the protocol used between clients and the CDN edge.


# Stream Management

Learn how to create and manage live stream definitions (SMIL) for your Streaming CDN Resources and Large CDN Resources (Streaming Content Caching with RTMP Push) using the Medianova Control Panel.

Stream Management allows you to create and manage adaptive bitrate (ABR) stream definitions for live streaming resources. A stream definition combines multiple encoded video renditions into a single logical stream, enabling compatible media players to switch between quality levels automatically based on network conditions and device capabilities.

After a stream is configured, Medianova packages the incoming live stream and delivers it using supported adaptive streaming protocols through the global CDN network.

{% hint style="info" %}
Stream Management is available only for live streaming resources configured to receive an RTMP ingest. Before creating a stream, ensure that your streaming resource is active and your encoder is configured to publish to the assigned RTMP endpoint.
{% endhint %}

A stream definition represents a live channel and contains one or more quality profiles. Each profile corresponds to a different encoded bitrate or resolution of the same live stream.

When a viewer starts playback, the media player retrieves the stream manifest and automatically selects the most appropriate rendition based on available bandwidth and playback conditions.

Typical use cases include:

* Live television
* Sports broadcasting
* Webcasts and webinars
* OTT platforms
* Corporate live events

### How Stream Management Works

The following workflow describes how a live stream is processed and delivered.

1. A live encoder publishes the stream using RTMP.
2. Medianova receives the incoming stream through the configured ingest endpoint.
3. Stream Management associates the incoming stream with the configured stream definition.
4. Medianova packages the stream into adaptive streaming formats.
5. Manifest files and media segments are generated.
6. The CDN caches and delivers the content from edge locations to viewers.

The CDN distributes streaming content but does not perform video encoding. Video encoding and bitrate generation are completed by the encoder before the stream reaches the CDN.

### Supported Streaming Protocols

Stream Management supports multiple streaming protocols to provide compatibility across different playback environments. While live streams are ingested using RTMP, viewers receive adaptive HTTP-based streams through one or more playback protocols.

| Protocol                                | Purpose                             | Typical Usage                                                            |
| --------------------------------------- | ----------------------------------- | ------------------------------------------------------------------------ |
| **HLS (HTTP Live Streaming)**           | Primary adaptive streaming protocol | Apple devices, Safari, Smart TVs, OTT platforms, and most modern players |
| **MPEG-DASH**                           | Standards-based adaptive streaming  | Web browsers, Android devices, Smart TVs, and OTT applications           |
| **Microsoft Smooth Streaming**          | Legacy adaptive streaming protocol  | Legacy Microsoft streaming environments                                  |
| **RTMP (Real-Time Messaging Protocol)** | Live stream ingest                  | Used by encoders to publish live streams to Medianova                    |
| **HDS (HTTP Dynamic Streaming)**        | Legacy Adobe streaming protocol     | Legacy Adobe Flash-based deployments                                     |

#### Protocol Roles

Streaming protocols serve different purposes throughout the delivery workflow.

* **RTMP** is used only to ingest the live stream from the encoder.
* **HLS**, **MPEG-DASH**, and **Smooth Streaming** are generated from the incoming stream and delivered to viewers.
* **HDS** is available only for legacy compatibility.

This architecture allows a single live stream to be delivered simultaneously using multiple playback protocols without requiring multiple encoder outputs.


# Website Framework Integrations


# Integrate Magento with Medianova CDN

Learn how to integrate your Magento-based e-commerce website with Medianova CDN to improve load speed and ensure high-performance content delivery.

Medianova provides CDN solutions for leading e-commerce companies in Türkiye to enhance performance, scalability, and customer experience.\
If your website is built on **Magento**, you can configure a CDN integration to serve static and media content faster through Medianova’s global edge network.

{% hint style="info" %}
Before starting, we recommend backing up your Magento files and database.
{% endhint %}

### Prerequisites

* An active **Medianova CDN Resource**
* Access to your **Magento Admin Panel** (Administrator role)
* Optional: A configured **Shared SSL** or **Custom SSL** in the [Medianova Control Panel](https://cloud.medianova.com) if HTTPS is required

### Integration Steps

<figure><img src="https://clients.medianova.com/__attachments/2521268246/image-20231206-180150.png?inst-v=b951364f-998c-42f5-99c8-65d87945d391" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Create a CDN Resource**

* Log in to the **Medianova Control Panel**.
* Create a new **CDN Resource** for your Magento domain.\
  → Once created, copy the Zone URL (for example: `https://example.mncdn.com`).
  {% endstep %}

{% step %}
**Access Magento Configuration**

* Log in to your **Magento Admin Panel**.
* In the left-hand menu, go to **Stores → Configuration**.
* Under the **General** section, select **Web**.
  {% endstep %}

{% step %}
**Configure Base URLs**

* Open the **Base URLs** section.
* In the **Base URL for Static View Files** field, enter your Zone URL followed by `/static/`.\
  Example: `https://example.mncdn.com/static/`
* In the **Base URL for User Media Files** field, enter your Zone URL followed by `/media/`.\
  Example: `https://example.mncdn.com/media/`
  {% endstep %}

{% step %}
**Save and Clear Cache**

* Click **Save Config** to apply the changes.
* Navigate to **System → Cache Management**.
* Select all cache types, click **Submit**, and then choose **Flush Magento Cache**.
  {% endstep %}
  {% endstepper %}

### Verify Integration

After completing these steps, Magento will deliver static and media files via **Medianova CDN**.

{% hint style="info" %}
To confirm integration, check the HTML source code of your website.\
All asset URLs should begin with your CDN Zone domain (for example: `https://example.mncdn.com`).
{% endhint %}

### Optional: Configure HTTPS

If your Magento site uses HTTPS, repeat the Base URL configuration steps for the **Secure** section as well.

{% hint style="info" %}
Ensure that you have configured **Shared SSL** or **Custom SSL** in the Medianova Control Panel before enabling HTTPS.
{% endhint %}

### Troubleshooting

| Problem                            | Cause                                      | Solution                                                                             |
| ---------------------------------- | ------------------------------------------ | ------------------------------------------------------------------------------------ |
| CDN URLs not visible in HTML       | Magento cache not refreshed                | Go to **System → Cache Management** and flush all caches.                            |
| Mixed content warning (HTTP/HTTPS) | HTTPS not configured properly in Medianova | Configure **Shared SSL** or **Custom SSL** before updating secure URLs.              |
| Slow asset delivery                | Zone caching disabled                      | Check the Zone settings in the Medianova Control Panel and ensure caching is active. |


# Integrate WordPress with Medianova CDN

Learn how to integrate WordPress with Medianova CDN to deliver static and media content faster, improve page load times, and enhance your website’s overall performance.

