Skip to main content
Gcore DDoS Protection safeguards servers and instances against distributed denial-of-service (DDoS) attacks. Two protection modes are available: Basic (free, enabled by default on all servers) and Advanced (paid, always-on filtering via a Threat Mitigation System).

Protection modes

The two modes differ in detection speed, traffic coverage, and cost.

Basic protection

Basic protection is enabled by default.

ACL rules

Basic protection uses predefined ACL rules to block the following traffic types:
  • Reflection attacks: DNS, NTP, SSDP, MSSQL, LDAP, SNMP, CharGen, Memcache, Echo, RIP, ARMS
  • Fake source IP attacks: 0/32, 127.0.0.0/8, 192.0.2.0/24, 224.0.0.0/3, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16
Volumetric filtering on Basic protection does not apply to floods below 200 Mbit/s per destination IP. To customize ACL rules, upgrade to Advanced protection.

Null-routing

When Basic protection detects a DDoS attack, the system temporarily blocks the target IP address. This mechanism is known as null-routing: the server is protected from attack traffic but becomes unreachable from the internet for 12 hours. To keep the service available during an attack, upgrade to Advanced protection.

Advanced protection

Advanced protection keeps the TMS active at all times, including when no attack is underway, so filtering starts the moment traffic turns malicious instead of only after an attack begins. Activate Advanced protection in the Gcore Customer Portal using the self-service setup flow. Start with service activation, which covers plan activation, network submission, NOC review, and network configuration.

Allowlists

IP addresses added to an allowlist are treated as trusted resources. For Enterprise customers, allowlisted IPs bypass DDoS Protection analysis entirely and are not inspected by TMS. For customers on public plans, allowlisted IPs remain subject to DDoS traffic filtering.

DDoS attack statistics

The real-time DDoS attack statistics feature provides a live dashboard with an overview of ongoing attacks on protected resources. Filter by data center, time interval, and attack metrics such as bits per second (bps) and packets per second (pps).
DDoS attack statistics

Pricing

Advanced protection pricing depends on the plan tier and the server location.
  • Plan tier. Plan activation lists the available tiers (PAYG, Start, Pro, and Pro+), based on the clean traffic volume and number of network prefixes to protect.
  • Server location. Prices vary by data center. Contact the Gcore sales team for pricing on a specific location.
Every tier covers L3-L7 attacks by default. For custom configurations, contact the Gcore sales team to request a tailored plan.