CX-SHD // included with every server

DDoS PROTECTION

Every server includes always-on L3/L4 mitigation: 10–20 Gbps of attack capacity depending on location, with filtering in place within 10 seconds for known attack vectors. Nothing to buy, nothing to switch on.

shield.conf

$ cat /etc/aixs/shield.conf

included
every server
mode
always-on
layers
L3, L4
capacity
10–20 Gbps per server
mitigation
≤ 10 s, known vectors
above_capacity
null-route 30 min
l7
not included
// illustration

SCRUB CHAMBER

Pick a server, set an attack size and watch what the included protection does.

scrub-chamber://hkg
Illustration

A drawing of the published policy. It is not live traffic and not a measurement.

Slider range: 0 to 40 Gbps, twice the largest included capacity.

attack
6 Gbps
included
10 Gbps · HKG
load
60%
state
Mitigating

6 Gbps against 10 Gbps included in Hong Kong: attack packets are dropped in the scrubbing layer and legitimate traffic reaches your server.

Configure this server
// mitigation path

HOW IT WORKS

Four steps, no action needed from you.

  1. 01 // DETECT

    Detect

    Traffic to your IPs is watched continuously at our network edge. A known L3/L4 attack pattern triggers mitigation within 10 seconds.

  2. 02 // DIVERT

    Divert

    Traffic for the targeted address is passed through the filtering layer. Your IP, routing and server configuration stay exactly as they are.

  3. 03 // SCRUB

    Scrub

    Filters drop packets that match the attack (floods, amplification, malformed fragments) and let the rest through.

  4. 04 // DELIVER

    Deliver

    Clean traffic continues to your server on the normal path. If an attack outgrows the included capacity, the overflow policy applies.

// coverage

WHAT IS COVERED

Network- and transport-layer floods, filtered by default.

Layers covered

  • L3Network layer
  • L4Transport layer

Attack types filtered

  • UDP flood
  • SYN flood
  • ACK flood
  • DNS amplification
  • NTP amplification
  • Memcached amplification
  • SSDP amplification
  • GRE flood
  • ICMP flood
  • Fragmented packets

Layer 7 (HTTP floods)

Plainly:Not included. Run your own WAF or rate limits for HTTP floods.

// capacity

CAPACITY BY LOCATION

Included per server, read from the plan catalogue, so it always matches what you order.

  • HKG Hong Kong

    10 Gbps
    Plans
    4
    Layers
    L3 / L4
    Mitigation
    ≤ 10 s
    Above capacity
    Null-route 30 min
    from$99/moView servers
  • TYO Tokyo

    10 Gbps
    Plans
    1
    Layers
    L3 / L4
    Mitigation
    ≤ 10 s
    Above capacity
    Null-route 30 min
    from$149/moView servers
  • SIN Singapore

    10 Gbps
    Plans
    1
    Layers
    L3 / L4
    Mitigation
    ≤ 10 s
    Above capacity
    Null-route 30 min
    from$139/moView servers
  • LAX Los Angeles

    20 Gbps
    Plans
    4
    Layers
    L3 / L4
    Mitigation
    ≤ 10 s
    Above capacity
    Null-route 30 min
    from$79/moView servers
// overflow policy

OVER THE LIMIT

What happens when an attack is bigger than what is included.

  1. [T+0]

    The attack exceeds the included capacity

    It is larger than the protection included for the server’s location and can no longer be filtered without affecting other customers.

  2. [T+0]

    The targeted IP is null-routed

    Traffic to that address is dropped upstream for 30 minutes, legitimate traffic included, so the attack cannot spill onto the rest of the network.

  3. [T+0]

    You are notified

    Notice goes out by email and client-area notice.

  4. [T+30m]

    The null-route is lifted

    After 30 minutes the address is routed normally again.

// roadmap

HIGHER TIERS

For more capacity than a location includes.

Coming later

Paid protection tiers are not on sale yet

We are preparing higher-capacity tiers on top of the included protection. If you need more headroom today, tell sales what you run and the attack sizes you see, and we will reply with what we can cover.

Email sales
// faq

DDoS FAQ

Is DDoS protection really included?

Yes. Every server includes always-on L3/L4 protection at no extra cost. Capacity depends on the location: 10–20 Gbps across our locations.

Do I need to switch anything on?

No. Protection is always-on and there is nothing to configure on your server.

How fast does mitigation start?

Within 10 seconds of an attack starting, for known L3/L4 vectors.

What happens if an attack is bigger than the included capacity?

The targeted IP is null-routed for 30 minutes and you are notified by email and client-area notice. During that time all traffic to the IP is dropped, legitimate traffic included.

Are HTTP (L7) floods covered?

Not included. Run your own WAF or rate limits for HTTP floods.

Can I get more than the included capacity?

Paid higher tiers are not on sale yet. Email sales@aixscloud.com with your requirements and we will reply with what we can cover.

Is the scrubbing chamber on this page real traffic?

No. It is an illustration of the policy described on this page. It does not show live attacks or measurements.

PROTECTION SHIPS WITH THE SERVER

Pick a machine in any location; the included protection comes with it.