WordPress is one of the world’s most widely used content management systems (CMS), offering flexibility through open-source development, easy setup, and extensive theme and plugin support.\
With **Medianova CDN**, your WordPress site’s static assets—such as images, scripts, and videos—are served from the nearest CDN edge node instead of your origin server, ensuring faster delivery to global users.

{% hint style="info" %}
We recommend backing up your WordPress files and database before starting the integration.
{% endhint %}

### Prerequisites

* Access to your **WordPress Admin Panel**
* A **Medianova CDN Resource** created in the [**Medianova Control Panel**](https://cloud.medianova.com)
* Optional: Separate CDN resources for static images (Small Resource) and large media files such as videos (Large Resource)

### Integration Steps

{% stepper %}
{% step %}
**Create a CDN Resource**

* Log in to the **Medianova Control Panel**.
* Create a **Small Resource** for static assets (e.g., `.jpg`, `.png`) and a **Large Resource** for video files (e.g., `.mp4`).\
  → Copy the CDN URLs of your created resources; they will be used in plugin configuration.
  {% endstep %}

{% step %}
**Install the Medianova CDN Plugin**

* Log in to your **WordPress Admin Panel**.
* In the left-hand menu, go to **Plugins → Add New**.
* In the search bar, type **Medianova** and press **Enter**.
* Install the **Medianova CDN** plugin and click **Activate**.
  {% endstep %}

{% step %}
**Configure the Plugin**

* After activation, go to **Settings → CDN Medianova** from the left menu.
* Enter your **CDN URLs**, specify the **folders to include**, and list **file extensions to exclude**.
* Click **Save Changes** to apply your configuration.
  {% endstep %}
  {% endstepper %}

### Tips and Best Practices

* To include multiple file extensions, separate them with commas (`,`).\
  Example: `jpg, png, gif, svg`
* You can view your CDN Resource URLs in the **Medianova Control Panel** under **CDN → Resources** or by visiting [Medianova CDN Integration Docs](https://docs.medianova.com/en/medianova-cdn-user-integration/).

### Troubleshooting

| Problem                              | Cause                                      | Solution                                                                                             |
| ------------------------------------ | ------------------------------------------ | ---------------------------------------------------------------------------------------------------- |
| CDN URLs not applied to static files | Plugin not configured or cache not cleared | Recheck the **CDN URLs** in plugin settings and clear the WordPress cache.                           |
| Site shows mixed content warnings    | HTTPS not enabled on CDN resource          | Configure **Shared SSL** or **Custom SSL** in the **Medianova Control Panel** before enabling HTTPS. |
| CDN plugin not found in search       | Outdated WordPress version                 | Update WordPress to the latest version and try again.                                                |


# Integrate Phalcon with Medianova CDN

Learn how to integrate Phalcon, a high-performance PHP framework, with Medianova CDN to serve static assets efficiently and enhance website performance.

Phalcon is an open-source PHP framework designed for speed and efficiency.\
Unlike traditional PHP frameworks, Phalcon is implemented as a C extension, providing exceptional execution performance with MVC architecture support.

This guide explains multiple integration methods for connecting Phalcon-based applications with **Medianova CDN** to deliver static files (CSS, JS, images) from the nearest CDN edge.

{% hint style="info" %}
Before integration, back up your project files and database.
{% endhint %}

### Prerequisites

* A configured **CDN Resource**
* Access to the Phalcon project source code
* PHP 7.4 or later (recommended)

### Integration Methods

{% stepper %}
{% step %}
**Use `setStaticBaseUri`**

The simplest way to integrate your Phalcon application with Medianova CDN is by defining a static base URI.\
This approach ensures that dynamic content stays on your origin, while static files (CSS, JS, images) are delivered via CDN.

```php
<?php

$url = new Phalcon\Mvc\Url();

// Dynamic URIs remain on your origin server
$url->setBaseUri('/');

// Static resources go through Medianova CDN
$url->setStaticBaseUri('https://<CDN_ZONE_URL>/');

```

{% hint style="info" %}
Replace `<CDN_Resource_URL>` with your actual CDN Resource URL (for example: `https://example.mncdn.com/`).
{% endhint %}
{% endstep %}

{% step %}
**Use Asset Collections with Conditional CDN Prefix**

For more granular control, you can configure your asset collections to automatically switch between development and production environments.

```php
<?php

$css = $this->assets->collection('header');
$scripts = $this->assets->collection('footer');

if ($config->environment == 'development') {
    $css->setPrefix('/');
    $scripts->setPrefix('/');
} else {
    $cdnURL = 'https://<CDN_ZONE_URL>/';
    $css->setPrefix($cdnURL);
    $scripts->setPrefix($cdnURL);
}

$css->addCss('css/bootstrap.min.css')
    ->addCss('css/custom.css');

$scripts->addJs('js/jquery.js')
    ->addJs('js/bootstrap.min.js');

```

{% hint style="info" %}
This method allows you to automatically use local assets in development and CDN-prefixed URLs in production.
{% endhint %}
{% endstep %}

{% step %}
**Direct CDN Path in Asset Definition**

You can also directly define CDN-prefixed URLs when adding assets to your project.

```php
<?php
$cdnURL = 'https://<CDN_ZONE_URL>/';
$this->assets
     ->addCss($cdnURL . 'css/custom.css', false);
```

{% endstep %}

{% step %}
**Verify CDN Integration**

After applying one of the methods above:

1. Deploy your changes to the web server.
2. Open your website in a browser.
3. View the HTML source (`Ctrl + U`) and confirm that static file URLs begin with your **CDN Resource** domain.

{% hint style="info" %}
Example:\
`https://example.mncdn.com/css/bootstrap.min.css`
{% endhint %}
{% endstep %}
{% endstepper %}

### Troubleshooting

| Problem                                     | Cause                                                     | Solution                                                                                                                           |
| ------------------------------------------- | --------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- |
| **Assets are still served from the origin** | The CDN prefix is not applied in code.                    | Verify that `setStaticBaseUri()` or `$css->setPrefix()` includes your correct CDN Resource URL.                                    |
| **Invalid asset paths**                     | The CDN prefix or local directory structure is incorrect. | Check the path structure inside your assets directory and ensure the CDN path matches the file hierarchy.                          |
| **SSL-related warnings**                    | HTTPS not enabled on CDN resource.                        | Enable **Shared SSL** or **Custom SSL** in the [**Medianova Control Panel**](https://cloud.medianova.com) before using HTTPS URLs. |


# Integrate CakePHP with Medianova CDN

Learn how to integrate CakePHP with Medianova CDN to deliver static assets such as images, CSS, and JavaScript files faster and improve website performance.

