Anti-DDoS protection for hosting and dedicated servers
In hosting an attack never concerns one customer. A flood aimed at one address crosses the same uplink and the same equipment everyone else uses, so the outage spreads across the node and sometimes the whole facility. We protect the entire prefix at the AS202520 edge, before the traffic reaches your port.
The customer under attack usually has no idea they are the target. All they know is that their site is down, and they write to you. The customers next to them write too, even though nobody attacked them. That is the real cost of an attack in hosting: not one angry customer but a whole queue of tickets and hours of support time.
What goes wrong
- One attacked address takes the service down for every customer on the node
- Protection sold per IP address fails against carpet bombing, because the target is not a single address
- A blackhole from your upstream ends the same way a successful attack does: the customer is offline
- Customers run very different traffic, so one coarse rule breaks somebody's service
- Attacks come back to the same customers on a cycle, usually after hours
What we do about it
- We filter the whole prefix at once, so spreading the attack across addresses gains nothing
- The attacked address stays reachable, because we do not drop it into a blackhole
- Rules are set per prefix and per service, separately for web, mail, DNS and control panels
- Traffic reflected off CDNs and DNS is dropped without blocklisting the content networks
- 24/7 NOC, so an attack at three in the morning does not wait for the morning shift
How it works for you
Whole-prefix protection, not single IPs
The model where protection is bought per address looks sensible on a price list and stops working with the first attack spread across a prefix. We filter the entire space we carry for you, so you do not have to guess which customer will be targeted.
A profile for mixed services on one machine
A dedicated server can serve web, mail, a control panel and a DNS resolver at once, and each of those looks different on the wire. Thresholds and allowed protocols are set so that protection does not kill legitimate traffic that happens to resemble an attack.
Connect where your racks already are
If your racks sit at Equinix WA, LIM DC, DataHouse or Korbank, a cross-connect is enough. If you have a port at THINX, TPIX, POZIX, WRIX, 1-IX or 1PL, we set up a VLAN. When we share no location, a GRE tunnel remains.
The full picture
The mechanics are the same for every segment: SkyGuard, our own stateful engine, filters every packet at the AS202520 edge, always-on or on-demand, with no RTBH and no blackholing. The main Anti-DDoS page covers the engine, the modes, reflected traffic, carpet bombing and how we compare against blackholing and outsourced scrubbing.
Frequently asked questions
Can I protect only selected customers?
Yes. In on-demand mode we cover the prefixes you point at us, so you can sell protection as an option and engage it for the customers who need it. In always-on mode the filter sits permanently in front of the whole space we carry for you.
What about customers who generate suspicious traffic themselves?
The stateful filter looks at traffic arriving at your addresses, so it does not block what your customers do outbound. If you have a problem with abuse leaving your network, that is a separate topic where we help tidy up BCP 38 style egress filtering.

