Anti-DDoS Profiles - Alpha
Anti-DDoS Profiles - global protection now tuned to your workloads
Tell your global DDoS protection at OVHcloud what applications do you run and where. It adapts then for fewer false alarms on heavy legitimate traffic and sharper real network attack mitigation.
Protection aligned with your traffic
OVHcloud Anti-DDoS Infrastructure protects internet facing servers and services, at no extra cost. Generic detection works great for most of the protected applications, but still can misread some more specific, thus legitimate workloads: a busy WireGuard tunnel looks like a UDP flood, a live-event audience spikes look like a volumetric attack, or some blockchain gossip may look like a botnet.
Anti-DDoS profiling let you describe such services more precisely instead of working around the protection. Pick a profile from the catalog, choose a sensitivity level, and attach your services. One change re-tunes your whole fleet - as simple as that! If your workload changes, switch profiles or adjust sensitivity.
Anti-DDoS profiling benefits
Secured traffic-intensive apps
Advanced protection for VPN tunnels, media streaming spikes or blockchain protocols is now in your hands! Anti-DDoS Profiles precisely define the legitimate behavior of the trickiest workloads - so you get fewer false-positive alarms.
Enhanced defense
With your services grouped and defined, protection sharpens: volumetric floods, reflection and amplification attacks are mitigated more precisely, with most care for your workloads.
Simple use
Group your services together and link them to the profile and sensitivity that match your needs - easy to manage, easy to change. Test and deploy at any time, directly from the Control Panel or the API.
Price, unchanged
No additional costs to use basic Anti-DDoS (VAC) Profiles - they extend the protection you already have for services within OVHcloud.
Key features
Profile catalog tuned by OVHcloud
This Alpha starts with the most-popular and most-requested application profiles on VAC Anti-DDoS, based on your feedbacks. More profiles will follow.
Adjustable sensitivity
Every profile offers few sensitivity levels: lower means fewer false positives on bursty legitimate traffic, higher means the most aggressive filtering during sophisticated attacks.
Fleet-level management
Attach many IPs to one policy; a single sensitivity change re-tunes all of them at once. IPv4 addresses are attached individually or per IP block, IPv6 per /64 or /56 (IPv6 settings will be offered since Beta).
Visibility built in
See which profile protects each IP, and filter mitigation events by profile in the Network Security Dashboard. Trace any profiling or resource changes over time.
Cloud-native
Profiles can be easily linked with your Public Cloud resources - specific project, nodes or kubernetes PODs. What's even more important - no more need to worry when your resources scale automatically!
Works with what you have
Profiling complement existing Anti-DDoS Infrastructure components, Edge Network Firewall rules, the Network Security Dashboard; nothing about your current setup needs to change.
How to join Anti-DDoS Profiles Alpha
Take part in the program and help us shape OVHcloud Anti-DDoS Profiles.
- Apply - fill in the survey and tell us about your workload: service type, traffic pattern, and other specific needs you have today.
- Get selected - our product team reviews applications and contacts selected testers.
- Activate - we enable Anti-DDoS Profiles on your account, for listed IP addresses with selected profile. You will get the information and will be able to observe results in Network Security Dashboard in the Control Panel.
- Change profile - you will be able to ask for profile change, modify sensitivity or add/remove IPs. Once API will be available, you will also be able to manipulate settings on your own.
- Observe and share feedback - watch the effect in the Network Security Dashboard. Does it meet your expectations? Tell us what works and what doesn't. Your feedback directly shapes the profile tuning and the beta scope.
More details on Anti-DDoS profiling will be available soon on documentation page.
FAQ
Q1. Who can join the alpha?
Any OVHcloud customer who want to enhance Anti-DDoS protection or whose workload suffers from DDoS false positive alerts can apply.
As capacity is limited, we prioritize specific workloads to ensure best outcomes.
Please note that access to the Alpha is at the discretion of OVHcloud.
Q2. How much does it cost?
Nothing. Anti-DDoS Profiles are included with the Anti-DDoS Infrastructure that already protects your OVHcloud services. The alpha is free, and the core feature remains free at general availability. Paid advanced options may be introduced later.
Q3. Will this weaken my protection?
No. Profiles simplify management and refine detection for your declared workload; all other attack vectors are mitigated as of today. If you remove a profile - your IPs keep the standard protection.
Q4. Which profiles are available during the alpha?
We prioritize VPN/UDP, Blockchain/Solana and Streaming protocols first. Additional profiles are planned for the later evolution.
Q5. How can I manage profiles?
During the Alpha phase, please fill-in the recruitment form to share your requested settings. Once you're onboarded, we will contact you and inform about changes.
Q6. What is expected from me as an alpha tester?
Real traffic and honest feedback: apply a profile to a workload that suffers false
positives today, observe the results in the Network Security Dashboard, and report both improvements and misbehavior. A short feedback loop with our product team is part of the program.
Q7. Does it support IPv6?
During Alpha phase we focus on the most-common features, thus IPv4 is the only protocol supported.
IPv6 support will be offered from Beta.
Q8. What is the product compatibility?
All public IPv4 (and IPv6 starting Beta) addresses are compatible with profiling, excluding those pointing GAME baremetal server ranges, protected by separate GAME DDoS protection.
Q9. What's next?
Beta and General Availability will come with more profiles, support for both IPv4/IPv6 and easy Control Panel configuration. Later evolution will include Log Data Platform integrations, cloud resources synchronization and more observability features.
-
Alpha
-
Beta
-
General Availability