**CakePHP** is an open-source PHP framework based on the MVC (Model-View-Controller) pattern, similar to Zend, Laravel, and Symfony.\
This guide explains how to configure **Medianova CDN** for **CakePHP version 2.4 and later**, enabling your application to serve static content from the nearest CDN edge node instead of the origin server.

{% hint style="info" %}
Before starting the integration, back up your CakePHP project files and database.
{% endhint %}

### Prerequisites

* A configured **CDN Resource**.
* A running **CakePHP 2.4+** application
* Write access to your `./Config/bootstrap.php` file

### Integration Steps

{% stepper %}
{% step %}
**Create a CDN Resource**

* Log in to the [**Medianova Control Panel**](https://cloud.medianova.com).
* Create a new **CDN Resource** for your application.
* Copy your Resource URL (for example: `https://example.mncdn.com/`).
  {% endstep %}

{% step %}
**Define CDN Base URLs**

* Open the configuration file:\
  \&#xNAN;**`./Config/bootstrap.php`**
* Add the following variables to define Medianova CDN paths for your assets:

```php
<?php
Configure::write('App.imageBaseUrl', 'https://<CDN_ZONE_URL>/img/');
Configure::write('App.cssBaseUrl',   'https://<CDN_ZONE_URL>/css/');
Configure::write('App.jsBaseUrl',    'https://<CDN_ZONE_URL>/js/');
```

{% hint style="info" %}
Replace `<CDN_RESOURCE_URL>` with your actual CDN Resource address, such as `https://example.mncdn.com/`.
{% endhint %}
{% endstep %}

{% step %}
**Use the HTML Helper for Images**

Use the `HtmlHelper::image()` function to generate image URLs automatically through the CDN.

```php
<?php echo $this->Html->image('medianova-logo.png', ['alt' => 'Medianova Logo']); ?>
```

**Output:**

```html
<img src="https://example.mncdn.com/img/medianova-logo.png" alt="Medianova Logo" />
```

{% endstep %}

{% step %}
**Use the HTML Helper for CSS Files**

To load your CSS files from the CDN, use the `HtmlHelper::css()` function:

```php
<?php echo $this->Html->css('style.css'); ?>
```

**Output:**

```html
<link rel="stylesheet" type="text/css" href="https://example.mncdn.com/css/style.css" />
```

{% endstep %}

{% step %}
**Use the HTML Helper for JavaScript Files**

To load JavaScript assets from the CDN, use the `HtmlHelper::script()` function:

```php
<?php echo $this->Html->script('script.js'); ?>
```

**Output:**

```html
<script type="text/javascript" src="https://example.mncdn.com/js/script.js"></script>
```

{% endstep %}

{% step %}
**Verify Integration**

* Save your configuration and clear the CakePHP cache.
* Open your website in a browser and view the HTML source (`Ctrl + U`).
* Confirm that image, CSS, and JS assets are loaded from your **Medianova CDN Resource**.

{% hint style="info" %}
Example:\
`https://example.mncdn.com/css/style.css`
{% endhint %}
{% endstep %}
{% endstepper %}

### Troubleshooting

| Problem                                      | Cause                                               | Solution                                                                                             |
| -------------------------------------------- | --------------------------------------------------- | ---------------------------------------------------------------------------------------------------- |
| **Assets still load from the origin server** | CDN URLs not defined or configuration not reloaded. | Check the `bootstrap.php` entries and clear the CakePHP cache.                                       |
| **Assets missing or 404 errors**             | Incorrect CDN path or directory mismatch.           | Verify that your `img`, `css`, and `js` directories match the structure in your CDN Resource.        |
| **Mixed content warning (HTTP/HTTPS)**       | HTTPS not enabled on CDN resource.                  | Enable **Shared SSL** or **Custom SSL** in the **Medianova Control Panel** before using secure URLs. |


# Analytics

Static CDN is primarily used for delivering fixed content, such as images, CSS files, and JavaScript files. These resources are typically unchanged, which allows for faster delivery through a CDN. The Static CDN Analytics section provides key metrics that help monitor, analyze, and optimize the performance of static content delivery. These metrics focus on the caching effectiveness, the amount of traffic being served from the cache versus the origin server, and the overall bandwidth usage.

### **Traffic**

* **Total Traffic**: This chart displays the total amount of traffic delivered during a selected time range. Users can view the traffic over a **custom time range** or compare it with the **previous time range** to understand the trends and fluctuations in traffic. A significant increase in traffic indicates that the content is being accessed more frequently, which can be beneficial for scaling infrastructure and improving cache efficiency.

<figure><img src="/files/c72dHXOPmCD0dCgb4H26" alt=""><figcaption></figcaption></figure>

* **Traffic in Time**: This chart provides insights into traffic variations over time. By analyzing traffic patterns, you can identify spikes in demand, possibly caused by promotions, seasonal events, or viral content. It also helps determine when content delivery peaks, assisting in optimizing server performance during high-traffic periods.

<figure><img src="/files/iGMzYxitHaWlyEf9koe5" alt=""><figcaption></figcaption></figure>

* **Cached vs Non-Cached**: This chart compares traffic served from the cache versus traffic retrieved from the origin server. High cache traffic indicates that most of the data is being served efficiently from the CDN, reducing load on the origin server and speeding up delivery to end-users. A low cache hit ratio might indicate a need for better cache configuration or optimization.

<figure><img src="/files/UJiyaJLWeqUpuh9cWu1x" alt=""><figcaption></figcaption></figure>

* **Cached Data**: This chart shows the breakdown of cached data into hits, updating, and stale categories:
  * **Hits**: Content successfully retrieved from the cache.
  * **Updating**: Content that is currently being updated in the cache.
  * **Stale**: Content served from the cache that is outdated because the origin server did not respond in time.\
    These metrics are crucial for understanding cache freshness and the efficiency of the content delivery process.

<figure><img src="/files/Pq5bhkPHkxmgEp1hRQXW" alt=""><figcaption></figcaption></figure>

* **Non-Cached Data**: This chart shows the amount of data retrieved from the origin server, broken down into **miss** and **expired** categories:
  * **Miss**: Content that was not found in the cache and had to be fetched from the origin server.
  * **Expired**: Cached content that has expired and needs to be fetched again from the origin server.\
    A higher proportion of non-cached data suggests that caching is not being utilized effectively, which could lead to higher latency and bandwidth usage.

<figure><img src="/files/2RhttT0akBfnCuEggkA5" alt=""><figcaption></figcaption></figure>

### **Bandwidth**

* **Bandwidth**: This chart shows the total bandwidth used for delivering static content. High bandwidth usage might indicate large file sizes or a high volume of requests, which can be optimized through compression, better cache utilization, or content delivery strategies.

