DDoS-Guard Protection
DDoS-Guard protection is a solution based on a partner product from DDoS-Guard. The following services are available:
-
DDoS-Guard L3-L4 protection operates at the network (L3) and transport (L4) layers. It protects against DDoS attacks that exploit vulnerabilities in TCP/IP protocols and are aimed at exhausting bandwidth and disrupting network infrastructure;
-
DDoS-Guard website protection and acceleration operates at the application (L7) layer. It allows you to block attacks on web applications and websites, and accelerates apps or sites using CDN and load balancing. The service can be activated in combination with the DDoS-Guard L3-L4 protection service or separately.
DDoS-Guard L3-L4 Protection
How it works
The service protects only IP addresses assigned to equipment in the Selectel infrastructure. The service can only be activated for addresses from a public dedicated subnet or a public subnet. Activation is not available for addresses from a shared subnet (/32) or public IP addresses.
You receive a secure public IPv4 address and configure traffic reception through it on your server. The address must be assigned to the network interface of the public network as an additional one.
By default, the service comes with one secure IP address. If you need to protect multiple servers in a pool, you must order additional secure IP addresses for them.
Incoming traffic directed to the secure address passes through filtering nodes located around the world, where it is analyzed and scrubbed. Every incoming packet is filtered. Scrubbed traffic is then routed to the server's primary address.
Pricing
The service cost consists of:
- from the selected DDoS-Guard L3-L4 Protection plan with the required throughput — 10, 20, 50, or 100 Mbps;
- cost of additional secure IPv4 addresses. The first secure address is provided free of charge; you must order an additional secure address for each additional server in the pool;
- the cost of a new subnet, if it is required to connect the service.
You can view the DDoS-Guard L3-L4 Protection service plan prices on selectel.ru.
The service is billed monthly; when ordering the service, the payment for the first month is deducted from the balance, and subsequent payments are deducted automatically at the beginning of each following period.
Depending on the type of balance in your account, a unified balance or master balance is used to pay for the service.
Order the service
- If your server only has a shared public address or a public IP address, or your servers are already under attack, order and configure a new subnet.
- Order DDoS-Guard L3-L4 Protection.
- If you need to protect more than one server in the pool, order additional protected IP addresses.
- Configure the protected IP address on the server.
- If you are connecting protection for a cloud server, add the protected IP address as an allowed IP address on the port.
1. Order and configure a new subnet
A new subnet is required if:
- your server only has a shared public address (
/32); - or your servers are under attack and the target IP address is already known to attackers.
Order a subnet and configure an address from it on your server:
- for a dedicated server, use the Connect additional public IP addresses section of the Dedicated Server Public Networks and Subnets guide;
- for a cloud server, use the Configure internet access via a public subnet section of the Configure internet access guide.
2. Order the service
If you need to protect equipment in different pools, connect a separate protection service for each pool.
Before connecting the service, top up your balance with the required amount.
-
In the control panel, on the top menu, click Products and select DDoS Protection.
-
Go to the DDoS Protection section.
-
Click Order services.
-
In the row for the DDoS-Guard DDoS Protection (L3-L4) service with the required throughput (10, 20, 50, 100 Mbps), click Pay.
-
Verify the details and click Pay for service.
-
We will create a ticket to connect the service.
-
In this ticket, send us:
- IP address to be protected;
- the email for registration in the DDoS-Guard control panel. Credentials for the control panel will be sent to this email.
-
We will notify you about the connection in the ticket.
3. Order additional protected IP addresses
The protection service includes one secure IP address. If you need to protect more than one server in your pool, order an additional secure address for each of them.
- In the control panel, on the top menu, click Products and select DDoS Protection.
- Go to the DDoS Protection section.
- Click Order services.
- In the row for the DDoS-Guard DDoS Protection (L3-L4) — additional IP address service, click Pay.
- Click Pay for service.
4. Configure the protected IP address on the server
Ubuntu
Debian
CentOS
Windows
-
Open the
netplanutility configuration file using thevitext editor:vi /etc/netplan/50-cloud-init.yamlor
vi /etc/netplan/01-netcfg.yaml -
Append the additional address details to the end of the file:
<eth_name>:0:addresses: [<ip_address>/32]Specify:
<eth_name>— the name of the network interface to which the additional address should be added;<ip_address>— the protected IP address you received in the ticket.
-
Press the
ESCkey. -
Exit the
vitext editor and save your changes::wq -
Apply the configuration:
netplan apply -
Optional: reboot the server.
-
Set all server applications to work with the protected IP address.
5. Add the protected IP address as an allowed IP address on the cloud server port
If you are connecting protection for a cloud server and traffic filtering (port security) is enabled in its public subnet, add the protected address as an allowed IP address on the port where you configured the protected address.
-
Check the traffic filtering (port security) status on the server network:
1.1. In the control panel, on the top menu, click Products and select Cloud Servers.
1.2. Go to the Network section → Public networks tab.
1.3. View the public subnet card for the IP address you configured on the server. If the subnet is marked with , traffic filtering (port security) is enabled for the network.
-
If traffic filtering is disabled for the subnet, no additional configuration is required. If filtering is enabled, add the secure IP address as an allowed IP address on the cloud server port:
Control panel
OpenStack CLI
2.1. In the control panel, on the top menu, click Products and select Cloud Servers.
2.2. Open the server page → Ports tab.
2.3. In the row for the port where you assigned the protected address, in the Security groups field, click .
2.4. Click Add IP/MAC pair.
2.5. Enter the protected IP address that you received in the ticket.
2.6. Enter the MAC address that corresponds to the IP address or leave the default port MAC address. Do not use addresses from the
00:00:5e:00:01:82–00:00:5e:00:01:c6range. These MAC addresses are reserved by Selectel network hardware; using them will result in traffic being blocked at the cloud server interface.2.7.Click Save.
