Curator protection
DDoS protection in partnership with Curator is provided as an optional service for Selectel products:
- Dedicated servers;
- Colocation;
- Cloud servers;
- Managed Kubernetes;
- Container Registry;
- Managed databases;
- Public Cloud powered by VMware.
Curator protection works at all levels of the network model, including the application layer (L7). In addition to the service, you can connect WAF Curator to protect against targeted attacks on your web application.
How it works
You receive a protected address to which you need to redirect your traffic. All traffic to the protected address is sent to Curator filtering nodes, where it is analyzed and cleaned, and then redirected to the protected server in the Selectel infrastructure.
All Curator network nodes operate independently of each other. If the filtering node closest to you becomes unavailable, traffic is automatically redirected to the next closest node.
Activating the service will not protect against DDoS attacks if attackers know the target IP address. Before activating, you must remove all references to the IP addresses you want to protect from external resources. If the IP addresses are already under attack, you must order a new subnet and configure it on your servers.
Pricing
Service pricing includes:
- of the selected service tariff plan;
- the cost of additional protected IPv4 addresses if you need to protect more than one IP address. The first protected address is provided free of charge;
- payment for additional bandwidth if it exceeds 10 Mbps;
- the cost of a new subnet if it is required to connect the service.
You can view Curator protection pricing at selectel.ru.
On the day of activation, a one-time payment equal to the cost of the selected plan is charged. Subsequently, payment is automatically charged on the first day of each month. An invoice for additional bandwidth is generated in the control panel within five business days after the end of the calendar month.
To pay for the service, depending on the account balance type, a unified balance or master balance is used.
Calculating legitimate traffic bandwidth
Only legitimate traffic—cleared of malicious requests—is billed.
To calculate bandwidth, the volume of incoming and outgoing traffic cleaned by the filtering system is measured every minute. From the obtained values, the maximum for each minute is selected. At the end of the calendar month, all maximum values are sorted in descending order. 90 maximum values are excluded from the calculation. The 91st maximum value is rounded down to the nearest whole number in Mbit/s — this number is the bandwidth value. If the value exceeds 10 Mbit/s, each additional Mbit/s is paid for separately.
Calculating attack traffic bandwidth
Attack traffic is not billed.
To calculate attack bandwidth, the volume of attack traffic is measured every three minutes. The 30 maximum values per month are not counted; the 31st maximum value is the bandwidth value. If an attack exceeds the bandwidth provided by the plan, the quality of traffic filtering may decrease. In this case, we will offer you to switch to the next plan for a period of at least three months. If you do not want to switch to the next plan but want to maintain the quality of filtering, you can limit all incoming traffic, including legitimate traffic, to the bandwidth specified in the plan.
Connect service
Before connecting the service, top up your balance with the required amount.
- Order and configure a new subnet if your server only has a public shared address or public IP address, or if the server is already under attack.
- Order service.
- Specify the protected address in the domain's A-record.
- Add a TLS(SSL) certificate.
1. Order and configure a new subnet
A new subnet is required if your server only has a public shared address or a public IP address /32, or if the server is under attack and the target IP is already known to attackers.
Order a subnet and configure an address from it on your server:
- for a dedicated server, use the Connect additional public IP addresses section of the Dedicated server public networks and subnets guide;
- for a cloud server, use the Create public subnet section of the Public subnets guide.
2. Order service
-
In the control panel, on the top menu, click Products and select DDoS protection.
-
Go to the DDoS protection section.
-
Click Order services.
-
In the row of the required Curator tariff plan (Professional, Business, Corporate), click Pay.
-
Check the details and click Pay for service.
-
We will create and send a ticket regarding your service order.
-
In this ticket, please send us:
- the domain to be protected (subdomains will be protected automatically);
- The IP address to which filtered traffic should be sent;
- email for registration in the Curator client area. Login details for the client area will be sent to this email.
-
We will notify you about the activation in a ticket. Connection takes up to one business day.
3. Specify the protected IP address in the domain's A-record
- Go to the control panel of your domain registrar where your domain records are stored.
- In the A-record, change the value to the protected IP address received in the ticket when ordering the service.
4. Add a TLS(SSL) certificate
-
Open the Curator client area. To log in, use the username and password you received via email when ordering the service in step 2.
-
Go to the Certificate storage section.
-
Click Add certificate.
-
If you do not have a TLS(SSL) certificate, you can issue a free Let's Encrypt® certificate that protects one domain:
4.1. Open the Use Let's Encrypt tab.
4.2. Click Next.
4.3. Select the domain that will be used to obtain the certificate.
4.4. Enter one or more domain names for which you need to issue a certificate.
4.5. Click Create certificate.
-
If you have a TLS(SSL) certificate or want to protect multiple domains with the same IP address, add a certificate. The certificate for protecting multiple domains must be multi-domain: an SSL or UCC with the SAN option for protecting different domains, or a Wildcard for protecting a domain and its subdomains.
5.1. Open the Upload certificate tab.
5.2. Select the file.
5.3. Click Upload.
View statistics
After connecting and configuring the service, you can view traffic statistics.
-
Log in to the Curator client area. To log in, use the username and password you received via email when ordering the service.
-
Go to the Documents section and select Reports. Here you can view statistics on incoming and filtered traffic. When generating statistics, you can use filters:
- by type (traffic, packets, requests, etc.);
- by time (five hours, day, week, month, etc.).
Disconnect service
If you disconnect the service before the end of the paid month, the payment for the remaining unused days is non-refundable.
- Make sure you have reconfigured traffic reception to the address from your subnet. The protected address issued when activating the service will be disabled along with the protection.
- Open the control panel of your domain registrar where your domain records are stored.
- In the domain's A-record, change the value to an address from your subnet.
- In the control panel, on the top menu, click Products and select DDoS protection.
- Go to the DDoS protection section.
- In the service menu, select Disable monthly payment.