Anti-DDoS
Anti-DDoS mitigation with auto-discovery.
Don't let a DDoS take your service down: the system detects and applies the right filter to your traffic, with nothing to configure. In-house Hostealo Shield in Madrid (+200 Gbps), PletX in Eygelshoven and W&D Shield + PletX in Mainhausen (up to 1 Tbps per DC), over our autonomous network (AS215691).
- L3 / L4 included at no cost
- Per-application auto-discovery
- In-house Hostealo Shield
- 24/7 NOC
PletX in NL · W&D Shield + PletX in DE.
In-house L3/L4 system with advanced control.
Heuristics + signatures, no manual intervention.
Volumetric and protocol (SYN/UDP/ICMP, amplification, reflection).
Universal
Auto-discovery across every DC
The system observes the traffic on your ports, identifies the protocol and automatically applies the matching filter. No tickets to open, no rules to configure, no need to know what A2S spoofing or a RakNet flood is.
- 01
Your service is provisioned
VPS or dedicated live on your IP in the chosen DC.
- 02
Scrubbing observes the traffic
Heuristics + signatures over the first window of connections.
- 03
The right filter is applied
Counter-Strike, Minecraft, FiveM, RakNet, OpenVPN… or the generic L4 one if it fits none.
- 04
Fine-tuning during an attack
The NOC monitors 24/7 and hardens rules in real time if a sustained attack warrants it.
Filter catalog by datacenter
Each DC runs a different stack. Madrid (Hostealo Shield, in-house) brings the widest catalog. EU (PletX / W&D Shield) covers the main presets plus a Custom filter where you define your own TCP values.
- AltVTCP
- FiveM Ultra StrictTCP
- Minecraft JavaTCP
- TibiaTCP
- AltVUDP
- Ark: Survival AscendedUDP
- TeamSpeak 3UDP
- TS3 Query/FiletransferTCP
- HTTPTCP
- HTTP StrictTCP
- TLSTCP
- SSL StrictTCP
- FTPTCP
- SSHTCP
- RDPTCP
- Remote Desktop ProtocolTCP
- RDPUDP
- DNSUDP
- OpenVPNUDP
- WireGuardUDP
New York runs Anti-DDoS Basic (generic volumetric protection, with no public per-application filter catalog).
Madrid only
Advanced panel · Hostealo Shield
Because it's an in-house system, in Madrid we expose direct control over per-IP scrubbing behaviour. Useful for clients with mixed traffic, persistent attacks or specific geo-filtering needs.
For external networks
IP Transit with Anti-DDoS
Do you run your own AS? We become your BGP upstream with scrubbing applied to all inbound traffic. Announce your prefix through our autonomous network and your network, as a downstream client, receives only clean traffic.
- Announce your IPv4 prefix with our autonomous network as your BGP upstream
- Hostealo Shield applied to all inbound traffic
- ASN / country blocking and IP lists managed by you
- LOA + RPKI managed, valid if you re-announce to your own BGP clients
- Works whether you have your own LIR or not
What's included (and what's not)
Included at no cost
- L3/L4 mitigation on all services
- Per-application filter auto-discovery
- Advanced per-IP panel (Madrid)
- 24/7 NOC monitoring sustained attacks
- No attack-traffic surcharge
Not included
- L7 mitigation (HTTP flood, bots, scraping) — handled server-side or with a WAF
- Anti-DDoS Basic in NY exposes no per-application filter catalog
- IP Transit with Anti-DDoS is quoted separately (not included with VPS/dedicated)
- Manual tuning outside Madrid (closed catalog)
FAQ
Frequently asked questions
We answer the most common questions. Still have one? Write to us and we'll reply within 24 hours.
Ready to protect your infrastructure?
Activation in under 24 hours for new customers. Auto-discovery does the rest.