Gateway Sentry

Products / Network Protection

Network Protection

L3/L4 DDoS mitigation on AS402349's anycast edge. Volumetric floods, protocol abuse, and reflection attacks are dropped at wire speed in a datapath developed in-house.

$3.50 per TB$4.39 per IP<1 s to mitigateglobal anycast edge

What It Stops

SYN Floods

Judged and dropped at the driver before a socket ever exists. Spoofed floods are contained by SYN validation and per-source verdicts, so connection tables never fill.

UDP Floods & Amplification

Reflection and amplification traffic, including DNS, NTP, and SSDP abuse, is identified by protocol shape and rate, then dropped at line rate across every ingress PoP at once.

TCP State Abuse

Established-flow floods and junk data streams are policed by per-flow rate and state checks. Abuse that hides inside a real connection is judged by how it behaves, not how it arrived.

Game & Realtime Protocols

Port-level filtering profiles tuned for game and realtime traffic, so aggressive defense does not mean dropped players. Latency-sensitive UDP keeps flowing while the noise disappears.

See Every Attack

Detections are recorded server-side as a permanent ledger: exact traffic totals, not samples. The dashboard shows the same numbers your invoice does.

Attack ledger example data
DetectedVectorPeakActionStatus
14:02:11 UTCUDP flood412 Gbpsdropped at edgemitigated
09:47:53 UTCSYN flood38 M ppsdropped at edgemitigated
02:13:36 UTCTCP est. flood96 Gbpsrate-limitedmitigated

Delivery Options

Anycast IPs for services that want the whole edge at once; unicast IPs pinned to a city for latency-critical workloads. Clean traffic forwards to any origin, or stays on-net with Sentry Compute.

ANYCAST IP
Announced across the global network; attacks fragment globally.
UNICAST IP
Pinned to a specific city for deterministic latency.
ON-NET ORIGIN
Run the workload on Sentry Compute; zero hops leave the edge.

Frequently Asked Questions

What is L3/L4 (network layer) DDoS protection?
L3/L4 DDoS protection defends the network and transport layers, where attackers flood your infrastructure with raw packets rather than application requests. Gateway Sentry inspects inbound TCP and UDP traffic at the edge and drops malicious packets at line rate before they reach your application.
Which network DDoS attacks does Gateway Sentry stop?
Gateway Sentry mitigates SYN floods, ACK floods, UDP floods and volumetric reflection or amplification attacks including DNS amplification, NTP reflection and SSDP amplification. Each vector is identified and dropped at the network edge instead of consuming origin server resources.
How does Gateway Sentry protect against UDP floods?
UDP floods saturate bandwidth with datagrams aimed at random ports, forcing servers to answer with ICMP unreachable messages. Gateway Sentry absorbs and filters the flood at the edge so legitimate UDP traffic for gaming, VoIP and custom applications passes through uninterrupted.
How does anycast routing help mitigate volumetric attacks?
Anycast routing sends inbound packets to the nearest of Gateway Sentry's edge PoPs, distributing volumetric attack traffic across the global network so it can be filtered close to its source. This minimizes latency for clean traffic while scrubbing attacks before they concentrate on a single origin.
What is reflection and amplification, and how is it filtered?
Reflection and amplification attacks spoof your IP to abuse open DNS, NTP or SSDP services, which then send oversized responses to your infrastructure. Gateway Sentry uses protocol-aware filtering and source validation at the edge to fingerprint and drop reflected traffic in real time.

Get Protected in Minutes

Provision a protected IP from the dashboard and point your traffic at it. No contracts.