CX-SHD // included with every server
DDoS PROTECTION
Every server includes always-on L3/L4 mitigation: 10–20 Gbps of attack capacity depending on location, with filtering in place within 10 seconds for known attack vectors. Nothing to buy, nothing to switch on.
$ cat /etc/aixs/shield.conf
- included
- every server
- mode
- always-on
- layers
- L3, L4
- capacity
- 10–20 Gbps per server
- mitigation
- ≤ 10 s, known vectors
- above_capacity
- null-route 30 min
- l7
- not included
SCRUB CHAMBER
Pick a server, set an attack size and watch what the included protection does.
A drawing of the published policy. It is not live traffic and not a measurement.
Slider range: 0 to 40 Gbps, twice the largest included capacity.
- attack
- 6 Gbps
- included
- 10 Gbps · HKG
- load
- 60%
- state
- Mitigating
6 Gbps against 10 Gbps included in Hong Kong: attack packets are dropped in the scrubbing layer and legitimate traffic reaches your server.
Configure this serverHOW IT WORKS
Four steps, no action needed from you.
- 01 // DETECT
Detect
Traffic to your IPs is watched continuously at our network edge. A known L3/L4 attack pattern triggers mitigation within 10 seconds.
- 02 // DIVERT
Divert
Traffic for the targeted address is passed through the filtering layer. Your IP, routing and server configuration stay exactly as they are.
- 03 // SCRUB
Scrub
Filters drop packets that match the attack (floods, amplification, malformed fragments) and let the rest through.
- 04 // DELIVER
Deliver
Clean traffic continues to your server on the normal path. If an attack outgrows the included capacity, the overflow policy applies.
WHAT IS COVERED
Network- and transport-layer floods, filtered by default.
Layers covered
- L3Network layer
- L4Transport layer
Attack types filtered
- UDP flood
- SYN flood
- ACK flood
- DNS amplification
- NTP amplification
- Memcached amplification
- SSDP amplification
- GRE flood
- ICMP flood
- Fragmented packets
Layer 7 (HTTP floods)
Plainly:Not included. Run your own WAF or rate limits for HTTP floods.
CAPACITY BY LOCATION
Included per server, read from the plan catalogue, so it always matches what you order.
HKG Hong Kong
10 Gbps- Plans
- 4
- Layers
- L3 / L4
- Mitigation
- ≤ 10 s
- Above capacity
- Null-route 30 min
from$99/moView serversTYO Tokyo
10 Gbps- Plans
- 1
- Layers
- L3 / L4
- Mitigation
- ≤ 10 s
- Above capacity
- Null-route 30 min
from$149/moView serversSIN Singapore
10 Gbps- Plans
- 1
- Layers
- L3 / L4
- Mitigation
- ≤ 10 s
- Above capacity
- Null-route 30 min
from$139/moView serversLAX Los Angeles
20 Gbps- Plans
- 4
- Layers
- L3 / L4
- Mitigation
- ≤ 10 s
- Above capacity
- Null-route 30 min
from$79/moView servers
OVER THE LIMIT
What happens when an attack is bigger than what is included.
- [T+0]
The attack exceeds the included capacity
It is larger than the protection included for the server’s location and can no longer be filtered without affecting other customers.
- [T+0]
The targeted IP is null-routed
Traffic to that address is dropped upstream for 30 minutes, legitimate traffic included, so the attack cannot spill onto the rest of the network.
- [T+0]
You are notified
Notice goes out by email and client-area notice.
- [T+30m]
The null-route is lifted
After 30 minutes the address is routed normally again.
We do not sell “unlimited” protection. The numbers on this page are the limits.
Need more headroom than your location includes? Talk to sales before you deploy.Under attack right now? Open a ticket.(opens in a new tab)HIGHER TIERS
For more capacity than a location includes.
Paid protection tiers are not on sale yet
We are preparing higher-capacity tiers on top of the included protection. If you need more headroom today, tell sales what you run and the attack sizes you see, and we will reply with what we can cover.
Email salesDDoS FAQ
Is DDoS protection really included?
Yes. Every server includes always-on L3/L4 protection at no extra cost. Capacity depends on the location: 10–20 Gbps across our locations.
Do I need to switch anything on?
No. Protection is always-on and there is nothing to configure on your server.
How fast does mitigation start?
Within 10 seconds of an attack starting, for known L3/L4 vectors.
What happens if an attack is bigger than the included capacity?
The targeted IP is null-routed for 30 minutes and you are notified by email and client-area notice. During that time all traffic to the IP is dropped, legitimate traffic included.
Are HTTP (L7) floods covered?
Not included. Run your own WAF or rate limits for HTTP floods.
Can I get more than the included capacity?
Paid higher tiers are not on sale yet. Email sales@aixscloud.com with your requirements and we will reply with what we can cover.
Is the scrubbing chamber on this page real traffic?
No. It is an illustration of the policy described on this page. It does not show live attacks or measurements.
PROTECTION SHIPS WITH THE SERVER
Pick a machine in any location; the included protection comes with it.