<figure><img src="/files/mB7UzeGkxio2weBQ55Sl" alt=""><figcaption></figcaption></figure>

* **Cached vs Non-Cached**: This chart compares the bandwidth used for cached versus non-cached data. Ideally, cached data should consume most of the bandwidth, as it reduces the need for repetitive fetching from the origin server, resulting in faster load times and reduced network strain.

### **Requests**

* **Total Requests**: This chart displays the total number of requests made for static content. A high number of requests indicates active content consumption, which is useful for monitoring content popularity and server load.

<figure><img src="/files/GiJehLSN2kEeuTN7fCiz" alt=""><figcaption></figcaption></figure>

* **Hits vs Misses**: This chart compares the number of requests that resulted in a cache hit versus a cache miss. A higher hit ratio is ideal, as it indicates that the CDN is effectively serving content from the cache, reducing the need to contact the origin server.

<figure><img src="/files/Wkd6Z58pnywQ6FrKyJ7x" alt=""><figcaption></figcaption></figure>

* **Request Hits**: This chart shows detailed information on hits, broken down into hit, updating, stale, and revalidated categories:
  * **Updating**: The content is in the process of being updated.
  * **Stale**: The content is outdated and served while awaiting a response from the origin server.
  * **Revalidated**: The cached content has been successfully revalidated with the origin server and is now fresh.\
    These metrics provide insights into the cache's efficiency and freshness.

<figure><img src="/files/MU6lsVl7n61u1Wsrl5oi" alt=""><figcaption></figcaption></figure>

* **Request Misses**: This chart shows detailed information on misses, broken down into **miss** and **expired** categories:
  * **Miss**: The content was not found in the cache and was fetched from the origin server.
  * **Expired**: The cached content expired and had to be retrieved from the origin server again.\
    Analyzing this data helps in understanding the reasons for cache misses and optimizing cache configurations.

<figure><img src="/files/zSiuz7TSYjmK85PuK2e7" alt=""><figcaption></figcaption></figure>

#### **Tier Filter**

A **Tier Filter** dropdown is available next to the **All Resources** selector.\
This filter defines which CDN layers are included in the request data.

<table><thead><tr><th width="175">Option</th><th>Description</th></tr></thead><tbody><tr><td><strong>Edge only</strong> <em>(default)</em></td><td>Displays requests from end users. Excludes internal CDN tiers.</td></tr><tr><td><strong>All</strong></td><td>Displays total requests from <strong>Edge + Mid + Origin</strong> layers. May include repeated counts of the same request across tiers.</td></tr></tbody></table>

Tooltips appear on hover for desktop and via an **info icon** on mobile.\
The selected filter is also reflected in exported reports.

**Example report titles:**\
Requests *- Edge only*\
Requests - *All*

**API parameter:**\
`tier=edge` or `tier=all` (default = `edge`)

### **Status Codes**

* **Total Requests**: This chart displays the total number of requests, helping you track overall activity and performance.
* **Status Code Structure**: This chart compares the distribution of different HTTP status codes:
  * **2xx**: Successful responses (e.g., 200 OK).
  * **3xx**: Redirects (e.g., 301, 302).
  * **4xx**: Client errors (e.g., 404, 403).
  * **5xx**: Server errors (e.g., 500, 502).\
    Monitoring these status codes helps identify potential issues in content delivery and client-side or server-side errors.

<figure><img src="/files/dwNVidjIWEdWYlYt3wlw" alt=""><figcaption></figcaption></figure>

* **Successful Responses (2xx)**: This chart shows the distribution of successful responses, particularly focusing on the 200 OK code and other 2xx codes. High 2xx responses indicate that the CDN is successfully delivering content.

<figure><img src="/files/Kxbyq3AXRqLlXHm63Ysk" alt=""><figcaption></figcaption></figure>

* **Redirects (3xx)**: This chart displays the distribution of redirect codes (301, 302, etc.). Redirects can indicate changes in content location, which should be minimized for optimal performance.

<figure><img src="/files/seJv9nWjfr4EJBzHaNSJ" alt=""><figcaption></figcaption></figure>

* **Client Errors (4xx)**: This chart shows errors on the client side, such as 403 (Forbidden), 404 (Not Found), and 429 (Too Many Requests). A high number of client errors suggests that users are requesting unavailable content or facing access issues.

<figure><img src="/files/zXTpKVibi1sZUts31gXY" alt=""><figcaption></figcaption></figure>

* **Server Errors (5xx)**: This chart shows server-side errors, such as 500 (Internal Server Error), 502 (Bad Gateway), and 504 (Gateway Timeout). These errors indicate issues on the origin server and require attention to ensure smooth content delivery.

<figure><img src="/files/u0209Le6N5Vhe9nWcGVJ" alt=""><figcaption></figcaption></figure>

#### **Tier Filter**

Status code metrics also reflect the selected **Tier Filter**.\
You can view codes for **Edge only** or include **All CDN tiers**.\
When *All* is selected, totals may increase because the same request can appear multiple times across tiers.

**Exported reports** and visual charts indicate the active filter in their titles.\
**API parameter:** `tier=edge` or `tier=all` (default = `edge`)

### **Error Logs**

Error logs provide a detailed record of requests that resulted in errors. By selecting a specific error code, users can view logs that include the request path, method, protocol, and hit status. The logs are invaluable for identifying patterns and resolving recurring issues in content delivery.

<figure><img src="/files/GjBpaIUaaDW1IM9tp3tn" alt=""><figcaption></figcaption></figure>

#### **Tier Filter**

The **Tier Filter** applies to all error log data.\
Users can toggle between **Edge only** and **All**, depending on whether they want to see only end-user–level errors or logs from all CDN layers.

{% hint style="success" %}
Selecting *Edge only* isolates actual user errors, while *All* shows cumulative errors from Edge, Mid, and Origin.
{% endhint %}

**API parameter:** `tier=edge` or `tier=all`\
**Default:** `edge`


# Dynamic Content Acceleration

Accelerate personalized, database-driven, or API-based content with Medianova’s Dynamic CDN. Cache dynamic responses at the edge to reduce origin load and deliver faster user experiences.

Accelerate personalized, database-driven, or API-based content with Medianova’s Dynamic CDN. Cache dynamic responses at the edge to reduce origin load and deliver faster user experiences.

Dynamic Content Acceleration improves the delivery of content that is generated by an application rather than served as static files. Unlike images, JavaScript, or CSS, dynamic responses are created in real time and often depend on user sessions, request parameters, application logic, or backend data.

Medianova's Dynamic CDN reduces response times by combining intelligent request routing, edge caching, optimized origin communication, and configurable cache policies. These capabilities improve application performance while maintaining content freshness.

