---
title: "Curator protection"
sidebar_label: "Curator protection"
sidebar_position: 3
description: "How it works, pricing and traffic calculation, how to connect the service, configure it, and disconnect the service"
---

import Tabs from '@theme/Tabs';
import TabItem from '@theme/TabItem';
import MoreVerticalIcon from '@selectel/docux/icons/more-vertical';
import Formbricks from '@theme/MDXComponents/Formbricks';

# Curator protection

DDoS protection in partnership with [Curator](https://curator.pro/) is provided as an optional service for Selectel products:

* [Dedicated servers](/dedicated/);
* [Colocation](/server-colocation/);
* [Cloud servers](/cloud-servers/);
* [Managed Kubernetes](/managed-kubernetes/);
* [Container Registry](/craas/);
* [Managed databases](/managed-databases/);
* [Public Cloud powered by VMware](/public-cloud/).

Curator protection works at all levels of the network model, including the application layer (L7). In addition to the service, you can connect [WAF Curator](/waf/curator.mdx) to protect against targeted attacks on your web application.

## How it works \{#principle-of-operation}

You receive a protected address to which you need to redirect your traffic. All traffic to the protected address is sent to Curator filtering nodes, where it is analyzed and cleaned, and then redirected to the protected server in the Selectel infrastructure.

All Curator network nodes operate independently of each other. If the filtering node closest to you becomes unavailable, traffic is automatically redirected to the next closest node.

Activating the service will not protect against DDoS attacks if attackers know the target IP address. Before activating, you must remove all references to the IP addresses you want to protect from external resources. If the IP addresses are already under attack, you must order a new subnet and configure it on your servers.

## Pricing \{#price}

Service pricing includes:

* of the selected service tariff plan;
* the cost of additional protected IPv4 addresses if you need to protect more than one IP address. The first protected address is provided free of charge;
* payment for additional bandwidth if it exceeds 10 Mbps;
* the cost of a new subnet if it is required to connect the service.

You can view Curator protection pricing at [selectel.ru](https://selectel.ru/services/additional/ddos-protection/?section=prices).

On the day of activation, a one-time payment equal to the cost of the selected plan is charged. Subsequently, payment is automatically charged on the first day of each month. An invoice for additional [bandwidth](#bandwidth) is generated in the [control panel](https://my.selectel.ru/balance/add) within five business days after the end of the calendar month.

To pay for the service, depending on the account balance type, a [unified balance](/balance-and-payments/balance.mdx#united-balance) or [master balance](/balance-and-payments/balance.mdx#balances-by-service-type) is used.

### Calculating legitimate traffic bandwidth \{#bandwidth}

Only legitimate traffic—cleared of malicious requests—is billed.

To calculate bandwidth, the volume of incoming and outgoing traffic cleaned by the filtering system is measured every minute. From the obtained values, the maximum for each minute is selected. At the end of the calendar month, all maximum values are sorted in descending order. 90 maximum values are excluded from the calculation. The 91st maximum value is rounded down to the nearest whole number in Mbit/s — this number is the bandwidth value. If the value exceeds 10 Mbit/s, each additional Mbit/s is paid for separately.

### Calculating attack traffic bandwidth \{#bandwidth}

Attack traffic is not billed.

To calculate attack bandwidth, the volume of attack traffic is measured every three minutes. The 30 maximum values per month are not counted; the 31st maximum value is the bandwidth value. If an attack exceeds the bandwidth provided by the plan, the quality of traffic filtering may decrease. In this case, we will offer you to switch to the next plan for a period of at least three months. If you do not want to switch to the next plan but want to maintain the quality of filtering, you can limit all incoming traffic, including legitimate traffic, to the bandwidth specified in the plan.

## Connect service \{#enable-service}

Before connecting the service, [top up your balance](/balance-and-payments/manage/top-up-balance.mdx) with the [required amount](#price).

1. [Order and configure a new subnet](#order-and-configure-new-subnet) if your server only has a public shared address or public IP address, or if the server is already under attack.
2. [Order service](#order-service).
3. [Specify the protected address in the domain's A-record](#specify-protected-ip-in-a-record).
4. [Add a TLS(SSL) certificate](#add-tls-ssl-certificate).

