Selectel Protection
Selectel Protection is enabled by default for the following products:
- Dedicated servers;
- Colocation;
- Certified Data Center;
- Public Cloud powered by VMware;
- Cloud servers;
- Managed Kubernetes;
- Managed Databases.
For the Fault-tolerant load balancer product, a comprehensive protection solution is automatically enabled — DDoS-Guard L3-L4 protection.
DDoS mitigation
Types of attacks mitigated by Selectel Protection
Protection is provided at the network and transport (L3, L4) layers and protects services against the following attack types:
- UDP-based reflection attacks (DNS, NTP, memcache, etc.);
- attacks using fragmented IP traffic;
- TCP SYN/RST/PSH flood;
- various types of UDP flood;
- various types of ICMP flood.
Types of attacks not mitigated by Selectel Protection
Selectel Protection does not protect against application-layer (L7) DDoS attacks, as well as attacks that require the analysis of traffic in both directions for detection:
- attacks with valid TCP connections;
- attacks with valid HTTP and HTTPS requests;
- attacks on bottlenecks or vulnerabilities of the attacked service.
To improve service security, you can enable additional protection.
How it works
Selectel Protection is automatically enabled for all IP addresses in the Selectel autonomous system. Customer IP addresses (PI and those announced as part of the BGP Connectivity service), that are routed via the Selectel network, are also protected.
Selectel Protection analyzes incoming traffic only, without restrictions.
Depending on the type of attack detected, filters are dynamically configured on edge routers to block unwanted traffic. If the level of any traffic exceeds the specified threshold, the filter applies a restriction on its passage through the network. In this case, the traffic is not completely blocked; only the part related to the DDoS attack is excluded.
Pricing
Selectel Protection is provided free of charge.
Limitations
If an attack has a long-term negative impact on the network infrastructure, incoming traffic may be blocked using Remote Triggered Black Hole (RTBH).
If a decision to block is made, we create a ticket and send it to you. To remove the block, reply in the ticket. The block is automatically removed after eight hours.