<figure><img src="/files/mlRfogUeKKwqhJ8fptSB" alt=""><figcaption><p>Dynamic Content Acceleration using a Dynamic CDN Resource</p></figcaption></figure>

## How dynamic content differs from static content

Static content can typically be cached for long periods because it rarely changes. Examples include:

* Images
* CSS
* JavaScript
* Fonts
* Downloadable files

Dynamic content is generated by the origin application when a request is received. Responses may vary depending on:

* User authentication
* Session data
* Cookies
* Query parameters
* API requests
* Database queries
* Geographic location

Because responses can change frequently, Dynamic CDN applies configurable caching policies instead of long-term edge caching.

{% hint style="info" %}
Dynamic Content Acceleration is intended for content that changes frequently but does not necessarily require regeneration for every request.
{% endhint %}

## How Dynamic Content Acceleration works

When a request reaches the CDN, the edge server evaluates the configured cache policy before contacting the origin.

1. A client sends a request to the nearest Medianova edge server.
2. The CDN evaluates the request and checks whether a valid cached response is available.
3. If a cached response exists, the edge server returns it immediately.
4. If no valid cache entry exists, the request is forwarded to the origin.
5. The origin generates the response.
6. The CDN caches the response according to the configured policy.
7. Subsequent requests can be served directly from the edge until the cache expires.

This approach reduces origin traffic while maintaining up-to-date application content.

## Acceleration techniques

Dynamic Content Acceleration combines multiple optimization techniques to improve response times and reduce backend load.

#### Microcaching

Caches dynamic responses for very short durations, typically a few seconds. This significantly reduces repeated requests during traffic spikes while preserving data freshness.

#### Full Page Caching

Caches complete HTML pages for applications where pages do not change for every user or request.

#### API Response Caching

Caches API responses based on configurable cache policies, reducing repeated backend processing for frequently requested endpoints.

#### Edge-based delivery

Serves cached responses directly from the nearest CDN edge location, reducing latency for end users.

#### Optimized origin communication

Reuses and optimizes connections between edge servers and origins to reduce connection overhead and improve cache-miss performance.

#### Configurable cache policies

Allows different cache durations and behaviors for specific URLs, API endpoints, or application paths.

## Typical use cases

Dynamic Content Acceleration is commonly used for applications that generate content on demand, including:

* E-commerce platforms
* Product catalogs
* CMS-driven websites
* Customer dashboards
* Search results
* Pricing services
* REST APIs
* GraphQL APIs
* News portals
* SaaS applications

## Best practices

To achieve the best balance between performance and content freshness:

* Cache only responses that can be safely reused.
* Exclude personalized and transactional pages from caching.
* Use short TTL values for frequently updated content.
* Configure Page Rules for endpoint-specific cache behavior.
* Monitor cache hit ratios and adjust cache policies as application behavior changes.
* Combine Dynamic CDN with WAF and Rate Limiting to improve both performance and security.

## Related features

Dynamic Content Acceleration works together with several Dynamic CDN capabilities.

<table><thead><tr><th width="212.6666259765625">Feature</th><th>Purpose</th></tr></thead><tbody><tr><td>Page Rules</td><td>Apply different cache behaviors to specific URLs or application paths.</td></tr><tr><td>Browser Cache Rules</td><td>Control how browsers cache dynamic responses.</td></tr><tr><td>Edge Cache Expiration</td><td>Configure how long responses remain cached at CDN edge locations.</td></tr><tr><td>Query String Caching</td><td>Define whether query parameters create separate cache entries.</td></tr><tr><td>Compression</td><td>Reduce response sizes before delivery.</td></tr><tr><td>WAF</td><td>Protect applications from common web attacks.</td></tr><tr><td>Rate Limiting</td><td>Control excessive or abusive traffic.</td></tr></tbody></table>

## Configure a Dynamic CDN Resource

To use Dynamic Content Acceleration, create a [**Dynamic CDN Resource**](/products/performance-cdn/dynamic-content-acceleration/create-dynamic-resource) in the [**Medianova Control Panel**](https://cloud.medianova.com).

The configuration process includes:

* Defining the origin server
* Configuring SSL/TLS
* Setting cache behavior
* Applying Page Rules
* Configuring security features

Continue with [**Create Dynamic Resource**](/products/performance-cdn/dynamic-content-acceleration/create-dynamic-resource) to configure a new Dynamic CDN Resource.


# Create Dynamic Resource

Learn how to create a Dynamic CDN Resource for dynamic websites, APIs, and personalized content.

A **Dynamic Resource** uses **Aksela**, Medianova's dynamic content acceleration platform, to optimize the delivery of HTML pages, APIs, and other frequently changing content.

By operating between your origin server and end users, Aksela reduces origin load through micro-caching while improving response times and applying CDN acceleration, connection optimization, and security features at the edge. Additional protection can be provided through the Web Application Firewall (WAF).

### When to Use a Dynamic Resource

Use a Dynamic Resource for:

* Dynamic websites
* HTML page delivery
* REST and GraphQL APIs
* Personalized or frequently changing content
* Micro-caching of cacheable dynamic responses
* Applications that benefit from origin acceleration

{% hint style="info" %}
For images, CSS, JavaScript, web fonts, and other static assets, use a [**Small CDN Resource**](/products/performance-cdn/static-content-delivery/create-small-cdn-resource).
{% endhint %}

{% hint style="info" %}
For large downloadable files or live streaming workloads, use a [**Large CDN Resource**](/products/performance-cdn/static-content-delivery/create-large-cdn-resource).
{% endhint %}

{% hint style="info" %}
For on-demand video that requires adaptive bitrate packaging, use a [**VOD Resource**](/products/performance-cdn/static-content-delivery/create-vod-resource).
{% endhint %}

{% hint style="warning" %}
Your **Website URL** and **Origin URL** should not be identical.

If your origin is configured by IP address instead of hostname, configure the appropriate **Host Header** after creating the Dynamic Resource so that your origin receives the expected hostname.

If your DNS provider does not support root-domain CNAME records, use a subdomain (for example, `www.example.com`) or an **ANAME** or **ALIAS** record if supported by your DNS provider.
{% endhint %}

If your origin is configured by IP address instead of hostname, configure the appropriate **Host Header** after creating the Dynamic Resource so that your origin receives the expected hostname.

If your DNS provider does not support root-domain CNAME records, use a subdomain (for example, `www.example.com`) or an **ANAME** or **ALIAS** record if supported by your DNS provider.

## Create a Dynamic Resource

Create and manage **Dynamic CDN Resources** from the [**Medianova Control Panel**](https://cloud.medianova.com).

Navigate to **CDN** and select **Create CDN Resource** to launch the **Create CDN** wizard.

{% stepper %}
{% step %}

### Select the Resource Type

Navigate to **CDN** and click **Create CDN Resource**.

The **Create CDN** wizard opens.

