Filtering that is already on
There is no button to press when an attack starts, because the filtering was in the path before it did. Up to 12 Tbit/s of scrubbing capacity, mitigation measured in seconds on the volumetric classes, and a section further down listing what none of this will save you from.
Always on means always in the path
No “activate protection” toggle. A toggle implies minutes of downtime while somebody finds it.
Every packet destined for your instance crosses the filtering layer whether an attack is happening or not. Under normal conditions it adds well under a millisecond and does nothing else. When something starts, the change is in what gets dropped rather than where the traffic goes.
The alternative model, where traffic gets diverted into a scrubbing centre once an alarm trips, sounds equivalent and is not. Diversion takes time to converge, and the first ninety seconds of an attack is exactly the part you wanted filtered.
Included on every plan
From the smallest Ryzen instance to a dual-socket bare-metal machine. Filtering capacity is a property of the site, not of what you spent.
Capacity by site
12 Tbit/s at Amsterdam, Frankfurt and New York; 8 Tbit/s at the mid-size sites; 4 Tbit/s at the smaller ones. The figure for each site is on its location page and it is not rounded up.
Latency cost, measured
Under 0.4 ms added at the edge in steady state. During active mitigation it rises, typically to between 1 and 2 ms, because dropping things costs cycles.
What gets detected, and how quickly
Detection is two systems doing different jobs. One matches known-bad traffic in hardware and needs no thinking. The other watches rates and distributions and decides that something has changed.
- 01
Line-rate signature match
Amplification protocols, malformed headers and fragment abuse are dropped at the edge on match. No threshold has to be crossed first, so the effective mitigation time is zero.
- 02
Flow aggregation, two-second window
Sampled flow telemetry from every edge router feeds a rolling window. Packet rate, connection rate, source entropy and protocol mix are watched per destination address rather than per site.
- 03
Threshold trip
A destination crossing its learned baseline gets a mitigation profile applied automatically. Median time from first attack packet to profile applied is under two seconds on volumetric classes.
- 04
A human, on the larger ones
Anything above 100 Gbit/s pages the network team at any hour. Not because the automation needs supervision, but because attacks of that size usually come with a second, quieter attack behind them.
- 05
It logs, you read it
Every mitigation writes a record you can see in the panel: start, end, peak bits and packets per second, top protocols and what the profile dropped.
Layer 3 and 4, which is the part that is genuinely solved
Volumetric and protocol attacks are an engineering problem with a known answer, and the answer is capacity plus stateful hardware sitting in front of you. Layer 7 is a different problem entirely and gets its own section.
| Attack class | Where it is handled | Typical time to mitigate |
|---|---|---|
| UDP amplification (DNS, NTP, memcached, SSDP, CLDAP) | Dropped at the edge on signature | Immediate, always on |
| Fragmented and malformed IP | Dropped before reassembly is attempted | Immediate, always on |
| SYN and ACK floods | Scrubbing layer, cookies and per-source rate profiles | Under 2 seconds |
| TCP state exhaustion | Scrubbing layer, connection caps per source | 5 to 20 seconds |
| Tunnel floods (GRE, IPIP, ESP) | Dropped unless you asked for the protocol | Immediate, always on |
| DNS query floods against your own resolver | Rate profile plus response-rate limiting | 10 to 60 seconds |
| HTTP and HTTPS request floods | DDoS Pro rules on the instance path | 30 seconds to a few minutes |
| Slow-read, slow-post and connection hoarding | DDoS Pro timeout and body-rate rules | Minutes, needs tuning |
| Abuse of your own application logic | Your code. We can rate-limit it, we cannot understand it | Not our layer |
The largest attack we have absorbed without a customer-visible drop was a little over 2.1 Tbit/s of reflected UDP across four sites inside the same twelve-minute window. Back in October 2020, the attack that first paid for this tier was 340 Gbit/s and it took AMS-01 down for eleven minutes.
What DDoS Pro adds, for twenty-nine euro
The included filtering handles everything that can be identified from the packet. DDoS Pro is for attacks that look exactly like customers, because they are shaped like customers.
Buy it before you need it. Writing layer-7 rules during an attack is possible and thoroughly unpleasant.
Rules at layer 7
Per-path rate limits, method and header conditions, JA-style client fingerprint matching, and challenge responses you can scope to one endpoint instead of your whole site. Rules apply in seconds and roll back just as fast.
