In-house DDoS protection for servers and games
We filter attack traffic before it reaches your server, on our own hardware and in real time. Protection comes free with every service: VPS, semi-dedicated servers, cPanel hosting and game servers.
- Included at no cost
- Automatic, in real time
- Port and country filters
- Anti-DDoS for game servers
How the protection works
The protection works on its own, before traffic reaches your server: there’s nothing you need to do when an attack starts.
-
We analyze the traffic
We check it in real time for malicious activity and watch for new attack methods: our filters are kept up to date.
-
We stop the attack
A transparent layer 4 firewall and a traffic analyzer drop TCP, UDP and ICMP floods before they reach your server. HTTP floods are filtered too.
-
Clean traffic gets through
Legitimate traffic reaches your server with little or no added latency.
The network in numbers
- In-house mitigation
- Up to 100 Gbit/s
- Packets per second
- Up to 8 million
- Upstream provider network
- Up to 50 Tbps
- Activation
- Automatic
Attacks it stops
It covers TCP, UDP and ICMP attacks as well as HTTP floods. TCP and UDP attacks are mitigated within seconds.
- TCP
- SYN flood
- Spoofed SYN
- SYN-ACK reflection
- ACK flood
Floods of SYN, SYN-ACK or ACK packets that don’t belong to real connections, meant to exhaust the server’s resources.
- UDP
- UDP flood
A nonstop stream of packets at the server’s ports, meant to saturate the link.
- IP
- IP fragments (frag flood)
Fragmented packets the server wastes resources reassembling.
- ICMP
- ICMP flood
A flood of pings meant to saturate the link.
- HTTP
- HTTP flood
Thousands of requests to your site posing as real visitors.
Filters tailored to your service
On top of the general protection, you can tailor it to what runs on your server: when you sign up, you choose how your IP is filtered. Ask us what works best for you.
-
Port filters
We assign filters to the ports your service uses. If you prefer, your public IP can go unfiltered.
-
Anti-DDoS for game servers
Game servers get custom protection that filters traffic on the UDP ports used by gaming platforms.
-
Country blocking
We block IP ranges from countries you don’t want reaching your IP, so only the traffic you care about gets in.
Mitigation at each location
The mitigation level varies by data center. Choose your location based on what you need to protect.
| Location | Uplink | Mitigation |
|---|---|---|
| Argentina Buenos Aires | 1 Gbps | Basic |
| Chile Santiago | 2 × 25 Gbps | Intermediate/advanced |
| Brazil São Paulo | 20 Gbps | Full Always on, with Cloudflare |
| Canada Montreal | 2 × 25 Gbps (OLA) | Full With the ARMYRED Edge firewall |
In Argentina the uplink is 1 Gbps and mitigation is basic: connection and latency are excellent for your users in Argentina, but protection against large attacks is limited. We make this clear before you sign up.
Not sure which location is right for you?
Ask us on WhatsAppDDoS protection FAQ
What people ask us most about attacks and how we stop them.
Have another question?
Message us on WhatsAppWhat is a DDoS attack?
It’s an attack in which hundreds or thousands of machines flood a server with traffic at the same time to overwhelm it. The goal is to knock the service offline, sometimes for hours or days.
Does DDoS protection cost extra?
No. It’s included with every service (VPS, semi-dedicated servers, cPanel hosting and game servers) at no extra charge.
Do I have to turn it on when I’m under attack?
No. It’s automatic: the filters detect the attack and stop it before it reaches your server, without you having to ask.
What is the protection’s capacity?
Our in-house mitigation handles up to 100 Gbit/s and 8 million packets per second. Separately, our upstream provider’s network has a capacity of up to 50 Tbps.
What attacks does it stop?
TCP, UDP and ICMP attacks such as SYN floods, spoofed SYN floods, SYN-ACK reflection, ACK floods, IP fragment floods and UDP floods, among others. It also filters HTTP floods.
Does it work for game servers?
Yes. Game servers get custom anti-DDoS protection that filters traffic on the UDP ports used by gaming platforms.
Can I choose what traffic gets filtered?
Yes. Your public IP can have filters on the ports you use or go unfiltered, and we can block IP ranges from countries you don’t want, so only the traffic you care about gets in.
Is the protection the same at every location?
No, it varies by data center: mitigation is full in Brazil and Canada, intermediate/advanced in Chile and basic in Argentina. Before you sign up, we explain the limits of each location.