<figure><img src="/files/Xmihid45FOOVNI3Knoys" alt=""><figcaption></figcaption></figure>

Select **Dynamic CDN**, then click **Create** to continue.
{% endstep %}

{% step %}

### Name the Resource

Provide the information used to identify the Dynamic Resource.

#### Resource Name

Enter a unique resource name.

The resource name becomes part of the default CDN hostname.

Example:

```
example.sm.mncdn.com
```

#### Internal Label (Optional)

Optionally assign a private label to help your team identify and manage the resource.

Internal labels are used only within the Control Panel and for API filtering. They do not affect the public CDN hostname.

Click **Next**.
{% endstep %}

{% step %}

### Configure Your Source

Specify where Aksela should retrieve your application content.

#### Website URL

Enter the public website URL that users will access through the CDN.

This hostname represents the website accelerated by the Dynamic Resource.

#### Customer Origin

Dynamic Resources retrieve content from your own origin infrastructure.

Click **Add Origin** to configure one or more origin servers.

The origin list displays:

<table><thead><tr><th width="140.3333740234375">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Host</strong></td><td>Origin hostname or IP address.</td></tr><tr><td><strong>Protocol</strong></td><td>HTTP or HTTPS used for CDN-to-origin communication.</td></tr><tr><td><strong>Priority</strong></td><td>Determines the order in which origins are selected.</td></tr><tr><td><strong>Weight</strong></td><td>Controls traffic distribution between origins with the same priority.</td></tr></tbody></table>

Multiple origins can be configured to improve availability.

#### Add Origin

Configure the origin server using the following fields.

<table><thead><tr><th width="219">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Protocol</strong></td><td>HTTP or HTTPS used when connecting to the origin.</td></tr><tr><td><strong>Domain or IP Address</strong></td><td>Hostname or IP address of the origin server.</td></tr><tr><td><strong>HTTP Port</strong></td><td>Port used for HTTP connections.</td></tr><tr><td><strong>HTTPS Port</strong></td><td>Port used for HTTPS connections.</td></tr><tr><td><strong>Host Header</strong> <em>(Optional)</em></td><td>Overrides the Host header sent to the origin server.</td></tr><tr><td><strong>Origin SNI Request</strong> <em>(Optional)</em></td><td>Specifies the hostname presented during the TLS handshake with the origin.</td></tr><tr><td><strong>Priority</strong></td><td>Determines the order in which origins are selected.</td></tr><tr><td><strong>Weight</strong></td><td>Controls traffic distribution between origins with the same priority.</td></tr></tbody></table>

#### S3 Presigned Authentication (Optional)

Enable **S3 Presigned Authentication** when the origin is an Amazon S3-compatible storage service that requires Signature Version 4 authentication.

Configure the following fields:

<table><thead><tr><th width="287">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Access Key</strong></td><td>Access key used to authenticate requests.</td></tr><tr><td><strong>Secret Key</strong></td><td>Secret key associated with the access key.</td></tr><tr><td><strong>Region</strong></td><td>AWS region containing the bucket.</td></tr><tr><td><strong>Bucket Name</strong></td><td>Name of the bucket containing the objects.</td></tr></tbody></table>

Click **Next**.
{% endstep %}

{% step %}

### Configure SSL/TLS

Choose how HTTPS should be configured for the Dynamic Resource.

Available options:

* **Use Existing SSL**
* **Add Own SSL**
* **Free SSL**
* **Skip for Now**

#### Use Existing SSL

Assign an SSL certificate that already exists in your account.

Only certificates available in the current account are listed.

#### Add Own SSL

Upload or paste your own certificate and private key.

Supported methods:

* Domain SSL
* Paste `.crt` and `.key`
* Upload Files
* `.pfx` / PKCS#12

For certificate upload and domain configuration, see [**CNAME & SSL**](/products/performance-cdn/static-content-delivery/advanced-configuration/cname-and-ssl).

#### Free SSL

Request a free Let's Encrypt certificate using DNS validation.

Coverage options:

* Single Domain
* Wildcard

Wildcard certificates require CNAME validation.

For the complete provisioning process, see [**Use Free SSL Certificates**](/products/security/ssl-tls-encryption/use-free-ssl-certificates).

#### Skip for Now

Continue without assigning a dedicated certificate.

The default CDN hostname remains accessible over HTTPS using Medianova's shared certificate. A dedicated certificate can be assigned later from **Settings →** [**SSL & TLS**](/products/security/ssl-tls-encryption).

For [Upload and Manage SSL Certificates](/products/security/ssl-tls-encryption/upload-and-manage-ssl-certificates)

Click **Next**.
{% endstep %}

{% step %}

### Review & Activate

Review the configuration before creating the Dynamic Resource.

The summary includes:

* Resource information
* Source configuration
* SSL/TLS configuration
* Deployment information

When the configuration is valid, click **Create Resource**.

Dynamic Resources are typically provisioned within **30 seconds**.
{% endstep %}
{% endstepper %}

## Validate Dynamic Delivery

Verify connectivity by requesting an existing page through the CDN hostname.

```c
curl -svo /dev/null "https://example.sm.mncdn.com/" --compressed
```

Replace `example.sm.mncdn.com` with your Dynamic Resource hostname.

The command sends an HTTP `GET` request to the CDN, displays the connection details and HTTP request and response headers, and discards the response body.

Use a URL that returns **HTTP 200 OK**. If a custom CNAME is configured, validate the custom hostname instead of the default MNCDN hostname.

## Troubleshooting

If the resource does not serve content correctly:

* Verify that the origin server is reachable.
* Confirm that the configured HTTP or HTTPS ports are accessible.
* Verify that the Website URL and Origin URL are configured correctly.
* Confirm that custom CNAME records have propagated before testing the custom hostname.
* Verify that the assigned SSL certificate is active and covers the requested domain.
* If S3 Presigned Authentication is enabled, verify the configured access key, secret key, region, and bucket name.


# Integrating Dynamic CDN Resource

After [creating a Dynamic CDN Resource](/products/performance-cdn/dynamic-content-acceleration/create-dynamic-resource), configure caching, SSL, and DNS before directing production traffic through the CDN.

{% hint style="info" %}
Before updating your DNS records, verify that your [Dynamic CDN Resource](/products/performance-cdn/dynamic-content-acceleration/create-dynamic-resource) is working correctly.
{% endhint %}

## Configure caching

Configure how the CDN caches dynamic and static content.

{% stepper %}
{% step %}

### Open your Dynamic CDN Resource and select the Caching tab.

<figure><img src="/files/vdizs1B26h9SPbIxMrO2" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}

### **Configure the Cache Settings section.**

Select one of the following cache types:

* **Origin** — Uses the `Cache-Control` headers returned by your origin server.
* **Edge** — Uses a cache duration configured in the CDN.