Signatures written for you
When an attack has a shape that generic rules miss, the network team writes the signature during the incident and leaves it in place afterwards. It stays yours; it is not shared into a global list without asking.
A person on the other end
A named engineer on the ticket for the duration, not a queue position. That is the part customers actually renew for, and it is why the price is twenty-nine euro rather than free.
DDoS Pro terminates TLS only if you hand us a certificate, which many customers reasonably decline to do. Without one, layer-7 rules work on connection behaviour and metadata rather than on request contents, and that is still enough for most floods.
What we cannot protect you from
This section exists because every competitor’s equivalent page stops before it. Filtering is a network capability with sharp edges, and knowing where they are is worth more than another paragraph about capacity.
An application that falls over at 400 requests a second
If your stack cannot survive a modest traffic spike, an attacker does not need a botnet, only patience. Filtering buys you time to fix the thing; it does not fix the thing.
Attacks on infrastructure we do not run
Your authoritative DNS hosted elsewhere, your registrar, your payment provider, your upstream API. Traffic that never touches our network cannot be filtered by it.
Anything past the site’s scrubbing capacity
A 4 Tbit/s site absorbs 4 Tbit/s. Beyond that the address is null-routed to protect everyone else on the floor, and pretending otherwise would be the kind of promise that reads well and fails loudly.
Attacks carried inside legitimate sessions
Credential stuffing at human speed, scraping from residential proxies, one expensive query repeated slowly. These are authorisation and application problems wearing a network costume.
Traffic you asked us to allow
If you open a UDP service to the world and it turns out to be an amplifier, we will filter the abuse and then tell you to fix the service. Both halves of that sentence matter.
Outbound attacks from your own instance
Filtering protects you from the internet. When the traffic goes the other way it becomes an abuse case, and that path ends with the instance suspended rather than scrubbed.
The honest limits, written down
Two policies people find out about at the worst possible moment elsewhere. Here they are in advance, in the order they would happen to you.
- 01
Null-route, and what triggers it
One address, when an attack against it exceeds what the site can scrub or when collateral starts affecting other customers. Never the whole account, never other instances, and never as a first response to a modest attack.
- 02
How long it lasts
Fifteen minutes to start with, extended in fifteen-minute steps while traffic is still arriving. Most lift on the first check. The panel shows the countdown rather than making you ask for it.
- 03
What you can do in the meantime
Bring up a second address on the same instance and move DNS, which takes a couple of minutes and is why extra IPv4 addresses cost three euro rather than thirty. Your IPv6 address is usually still reachable, because attacks are still overwhelmingly IPv4.
- 04
When we ask you to move
A customer attracting sustained multi-terabit traffic at a 4 Tbit/s site gets offered a transfer to an anchor site at no charge. That conversation happens once and is not a prelude to termination.
- 05
What we will not do
Terminate you for being a target. Being attacked is not a breach of the acceptable use policy, it is a Tuesday, and hosts that cancel victims for causing inconvenience are the reason people end up here.
“Four years, two attacks, one dead NVMe replaced without me noticing. That is the entire list of events.”
Questions about filtering
No. Layer 3 and 4 filtering is in path from the moment the instance boots, on every plan, at every site. The only thing you can buy is the layer-7 tier, and the only thing you can switch off is a specific rule you disagree with.
Not by default, but tell us what you are running. Custom UDP services on non-standard ports are the one case where a generic profile can be wrong, and a two-line ticket produces an allowance for your ports in a few minutes.
Mitigation records appear in the panel with start and end times, peak rates and the top protocols involved. Anything lasting more than five minutes also generates an email, because you may want to correlate it with what your own logs saw.
No. Scrubbed traffic never counts towards the fair-use figure, and there is no per-incident fee. Charging you for being attacked is a business model we have looked at and declined.
Traffic inside a private VLAN never crosses the edge, so it is not filtered and does not need to be. If one of your instances is attacking another, that is a compromised instance and a different conversation.
A little over 2.1 Tbit/s of reflected UDP, spread across four sites inside twelve minutes, with no customer-visible packet loss. The status page has the incident note, including the parts that did not go perfectly.
Add DDoS Pro before the afternoon you need it
Twenty-nine euro a month for layer-7 rules, custom signatures and an engineer on the ticket. It can be added to a running instance without a reboot and cancelled the same way.