Curator's defense
DDoS protection in partnership with Curator is available as an optional service for Selectel products:
- Dedicated servers;
- Equipment Placement;
- Cloud servers;
- Managed Kubernetes;
- Container Registry;
- Cloud databases;
- VMware-based public cloud.
Curator protection works at all layers of the network model, including the application layer (L7).Additionally, WAF Curator can be connected to the service to protect against targeted attacks on the web application.
Principle of operation
All traffic to the protected address is sent to Curator filtering nodes, where it is analyzed and cleaned, and then redirected to the protected server in the Selectel infrastructure.
All nodes in the Curator network operate independently of the others.If the filtering node closest to you becomes unavailable, traffic is automatically redirected to the next closest node.
Connecting the service will not protect against DDoS attacks if the attackers know the target IP address.Before connecting, you should remove from external resources all mentions of IP addresses you want to protect.If IP addresses are already under attack, you should order a new subnet and configure it on your servers.
Cost
The cost of the service adds up:
- from the selected service tariff;
- The cost of additional secure IPv4 addresses if you need to protect more than one IP address.The first secure address is free of charge;
- paying for additional bandwidth if it exceeds 10 Mbps;
- the cost of a new subnet if it is needed to connect the service.
You can see the prices for Curator Protection service tariffs at selectel.ru.
On the day of connection a one-time payment equal to the cost of the selected tariff is deducted.Then the payment is deducted automatically on the first day of each month.The invoice for payment of additional bandwidth is generated in the control panel within five working days after the end of the calendar month.
A single balance or a basic balance is used to pay for the service depending on the type of balance in the account.
Calculating the bandwidth of legitimate traffic
Only legitimate traffic — cleared of malicious requests — is charged.
To calculate the bandwidth every minute the volume of incoming and outgoing traffic, which was cleared by the filtering system, is measured.The maximum value for each minute is selected from the obtained values.At the end of the calendar month all maximum values are sorted in descending order.90 maximum values are excluded from the calculation.91st maximum value is rounded down to a whole number of Mbit/s — this number is the bandwidth value.If the value exceeds 10 Mbit/s, each additional Mbit/s is paid separately.
Calculating the bandwidth of attack traffic
Attack traffic is not charged.
To calculate the bandwidth of attacks, the volume of attack traffic is measured every three minutes.30 maximum values per month are not taken into account, the 31st maximum value is the bandwidth value.If an attack exceeds the bandwidth provided by the tariff, the quality of traffic filtering may deteriorate.In this case, we will offer you to switch to the next tariff plan for a period of at least three months.If you do not want to switch to the next tariff plan, but want to maintain the quality of filtering, you can limit all incoming traffic, including legitimate traffic, to the bandwidth specified in the tariff.
Connect the service
Before activating the service , top up the balance by the required amount.
- Order and configure a new subnet If your server only has a public shared address or public IP address, or if the server is already under attack.
- Order a favor.
- Specify a protected address in the domain's A-record.
- Add a TLS(SSL)-certificate.
1. Order and configure a new subnet
A new subnet is required if your server only has a public shared address or public IP address /32, or if the server is under attack and the target IP address is already known to the attackers.
Order a subnet and configure the address from it on the server:
- For a dedicated server, use the Connect additional public IP addresses subsection of the dedicated server IP address instructions;
- For a cloud server, use the Create a public subnet subsection of the Public Subnets instruction.
2. Order a service
-
In the control panel, click Products in the top menu and select DDoS Protection.
-
Go to the DDoS Protection section.
-
Click Order Services.
-
In the line of the desired Curator tariff (Professional, Business, Corporate), click Pay.
-
Verify the details and click Pay for Service.
-
We will create and send a service order ticket.
-
In this ticket, send us:
- domain to be protected (subdomains will be protected automatically);
- The IP address to which to send the filtered traffic;
- email for registration in Curator's personal cabinet. The data for entering the personal cabinet will be sent to this email.
-
We will notify you of the connection in a ticket.Connection takes up to one business day.
3. Specify a secure IP address in the domain A record
- Go to your domain registrar's control panel where your domain records are stored.
- In the A record, change the value to the secure IP address that you received in the ticket when ordering the service.
4. Add a TLS(SSL)-certificate
-
Open your Curator's personal account and use the login and password you received by email when ordering the service in step 2.
-
Navigate to the Certificate Store section.
-
Click Add Certificate.
-
If you don't have a TLS(SSL)-certificate, you can issue a free Let's Encrypt® certificate that protects a single domain:
4.1 Open the Use Let's Encrypt tab.
4.2 Click Next.
4.3 Select the domain that will be used to obtain the certificate.
4.4 Enter one or more domain names for which you want to issue a certificate.
4.5 Click Create Certificate.
-
If you have a TLS(SSL)-certificate or want to protect multiple domains with the same IP address, add a certificate.A certificate to protect multiple domains should be multi-domain: to protect different domains — SSL or UCC with SAN option, to protect a domain and subdomains — Wildcard.
5.1 Open the Upload Certificate tab.
5.2. Select a file.
5.3 Click Upload.
View statistics
After connecting and configuring the service, you can view statistics on traffic.
-
Log in to your Curator's personal account. To log in, use the login and password you received by email when ordering the service.
-
Go to the Documents section and select Reports.Here you can view statistics on incoming and filtered traffic.You can use filters when building statistics:
- by type (traffic, packets, requests, and so on);
- by time (five hours, a day, a week, a month, and so on).
Deactivate the service
If you wish to disconnect the service before the end of the paid month, payment for the unused balance of the month will not be refunded.
- Make sure that you have reconfigured traffic reception to an address from your subnet.The protected address issued when you connected the service will be deactivated along with the protection.
- Open your domain registrar's control panel where your domain records are stored.
- In the domain A record, change the value to an address from your subnet.
- In the control panel, click Products in the top menu and select DDoS Protection.
- Go to the DDoS Protection section.
- From the menu of the service, select Disable Monthly Payment.