<figure><img src="/files/ICCWMqnxuy8UVBJoUTH1" alt=""><figcaption></figcaption></figure>

If you select **Edge**, specify:

* **Cache Expiration**
* Whether to **Cache Dynamic Pages**

Save your changes.
{% endstep %}

{% step %}

### Configure [Query String Caching](/products/performance-cdn/static-content-delivery/advanced-configuration/caching/query-string-caching).

<figure><img src="/files/ZlhbhbYTSocqdn88cNKG" alt=""><figcaption></figcaption></figure>

Choose whether query strings create separate cache entries or are ignored during caching.
{% endstep %}
{% endstepper %}

## Exclude sensitive pages from caching

If **Cache Dynamic Pages** is enabled, HTML pages can also be cached.

Exclude pages containing personalized or sensitive information, such as:

* User account pages
* Checkout pages
* Payment pages
* Profile pages

You can bypass caching using one of the following methods:

### Option 1: Configure Page Rules

Create a [**Page Rule**](/products/performance-cdn/static-content-delivery/advanced-configuration/page-rules) that sets the appropriate cache behavior for specific paths or URL patterns.

### Option 2: Configure Cookie Based Cache Bypass

Configure [**Disallow Cookie Based Cache**](/products/performance-cdn/dynamic-content-acceleration/advanced-configuration/caching/disallow-cookie-base-cache) in the **Caching** tab.

<figure><img src="/files/TuV9FMNB4hbKQ1qVigjd" alt="" width="563"><figcaption></figcaption></figure>

Specify the cookie name and value that identify requests which should always be served from the origin.

## Configure SSL

Upload or assign an [SSL certificate](/products/security/ssl-tls-encryption) from the **SSL** tab.

<figure><img src="/files/GMV0b4BoBlg1JaZdCv6x" alt="" width="563"><figcaption></figcaption></figure>

Your custom domain should use a valid certificate before production traffic is routed through the CDN.

## Test the CDN configuration

Before updating DNS, verify that requests are served through the CDN.

{% stepper %}
{% step %}

### Find the IP address of your CDN hostname.

Example:

```c
ping <CDN_HOSTNAME>.mncdn.com
```

{% endstep %}

{% step %}

### Update your local hosts file

Temporarily map your domain to the CDN IP address by editing your local **hosts** file.

This allows you to test the website without changing public DNS records.
{% endstep %}

{% step %}

### Verify CDN response headers

Clear your browser cache and open your website.

Inspect the response headers in your browser's Developer Tools.

Verify that the response contains the following header:

```c
Server: MNCDN
```

This confirms that the request is being served through the Medianova CDN.
{% endstep %}
{% endstepper %}

## Update your DNS

After testing completes successfully, create a CNAME record that points your domain to the CDN hostname.

Example:

```
yourdomain.com    IN    CNAME    <CDN_HOSTNAME>.mncdn.com
```

DNS propagation times depend on your DNS provider and configured TTL values.

### Verify production traffic

After DNS propagation completes:

* Confirm that requests are reaching the CDN.
* Verify that SSL is functioning correctly.
* Review cache behavior using the response headers.
* Monitor requests from the [**Analytics**](/products/performance-cdn/dynamic-content-acceleration/analytics) dashboard.


# Test a Dynamic CDN Resource

Learn how to verify that your Dynamic CDN Resource is working correctly before updating your DNS records.

After configuring your Dynamic CDN Resource, verify that requests are served through the Medianova CDN before directing production traffic to the resource.

{% hint style="info" %}
This procedure temporarily modifies your local hosts file for testing purposes. Public DNS records are not affected.
{% endhint %}

{% stepper %}
{% step %}

### Retrieve the CDN IP address

Open a command prompt or terminal.

Run the following command using your Dynamic CDN Resource hostname.

```
ping <CDN_HOSTNAME>.mncdn.com
```

→ Record the returned IP address.
{% endstep %}

{% step %}

### Configure your local hosts file

Open the local **hosts** file with administrator privileges.

Add a new entry that maps your domain to the CDN IP address.

Example:

```
203.0.113.10    www.example.com
```

Replace the IP address and domain with your own values.

Save the file.
{% endstep %}

{% step %}

### Verify CDN delivery

Clear your browser cache.

Open your website using its normal domain.

Open the browser's Developer Tools and navigate to **Network**.

Select the HTML document and review the **Response Headers**.

Verify that the response contains:

```
Server: MNCDN
```

→ This confirms that the HTML response is being served through the Dynamic CDN Resource.
{% endstep %}
{% endstepper %}

### Next step

After verifying that the Dynamic CDN Resource is serving requests correctly, create a [CNAME record](/products/performance-cdn/static-content-delivery/advanced-configuration/cname-and-ssl) that points your domain to the CDN hostname.


# Advanced Configuration

Configure origin behavior, caching, headers, and delivery controls for Dynamic CDN Resources.

Fine-tune how your Dynamic CDN Resource connects to the origin and delivers content. Select a configuration area to continue.

<table data-view="cards"><thead><tr><th>Configuration area</th><th data-card-target data-type="content-ref">Learn more</th></tr></thead><tbody><tr><td><strong>Origin Settings</strong><br>Control origin routing, timeouts, redirects, TLS, and compression.</td><td><a href="/pages/Pra5QgSJ6ZeRrjB77vim">/pages/Pra5QgSJ6ZeRrjB77vim</a></td></tr><tr><td><strong>Caching</strong><br>Define cache lifetime, cache keys, cookie rules, and stale-content behavior.</td><td><a href="/pages/E1LUmSu1sXq6c0WsHQoG">/pages/E1LUmSu1sXq6c0WsHQoG</a></td></tr><tr><td><strong>Headers</strong><br>Manage request and response headers, CORS, HSTS, and browser protections.</td><td><a href="/pages/sVzVIzrsyiCphmF8gxmE">/pages/sVzVIzrsyiCphmF8gxmE</a></td></tr><tr><td><strong>Purge</strong><br>Invalidate cached content when the origin has updated.</td><td><a href="/pages/7BdbVFFXo2fpyk2gvrcP">/pages/7BdbVFFXo2fpyk2gvrcP</a></td></tr><tr><td><strong>Prefetch</strong><br>Warm edge caches before visitors request content.</td><td><a href="/pages/ZWGr5WDS9LpIx86Yt7je">/pages/ZWGr5WDS9LpIx86Yt7je</a></td></tr><tr><td><strong>Page Rules</strong><br>Apply targeted caching, redirect, and optimization behavior by URL.</td><td><a href="/pages/UrcCnbbp0HgWtbDLPNkJ">/pages/UrcCnbbp0HgWtbDLPNkJ</a></td></tr><tr><td><strong>Compression</strong><br>Enable Gzip or Brotli for smaller dynamic responses.</td><td><a href="/pages/NvmmKUyJYXJIBMpW7Wf9">/pages/NvmmKUyJYXJIBMpW7Wf9</a></td></tr></tbody></table>


# Origin Settings


# Advanced Origin Settings

Learn how Advanced Origin Settings control granular routing behavior for dynamic traffic within your CDN Resource.

