Skip to main content
Gcore DDoS Protection safeguards networks, servers, and instances against distributed denial-of-service (DDoS) attacks. Two protection modes are available: Basic (free, enabled by default) and Advanced (paid, always-on filtering via a Threat Mitigation System (TMS)).
This article covers Basic protection for Gcore-hosted resources and Advanced protection for customer networks onboarded through Generic Routing Encapsulation (GRE). Basic protection is applied automatically to all Gcore-hosted resources with no enrollment required. Advanced protection is a paid service activated through the GRE-based onboarding flow.Bare Metal servers and dedicated servers are not covered here; they use separate procedures with different specifications and pricing:

Protection modes

The two modes differ in detection speed, traffic coverage, and cost.
Detection times apply to network protection. Advanced DDoS Protection for Bare Metal servers and dedicated servers detects attacks within 5 seconds.

Basic protection

Basic protection is applied automatically to all Gcore-hosted resources. No additional enrollment or network submission is required.

Access control list (ACL) rules

Basic protection uses predefined ACL rules to block the following traffic types:
  • Reflection attacks: DNS, NTP, SSDP, MSSQL, LDAP, SNMP, CharGen, Memcache, Echo, RIP, ARMS
  • Fake source IP attacks: 0.0.0.0/32, 127.0.0.0/8, 192.0.2.0/24, 224.0.0.0/3, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16
Volumetric filtering on Basic protection does not apply to floods below 200 Mbit/s per destination IP. To customize ACL rules, upgrade to Advanced protection.

Null-routing

When Basic protection detects a DDoS attack, the system temporarily blocks the targeted IP address. This mechanism is known as null-routing: the targeted IP address is protected from attack traffic but becomes unreachable from the internet for 12 hours. To keep the service available during an attack, upgrade to Advanced protection.

Advanced protection

Advanced protection keeps the TMS active at all times, including when no attack is underway, so filtering starts the moment traffic turns malicious instead of only after an attack begins. Activate Advanced protection in the Gcore Customer Portal using the self-service setup flow. Start with service activation, which covers plan activation, network submission, Network Operations Center (NOC) review, and network configuration.

Allowlists

IP addresses added to an allowlist are treated as trusted resources. For Enterprise customers, allowlisted IPs bypass DDoS Protection analysis entirely and are not inspected by TMS. For customers on public plans, allowlisted IPs remain subject to DDoS traffic filtering.

DDoS attack statistics

The DDoS attack statistics dashboard provides a live overview of traffic on protected resources. Filter by data center, time interval, and traffic type. Three traffic categories are displayed:
  • Input — all traffic received before filtering
  • Dropped — traffic blocked by TMS as malicious
  • Passed — clean traffic forwarded to the protected IP address
Each category shows real-time metrics in bits per second (bps) and packets per second (pps). Outside the chart, each category also displays a 95th percentile value (bits_95 and packets_95). The 95th percentile of clean traffic volume is the billing metric for the Advanced protection service. For the applicable measurement period and billing rules, see Plan activation.
DDoS attack statistics

Pricing

Advanced network protection pricing depends on the plan tier and the data center location.
  • Plan tier. Plan activation lists the available tiers — pay as you go (PAYG), Start, Pro, and Pro+ — based on the clean traffic volume and number of network prefixes to protect.
  • Data center location. Prices vary by data center. Contact the Gcore sales team for pricing at a specific location.
Every tier covers L3–L7 attacks by default. For custom configurations, contact the Gcore sales team to request a tailored plan. For Bare Metal and dedicated server protection, pricing depends on the data center location, the traffic capacity, and the protected OSI layers. See Advanced DDoS Protection for Bare Metal and DDoS protection for dedicated servers for details.