Skip to main content
Edge Proxy protects applications from DDoS attacks by routing traffic through the Gcore CDN edge network. Protection is active within minutes, without deploying additional infrastructure or configuring complex networking.

Traffic flow

Clients connect to the Edge Proxy address instead of connecting directly to the origin.
Edge Proxy traffic flow — client to Anycast IP, PoP filtering drops DDoS traffic, clean traffic forwarded to origin
Incoming traffic routes through Anycast IP addresses to the nearest Point of Presence, where Gcore filters DDoS traffic at the edge. Gcore then forwards clean traffic to the origin server. Each protected server receives a dedicated proxy IP address. Edge Proxy applies a filtering profile from Supported applications to game servers, APIs, backend services, and other TCP or UDP applications. With traffic routed through the Gcore edge network, Edge Proxy provides:
  • High availability — traffic is distributed across multiple PoPs, reducing dependence on a single location and providing multi-terabit filtering capacity.
  • Lower latency — processing at the nearest PoP reduces round-trip time and improves responsiveness.
  • Simple setup — configured in a few steps without managing virtual machines or networking components.
  • Efficient IP usage — multiple servers share the same Anycast infrastructure, so no additional transit or IP allocation is required per server.
  • Flexible configuration — multiple applications and ports can be protected behind a single proxy IP.

Core concepts

The following terms appear throughout the Edge Proxy documentation. After setup, Traffic Overview shows traffic metrics for the protected server.