### 1. Order and configure a new subnet \{#order-and-configure-new-subnet}

A new subnet is required if your server only has a public shared address or a public IP address `/32`, or if the server is under attack and the target IP is already known to attackers.

Order a subnet and configure an address from it on your server:

* for a dedicated server, use the [Connect additional public IP addresses](/dedicated/networks/public-networks-and-subnets.mdx#add-additional-ips) section of the [Dedicated server public networks and subnets](/dedicated/networks/public-networks-and-subnets.mdx) guide;
* for a cloud server, use the [Create public subnet](/cloud-servers/cloud-networks/public-subnets.mdx#create-public-subnet) section of the [Public subnets](/cloud-servers/cloud-networks/public-subnets.mdx) guide.

### 2. Order service \{#order-service}

1. In the [control panel](https://my.selectel.ru/network/antiddos), on the top menu, click **Products** and select **DDoS protection**.

2. Go to the **DDoS protection** section.

3. Click **Order services**.

4. In the row of the required Curator tariff plan (Professional, Business, Corporate), click **Pay**.

5. Check the details and click **Pay for service**.

6. We will create and send a [ticket](https://my.selectel.ru/tickets/create/) regarding your service order.

7. In this ticket, please send us:

   * the domain to be protected (subdomains will be protected automatically);
   * The IP address to which filtered traffic should be sent;
   * email for registration in the Curator client area. Login details for the client area will be sent to this email.

8. We will notify you about the activation in a ticket. Connection takes up to one business day.

### 3. Specify the protected IP address in the domain's A-record \{#specify-protected-ip-in-a-record}

1. Go to the control panel of your domain registrar where your domain records are stored.
2. In the A-record, change the value to the protected IP address received in the ticket when [ordering the service](#order-service).

### 4. Add a TLS(SSL) certificate \{#add-tls-ssl-certificate}

1. Open the [Curator client area](https://client.curator.pro/control/certificates/add). To log in, use the username and password you received via email when [ordering the service in step 2](#order-service).

2. Go to the **Certificate storage** section.

3. Click **Add certificate**.

4. If you do not have a TLS(SSL) certificate, you can issue a free Let's Encrypt® certificate that protects one domain:

   4.1. Open the **Use Let's Encrypt** tab.

   4.2. Click **Next**.

   4.3. Select the domain that will be used to obtain the certificate.

   4.4. Enter one or more domain names for which you need to issue a certificate.

   4.5. Click **Create certificate**.

5. If you have a TLS(SSL) certificate or want to protect multiple domains with the same IP address, add a certificate. The certificate for protecting multiple domains must be multi-domain: an SSL or UCC with the SAN option for protecting different domains, or a Wildcard for protecting a domain and its subdomains.

   5.1. Open the **Upload certificate** tab.

   5.2. Select the file.

   5.3. Click **Upload**.

## View statistics \{#check-statistics}

After connecting and configuring the service, you can view traffic statistics.

1. Log in to the [Curator client area](https://client.curator.pro/curator/reports/). To log in, use the username and password you received via email when [ordering the service](#order-service).

2. Go to the **Documents** section and select **Reports**. Here you can view statistics on incoming and filtered traffic. When generating statistics, you can use filters:

   * by type (traffic, packets, requests, etc.);
   * by time (five hours, day, week, month, etc.).

## Disconnect service \{#disable-service}

If you disconnect the service before the end of the paid month, the payment for the remaining unused days is non-refundable.

1. Make sure you have reconfigured traffic reception to the address from your subnet. The protected address issued when activating the service will be disabled along with the protection.
2. Open the control panel of your domain registrar where your domain records are stored.
3. In the domain's A-record, change the value to an address from your subnet.
4. In the [control panel](https://my.selectel.ru/network/antiddos), on the top menu, click **Products** and select **DDoS protection**.
5. Go to the **DDoS protection** section.
6. In the <MoreVerticalIcon /> service menu, select **Disable monthly payment**.

<Formbricks />
