How DDoS filtering works here
Every server comes with basic DDoS protection as standard, and large attacks are absorbed at backbone level before they reach our network.
What happens during an attack
Volumetric floods are handled upstream: the traffic is dropped at backbone level rather than delivered to our edge and sorted out afterwards. For you, an attack that would have filled your port usually shows up as nothing more than a busier graph.
Filtering is standard on every machine. There is no package to buy, no protection tier and no per-attack fee.
What filtering does not cover
Anything that looks like legitimate traffic to a network device. A flood of valid HTTP requests to an expensive endpoint, a login form being hammered at a normal rate, a slow-loris style connection drain — those are decided in your application, not in a router. Rate limits, caching and a sensible timeout policy are yours to set.
What to do when you are under attack
- Tell us, with timestamps. The sooner we look, the more useful the capture is.
- Do not change your IP address in a panic; it rarely helps and it breaks your DNS for a day.
- Keep your own logs rolling — afterwards they are the only record of what the application actually saw.
And the other direction
Attacks leaving our network are a different matter entirely. Running an attack, selling access to one or hosting the front end for one is not allowed under any circumstances and ends the service, usually without notice. See our acceptable use policy.
That also applies when it is not your fault: a compromised box joining a botnet gets the same treatment, because the traffic looks the same from outside. Keeping the machine patched is part of the deal.
Still stuck? Mail support@novogara.com — an engineer answers, at any hour. Back to the knowledge base