This is an old revision of the document!


DDOS Protection

What does this service do?

This addon provides you with an affordable source of Denial Of Service protection.

We use Path.net for our DDOS Protection on all DDOS Protected IPs.

If you don't know what this is, nor have you been sent an email regarding a nullroute being applied against your IP, it's unlikely you need this :)

How much does it cost ?

Protected IP addresses cost $3.00/month per IP address in all locations we operate.

How much filtering is provided?

Path.net provides 3Tbit+ DDOS Protection on all DDOS Protected IPs.

What types of floods does it protect against?

Here is an exhaustive list of floods that our filtering helps protect against:

  • TCP SYN + ACK
  • TCP FIN
  • TCP RESET
  • TCP ACK
  • TCP ACK + PSH
  • TCP Fragment
  • TCP (SYN, etc.), ICMP, UDP Floods
  • HTTP URL GET/POST Floods
  • Malformed HTTP Header Attacks
  • Slow-HTTP Request Attacks
  • SYN Floods Against SSL Protocols
  • Malfromed SSL Attacks
  • SSL Renegotiation Attacks
  • SSL Exhaustion (Single Source/Distributed Source)
  • DNS Cache Poising Attacks
  • DNS Request Flood
  • SIP Request Floods
  • IGMP
  • Brute Force
  • Connection Flood
  • Spoofing / Non-Spoofed
  • Mixed SYN + UDP or ICMP + UDP flood
  • Ping of Death
  • Smurf
  • Reflected ICMP and UDP
  • Teardrop
  • Botnets
  • Blackenergy, Darkness, YoYoDDoS, etc
  • Common DoS/DDoS Tools
  • Slowloris/Pyloris, Pucodex, Sockstress, ApacheKiller
  • Voluntary Botnets
  • HOIC, LOIC, Etc
  • Application Attacks
  • Zero-day DDoS attacks
  • DDoS attacks targeting Apache, Windows, or OpenBSD vulnerabilities

As well as many others. Some protection may require a ticket to be enabled, namely some of the HTTP layer 7 protection.

In some cases we can get custom rules put in place to help, so be sure to let us know if you see a flood passing through.

What extra features do you include?

You can configure the DDOS Protection firewall on the Stallion. Please note that the DDOS Protection firewall only works on a path.net IP.

You can also add Application filters on the Stallion aswell.

Path.net currently offers these application filters:

  • TeamSpeak 3
  • OpenVPN (UDP)
  • Half-Life 2 / Source Server
  • FiveM Server (BETA)
  • RAKNET (Rust, Minecraft Bedrock, Geyser, etc)
  • TCP SYNPROXY

Note: Some filters may require a ticket. (Such as Minecraft or HTTP Layer 7 Protection.

Is there an SLA?

Our filtering carries a 99.9% uptime SLA.

This SLA does not cover users getting application layer floods.

Where can I order a DDOS protected IP address?

While at checkout, or on the product upgrade page, simply enter how many protected IP addresses you want in the 'DDOS protection' field.

How long do I have to wait to be activated?

DDOS protected IP's are automatically bound at order time. Ordering them at any other time will take anywhere from 5 minutes to a few hours depending on the time of day.

Where can I find my protected IP address once I've been provisioned?

You can find your IP address listed in the networking section in the Stallion.

The DDOS Protected IP should show up and the type should say DDoS Protected in red.

How do I enable my DDOS Protected IP and make it my primary IP?

  1. Go to the Stallion and click “Networking”
  2. Activate the DDOS Protected IP and turn off the non protected IP if needed.
  3. Click on the dropdown where it says “Main IP Address” and select your protected IP and click “Save Changes”
  4. Reboot your VPS.
  5. Run curl ipinfo.io and see if your DDOS Protected IP shows up.

What services will you not protect?

Please abide by our Terms of Service and Acceptable Use Policy for a list of applications allowed on our network.

TL;DR Camfrog is fine.