Products / Network Protection
Network Protection
L3/L4 DDoS mitigation on AS402349's anycast edge. Volumetric floods, protocol abuse, and reflection attacks are dropped at wire speed in a datapath developed in-house.
Inside Network Protection
Five deep-dive pages cover the stack, from the datapath to analytics
In-House Filtering
How packets are parsed, judged, and dropped at the NIC driver, and why in-house filter code matters when attacks evolve.
Anycast Delivery
Anycast and unicast protected IPs, how clean traffic reaches your origin, and choosing a routing mode per service.
Attack Analytics
Every detection recorded server-side with exact totals: what hit you, when, how big, and what the edge did about it.
Trusted Networks
Declare your own infrastructure, or trust a whole provider: CIDRs, IP groups, and auto-updating lists for major clouds, all recognized as yours.
Game Query Caching
Server-browser queries like A2S answered from edge cache at every site, so query floods and player refreshes never touch your box.
What It Stops
SYN Floods
Judged and dropped at the driver before a socket ever exists. Spoofed floods are contained by SYN validation and per-source verdicts, so connection tables never fill.
UDP Floods & Amplification
Reflection and amplification traffic, including DNS, NTP, and SSDP abuse, is identified by protocol shape and rate, then dropped at line rate across every ingress PoP at once.
TCP State Abuse
Established-flow floods and junk data streams are policed by per-flow rate and state checks. Abuse that hides inside a real connection is judged by how it behaves, not how it arrived.
Game & Realtime Protocols
Port-level filtering profiles tuned for game and realtime traffic, so aggressive defense does not mean dropped players. Latency-sensitive UDP keeps flowing while the noise disappears.
See Every Attack
Detections are recorded server-side as a permanent ledger: exact traffic totals, not samples. The dashboard shows the same numbers your invoice does.
| Detected | Vector | Peak | Action | Status |
|---|---|---|---|---|
| 14:02:11 UTC | UDP flood | 412 Gbps | dropped at edge | mitigated |
| 09:47:53 UTC | SYN flood | 38 M pps | dropped at edge | mitigated |
| 02:13:36 UTC | TCP est. flood | 96 Gbps | rate-limited | mitigated |
Delivery Options
Anycast IPs for services that want the whole edge at once; unicast IPs pinned to a city for latency-critical workloads. Clean traffic forwards to any origin, or stays on-net with Sentry Compute.
Frequently Asked Questions
What is L3/L4 (network layer) DDoS protection?
Which network DDoS attacks does Gateway Sentry stop?
How does Gateway Sentry protect against UDP floods?
How does anycast routing help mitigate volumetric attacks?
What is reflection and amplification, and how is it filtered?
Get Protected in Minutes
Provision a protected IP from the dashboard and point your traffic at it. No contracts.