Skip to main content
Edge Proxy protects applications from DDoS attacks by routing traffic through the Gcore CDN edge network. Protection is active within minutes, without deploying additional infrastructure or configuring complex networking.

Traffic flow

Clients connect to a proxy IP; Gcore filters the traffic at the nearest PoP and forwards clean connections to the origin.
Edge Proxy traffic flow — client to Anycast IP, PoP filtering drops DDoS traffic, clean traffic forwarded to origin
Incoming traffic routes through Anycast IP addresses to the nearest Point of Presence, where DDoS filtering runs at the edge. Clean traffic forwards to the origin server. Each protected server receives a dedicated proxy IP address that clients connect to instead of the origin directly. Edge Proxy suits game servers, APIs, backend services, and any TCP or UDP application that requires DDoS protection:
  • High availability — traffic distributed across multiple PoPs removes regional bottlenecks and enables multi-terabit filtering capacity.
  • Lower latency — processing at the nearest PoP reduces round-trip time and improves responsiveness.
  • Simple setup — configured in a few steps without managing virtual machines or networking components.
  • Efficient IP usage — multiple servers share the same Anycast infrastructure, so no additional transit or IP allocation is required per server.
  • Flexible configuration — multiple applications and ports can be protected behind a single proxy IP.

Core concepts

The following terms appear throughout the Edge Proxy documentation. Once configured, Edge Proxy assigns a proxy IP, starts filtering traffic immediately, and exposes traffic metrics in Traffic Overview.