Anti-DDoS

Anti-DDoS mitigation with auto-discovery.

Don't let a DDoS take your service down: the system detects and applies the right filter to your traffic, with nothing to configure. In-house Hostealo Shield in Madrid (+200 Gbps), PletX in Eygelshoven and W&D Shield + PletX in Mainhausen (up to 1 Tbps per DC), over our autonomous network (AS215691).

  • L3 / L4 included at no cost
  • Per-application auto-discovery
  • In-house Hostealo Shield
  • 24/7 NOC
Blocked
Blocked
Blocked
Blocked
Blocked
+1 Tbps
Per-DC capacity in EU

PletX in NL · W&D Shield + PletX in DE.

+200 Gbps
Hostealo Shield (Madrid)

In-house L3/L4 system with advanced control.

< 1s
Automatic detection

Heuristics + signatures, no manual intervention.

L3 / L4
Layers covered

Volumetric and protocol (SYN/UDP/ICMP, amplification, reflection).

Universal

Auto-discovery across every DC

The system observes the traffic on your ports, identifies the protocol and automatically applies the matching filter. No tickets to open, no rules to configure, no need to know what A2S spoofing or a RakNet flood is.

  1. 01

    Your service is provisioned

    VPS or dedicated live on your IP in the chosen DC.

  2. 02

    Scrubbing observes the traffic

    Heuristics + signatures over the first window of connections.

  3. 03

    The right filter is applied

    Counter-Strike, Minecraft, FiveM, RakNet, OpenVPN… or the generic L4 one if it fits none.

  4. 04

    Fine-tuning during an attack

    The NOC monitors 24/7 and hardens rules in real time if a sustained attack warrants it.

Filter catalog by datacenter

Each DC runs a different stack. Madrid (Hostealo Shield, in-house) brings the widest catalog. EU (PletX / W&D Shield) covers the main presets plus a Custom filter where you define your own TCP values.

Spain · Madrid — +200 Gbps · Hostealo Shield
Gaming25
  • AltVTCP
  • FiveM Ultra StrictTCP
  • Minecraft JavaTCP
  • TibiaTCP
  • AltVUDP
  • Ark: Survival AscendedUDP
Voice2
  • TeamSpeak 3UDP
  • TS3 Query/FiletransferTCP
Web / TLS4
  • HTTPTCP
  • HTTP StrictTCP
  • TLSTCP
  • SSL StrictTCP
Infra7
  • FTPTCP
  • SSHTCP
  • RDPTCP
  • Remote Desktop ProtocolTCP
  • RDPUDP
  • DNSUDP
VPN2
  • OpenVPNUDP
  • WireGuardUDP

New York runs Anti-DDoS Basic (generic volumetric protection, with no public per-application filter catalog).

Madrid only

Advanced panel · Hostealo Shield

Because it's an in-house system, in Madrid we expose direct control over per-IP scrubbing behaviour. Useful for clients with mixed traffic, persistent attacks or specific geo-filtering needs.

For external networks

IP Transit with Anti-DDoS

Do you run your own AS? We become your BGP upstream with scrubbing applied to all inbound traffic. Announce your prefix through our autonomous network and your network, as a downstream client, receives only clean traffic.

  • Announce your IPv4 prefix with our autonomous network as your BGP upstream
  • Hostealo Shield applied to all inbound traffic
  • ASN / country blocking and IP lists managed by you
  • LOA + RPKI managed, valid if you re-announce to your own BGP clients
  • Works whether you have your own LIR or not
Request an IP Transit quote →
Internet
Inbound traffic
Mixed traffic: legitimate + attacks.
AS215691 · Upstream
Hostealo Shield
Your BGP provider · L3/L4 scrubbing · ASN/country · IP rules.
Your AS · Downstream
Your network
Receives only clean traffic.
AttackLegitimate trafficClean traffic

What's included (and what's not)

Included at no cost

  • L3/L4 mitigation on all services
  • Per-application filter auto-discovery
  • Advanced per-IP panel (Madrid)
  • 24/7 NOC monitoring sustained attacks
  • No attack-traffic surcharge

Not included

  • L7 mitigation (HTTP flood, bots, scraping) — handled server-side or with a WAF
  • Anti-DDoS Basic in NY exposes no per-application filter catalog
  • IP Transit with Anti-DDoS is quoted separately (not included with VPS/dedicated)
  • Manual tuning outside Madrid (closed catalog)

FAQ

Frequently asked questions

We answer the most common questions. Still have one? Write to us and we'll reply within 24 hours.

Over 2 Tbps spread across datacenters: +200 Gbps in Madrid (Hostealo Shield, in-house system), +1 Tbps in the Netherlands (PletX) and +1 Tbps in Germany (W&D Shield + PletX). New York runs Anti-DDoS Basic (generic volumetric protection).

Ready to protect your infrastructure?

Activation in under 24 hours for new customers. Auto-discovery does the rest.