The **Advanced Origin Settings** feature for Dynamic Content Acceleration operates the same way as in Static Content Delivery.\
It allows you to define rule-based origin routing for specific URLs, extensions, or directories, enabling precise control over how dynamic traffic is forwarded to different origins. You can override protocols, ports, host headers, and assign priorities to create complex multi-origin routing behaviors.

For configuration details, match types, and examples, refer to the main Advanced Origin Settings documentation:\
**Learn more in the** [**Advanced Origin Settings documentation**](/products/performance-cdn/static-content-delivery/advanced-configuration)**.**


# Rewrite Origin URLs

Learn how Rewrite Origin URLs modify request paths before forwarding dynamic traffic to origin servers.

The **Rewrite Origin URLs** feature for Dynamic Content Acceleration operates the same way as in Static Content Delivery.\
It rewrites incoming request paths based on defined match rules, allowing you to adjust backend routing for APIs, directory changes, or custom origin mappings. You can configure match modes, origin and target URIs, and rule priority to control how dynamic requests are transformed before reaching the origin.

For configuration details, supported match modes, and examples, refer to the main documentation:\
**Learn more in the** [**Rewrite Origin URLs documentation**](/products/performance-cdn/static-content-delivery/advanced-configuration/origin-settings/rewrite-origin-urls)**.**


# Origin SNI Request

Learn how Origin SNI Request controls the SNI value used when the CDN establishes TLS connections for dynamic traffic.

The **Origin SNI Request** feature for Dynamic Content Acceleration operates the same way as in Static Content Delivery.\
It ensures the CDN includes the correct Server Name Indication (SNI) during the TLS handshake when forwarding dynamic HTTPS requests to your origin. This enables the origin server to select the appropriate SSL certificate and prevents certificate mismatch issues in multi-domain environments.

For configuration details, expected behavior, and examples, refer to the main documentation:\
**Learn more in the** [**Origin SNI Request documentation**](/products/performance-cdn/static-content-delivery/advanced-configuration/origin-settings/origin-sni-request)**.**


# Redirect Handle From Origin

Learn how Redirect Handle From Origin manages origin-generated redirects and applies custom header logic for dynamic traffic.

The **Redirect Handle From Origin** feature for Dynamic Content Acceleration operates the same way as in Static Content Delivery.\
It allows the CDN to process selected 3xx redirect responses returned by your origin and apply custom request or response headers. This provides consistent redirect behavior for dynamic workloads and ensures greater control over how clients receive redirected responses.

For configuration details, supported redirect codes, and examples, refer to the main documentation:\
**Learn more in the** [**Redirect Handle From Origin documentation**](/products/performance-cdn/static-content-delivery/advanced-configuration/origin-settings/redirect-handle-from-origin)**.**


# Origin Response Timeout

Learn how Origin Response Timeout controls how long the CDN waits for dynamic origin responses before returning an error.

The **Origin Response Timeout** feature for Dynamic Content Acceleration operates the same way as in Static Content Delivery.\
It defines the maximum time the CDN waits for the origin to return an HTTP(S) response. When the origin exceeds this duration, the CDN stops waiting and returns a 504 Gateway Timeout, ensuring predictable behavior for dynamic workloads and preventing long wait times caused by slow or overloaded origins.

For configuration details, timeout behavior, and examples, refer to the main documentation:\
**Learn more in the** [**Origin Response Timeout documentation**](/products/performance-cdn/static-content-delivery/advanced-configuration/origin-settings/origin-response-timeout)**.**


# Enable Gzip from Origin

Learn how Enable Gzip from Origin optimizes dynamic traffic by requesting gzip-compressed content from your origin.

The **Enable Gzip from Origin** feature for Dynamic Content Acceleration operates the same way as in Static Content Delivery.\
It instructs the CDN to include `Accept-Encoding: gzip` when requesting eligible text-based content from your origin. If the origin supports gzip, the CDN stores the compressed response; otherwise, it stores the uncompressed version. This reduces bandwidth usage on the origin → CDN path and improves overall delivery efficiency for dynamic workloads.

For configuration details, supported MIME types, and examples, refer to the main documentation:\
**Learn more in the** [**Enable Gzip from Origin documentation**](/products/performance-cdn/static-content-delivery/advanced-configuration/origin-settings/enable-gzip-from-origin)**.**


# Caching


# Edge Cache Expiration

Learn how Edge Cache Expiration determines caching behavior and freshness for dynamic content at CDN edge servers.

The **Edge Cache Expiration** feature for Dynamic Content Acceleration operates the same way as in Static Content Delivery.\
It defines how the CDN caches objects at the edge and how long cached responses remain valid before refreshing from the origin. You can configure cache modes that rely on Panel-defined TTL values, defer to origin headers, or disable caching entirely for dynamic workloads.

For configuration details, cache modes, and examples, refer to the main documentation:\
**Learn more in the**[ **Edge Cache Expiration documentation**](/products/performance-cdn/static-content-delivery/advanced-configuration/caching/edge-cache-expiration)**.**


# Browser Cache Rule

Learn how Browser Cache Rules define how long dynamic content remains cached in the visitor’s browser.

The **Browser Cache Rule** feature for Dynamic Content Acceleration operates the same way as in Static Content Delivery.\
It controls browser-side caching by defining cache duration, cache modes, and rule priorities for different URL patterns, directories, or file types. These rules determine how browsers store and revalidate dynamic content, independent of CDN edge caching behavior.

For configuration details, rule types, and examples, refer to the main documentation:\
**Learn more in the** [**Browser Cache Rule documentation**](/products/performance-cdn/static-content-delivery/advanced-configuration/caching/browser-cache-rule)**.**


# Query String Caching

Learn how Query String Caching defines cache key behavior for dynamic URLs containing query parameters.

The **Query String Caching** feature for Dynamic Content Acceleration operates the same way as in Static Content Delivery.\
It determines how the CDN evaluates query parameters when generating cache keys, allowing you to cache each query string variant separately, ignore specific parameters, or build cache keys using only selected values. These configurations provide granular control over caching behavior for dynamic endpoints, APIs, and personalized content.

For configuration details, caching modes, and examples, refer to the main documentation:\
**Learn more in the** [**Query String Caching documentation**](/products/performance-cdn/static-content-delivery/advanced-configuration/caching/query-string-caching)**.**




---

[Next Page](/llms-full.txt/1)

