Network Security
DDoS Protection
What is included, who filters the traffic before it reaches AS208220, and exactly when an IP gets null-routed. Every number on this page is confirmed in writing by the provider that does the filtering.
At a glance
- Included with every server
- To confirm
- Who filters
- To confirm
- Where filtering happens
- To confirm
- Total mitigation capacity
- To confirm
- Mitigation per IP
- To confirm
- Mode
- To confirm
- Time to mitigate
- To confirm
- Attack types covered
- To confirm
When does an IP get null-routed?
A null-route (blackhole) drops all traffic to one IP address at the upstream edge. It takes that IP offline, but keeps every other customer on the network reachable. It is the last resort, used only when an attack exceeds what can be filtered.
- Trigger: To confirm
- Duration: To confirm
- Only the attacked IP is null-routed — other IPs on your server stay online.
- You are notified by email when a null-route starts and ends.
Null-routing during an attack is excluded from the SLA because it protects the network for everyone.
What it does not cover
- Application-layer (L7) attacks such as HTTP floods against your website. Use a reverse proxy or WAF in front of your application for those.
- Attacks that originate from your own server — those fall under the Acceptable Use Policy.
Upgrade
Upgrade option to confirm