View statistics
- Go to your DDoS-Guard cabinet. You can find your login credentials in the service activation ticket.
- Open the IP Transit tab. This shows traffic statistics before scrubbing by filters. Graphs are based on five-minute traffic samples, so traffic spikes may be smoothed out.
Disable the service
-
Ensure that you have reconfigured traffic reception to an address from your subnet. The secure address you received when ordering the service will be disabled along with the protection service.
-
In the control panel, on the top menu, click Products and select DDoS protection.
-
Go to the DDoS protection section.
-
In the menu for the service, select Disable monthly payment. The service will remain active until the end of the paid period.
-
We will deactivate the service after the end of the paid period.
DDoS-Guard Website Protection and Acceleration
How it works
After ordering the service, you receive a secure address you need to redirect your traffic to. All traffic to the secure address is sent to DDoS-Guard filtering nodes, where it is analyzed and scrubbed, and then forwarded to the protected server in the Selectel infrastructure.
The protection works with HTTP and HTTPS requests only on ports 80 and 443; requests to other ports are not processed.
Activating this service will not protect against a DDoS attack if the target IP address is known to the attackers. Before activation, you must remove all references to the IP addresses you want to protect from public resources. If the IP addresses are already under attack, you must order a new subnet and configure it on your servers.
Pricing
The following service plans are available: Normal, Medium, Premium, Enterprise. Their key differences are:
- number of protected domains;
- number of servers for load balancing;
- number of rules for restricting access by IP address. You can purchase an additional rules package for any plan via a ticket;
- possibility of flexible filtering rule configuration.
The filtering bandwidth and traffic volume, including legitimate traffic, are unlimited.
You can view a detailed comparison of plans and their costs on selectel.ru.
The service is billed monthly; when ordering the service, the payment for the first month is deducted from the balance, and subsequent payments are deducted automatically at the beginning of each following period.
Depending on the account balance type, either a single balance or a master balance is used to pay for the service.
Order the service
The minimum service term is 1-2 days. If you require urgent protection activation, create a ticket specifying the domain and IP address you want to protect, and an email address for DDoS-Guard account registration. After creating the ticket, call us.
- If malicious actors already know the domain IP address, order and configure a new subnet.
- Order the DDoS-Guard website protection and acceleration service.
- Specify the protected IP address in the domain A record.
- Optional: restrict server access from IP addresses.
- Optional: configure additional protection.
1. Order and configure a new subnet
A new subnet is required if your servers are under attack and the target IP address is already known to attackers.
Order a subnet and configure an address from it on your server:
- for a dedicated server, use the Connect additional public IP addresses section of the Public networks and subnets for dedicated servers guide;
- for a cloud server, use the Create a public subnet section of the Public subnets guide.
2. Order the service
Before activating the service, top up your balance with the required amount.
-
In the control panel, on the top menu, click Products and select DDoS protection.
-
Go to the DDoS protection section.
-
Click Order services.
-
In the row for the required plan, DDoS-Guard. Website protection and acceleration (Normal, Medium, Premium, Enterprise), click Pay.
-
Verify the information and click Pay for service.
-
We will create a ticket for service activation and specify the activation date.
-
In this ticket, send us:
- the domain to be protected;
- domain IP address. You can specify multiple IP addresses if they point to one domain and you need load balancing between them;
- the email for registration in the DDoS-Guard control panel.
-
We will notify you when the service is connected.
3. Specify the protected IP address in the domain A record
- Go to the DDoS-Guard personal account.
- Enter the username and password received by email when ordering the service.
- Open the Website Protection and Acceleration service page.
- Open the Domains tab.
- Save the protected IP address specified in the Protected IP field.
- Go to the control panel of the domain registrar where your domain records are stored.
- In the domain A record, change the value to the protected IP address you copied in step 5. Do not change the A record value intended for mail server or FTP server traffic.
- If AAAA records are specified for the domain, remove them. DDoS-Guard does not work with IPv6 addresses; these can be attacked, bypassing protection.
- If you want to protect subdomains, add an A record with a secure IP address for each one. An unlimited number of subdomains can be protected.
4. Optional: restrict connection to the server by IP addresses
You can restrict access to the server from all IP addresses, except for trusted DDoS-Guard IP addresses. Learn more about configuration in the Firewall configuration subsection of the L7 protection configuration DDoS-Guard documentation.
5. Optional: configure additional protection
You can configure additional protection in your DDoS-Guard account. For example, configure traffic filtering rules, enable geo-blocking, or other options. A full list of options is available in the Website protection section of the DDoS-Guard documentation.
To configure additional protection:
- Log in to your account. To log in, use the username and password you received via email when ordering the service.
- Perform the configuration according to the necessary instructions in the Website protection section of the DDoS-Guard documentation.
View statistics
- Go to your account. To log in, use the username and password you received via email when ordering the service.
- View statistics by following the L7 attacks and attack reports guide in the DDoS-Guard documentation.
Disable the service
- Ensure that you have reconfigured traffic reception to an address from your subnet. The secure address you received when ordering the service will be disabled along with the protection service.
- Open the control panel of the domain registrar where your domain records are stored.
- In the domain A record, change the value to an address from your subnet.
- In the control panel, on the top menu, click Products and select DDoS protection.
- Go to the DDoS protection section.
- In the menu for the service, select Disable monthly payment. The service will remain active until the end of the paid period.
- We will deactivate the service after the end of the paid period.