DDoS Protection
Protection against DDoS attacks
Volumetric attacks are scrubbed at the network edge and application-layer attacks are separated out by behavioural analysis, so real users and search engine crawlers keep reaching you during an attack.
- Protected layers
- L3 / L4 / L7
- Detection and scrubbing
- Automatic
- No activation request needed
- Always-on
- Scrubbing at data centre level
- Volumetric
Three attack types, three defences
DDoS is not one thing. Volumetric attacks (UDP amplification, ICMP flood) aim to fill the pipe, and the defence happens at the data centre edge by scrubbing traffic before it reaches the server. No server-side measure can unclog a saturated link.
Protocol attacks such as SYN flood target the connection table rather than bandwidth, making the server unable to accept new connections using comparatively little traffic. The defence is filtering half-open connections at the network layer.
Application-layer attacks (HTTP flood) are the most insidious: because the traffic resembles legitimate requests it never trips a volume threshold. Requests aimed at expensive endpoints such as search or checkout exhaust the server. Here the distinction is drawn through behavioural analysis — request patterns, session behaviour and source distribution.
The measure of a well-built defence is not blocking the attack but not blocking real users. Overly aggressive rules can stop the attack while shutting out your customers and search engine crawlers too — which is simply another way for the attack to succeed.
- Volumetric attacks scrubbed at the data centre edge
- Protocol attacks filtered at the network layer
- Application-layer attacks separated behaviourally
- Real user and search crawler access preserved
- Protection is always on; no activation request needed
Comparison
Attack types and defence points
| Attack type | Target | Defence point |
|---|---|---|
| UDP / ICMP flood | Link capacity | Data centre edge |
| SYN flood | Connection table | Network layer filtering |
| HTTP flood | Application resources | Behavioural analysis |
| Slowloris | Connection pool | Timeout policies |
| DNS amplification | Bandwidth | Edge scrubbing |
Features
How protection works
Always-on protection
Not a system that must be switched on when an attack starts — traffic is evaluated continuously.
Anomaly detection
Deviation from normal traffic patterns is detected automatically and scrubbing rules adapt to the attack profile.
Preserving legitimate traffic
Separation is tuned so real users are not shut out, and search engine crawlers keep access as well.
Edge scrubbing
Volumetric traffic is cleaned before it reaches your server, protecting both your link and your server resources.
Uninterrupted transition
The goal is keeping the service up during an attack, with no routing change required.
Post-incident review
After an attack, traffic logs are reviewed and protection policies revisited.
FAQ
Frequently asked questions
Is there an extra charge for DDoS protection?
Protection runs continuously as part of the infrastructure rather than being a separate service activated during an attack. If an unusually large or sustained attack requires additional capacity, we assess that with you.
Will my site go down completely during an attack?
The goal is keeping the service up. Because volumetric traffic is scrubbed before it reaches the server, your resources are not consumed by attack packets. Application-layer attacks can cause temporary slowdown, in which case scrubbing rules are tightened to match the attack profile.
How will I know I'm under attack?
Traffic anomalies raise alerts in our monitoring system. If the situation affects your service, our technical team informs you and stays in contact throughout the incident.
Are there measures I can take in my own application?
Yes, and they matter. Rate limiting on expensive endpoints, caching heavy queries and throttling login attempts markedly reduce the impact of application-layer attacks. We plan these with you.
More
Related pages
- FirewallFortiGate firewallHardware FortiGate protection at the network edge: stateful filtering, IPS signatures, VLAN segment policies and VPN access.
- Network SecurityNetwork security with pfSenseIn-segment routing, encrypted VPN access, port forwarding and detailed rule sets with pfSense — a second protection layer behind the hardware firewall.
- High AvailabilityHigh availability (HA) architectureHA architectures with single points of failure removed: per-component redundancy, a defined failover scenario and regular rehearsals.
Let's plan your infrastructure together
Tell us what you need and we prepare a configuration and pricing specific to you. We don't sell fixed packages; we build the deployment, licensing and backup plan with you.