SERVER PLUS ANTI-DDOS

Enterprise L3/L4Anti-DDoS Protection

Built on a Cloudflare Magic Transit protection architecture to identify and mitigate network-layer attacks across a global Anycast network, with clean traffic delivered by Server Plus to your data center or office.

100 Gbps

Entry protection scale

1 Tbps+

Maximum plan scale

10G–100G

Delivery ports

NETWORK-LAYER RISK

The circuit can saturate before the firewall fails

When volumetric attacks fill upstream capacity first, on-premises firewalls and appliances have no room to process legitimate traffic. L3/L4 protection must act before attack traffic reaches the enterprise edge.

Bandwidth exhaustion

UDP amplification and volumetric floods can consume Internet capacity before legitimate sessions arrive.

State-table exhaustion

SYN floods and abnormal TCP traffic consume firewall, load-balancer, and server connection resources.

Multi-vector attacks

Attackers can shift between UDP, TCP, ICMP, and destination ports faster than static rules can adapt.

Service disruption

Websites, APIs, VPNs, games, hosting platforms, and data-center services can all become unreachable.

PROTECTION ARCHITECTURE

Attacks are stopped upstream; only clean traffic reaches your network

Cloudflare uses BGP and its global Anycast network to receive inbound traffic for protected prefixes and apply L3/L4 detection and mitigation. Server Plus handles local onboarding, routing, and clean-traffic delivery.

01

Internet traffic

Legitimate and attack traffic enters the global network

02

Cloudflare Magic Transit

Anycast ingestion and L3/L4 attack mitigation

03

Server Plus delivery network

Routing, delivery points, and circuit integration

04

Enterprise network

Clean traffic reaches the data center or office

SERVICE CAPABILITIES

Plan the prefix, protection, and delivery path together

The service covers more than filtering. It includes BGP, delivery redundancy, mitigation thresholds, event notifications, and capacity planning.

Automated L3/L4 mitigation

Detect and mitigate UDP floods, SYN floods, ICMP floods, and abnormal network-layer traffic.

BGP prefix protection

Protect publicly routable IPv4 prefixes; customer-owned space is generally onboarded as /24 or larger.

Global Anycast ingestion

Traffic enters the protection platform at distributed network edges instead of a single centralized scrubbing site.

Redundant delivery

Plan one or more BGP sessions, delivery locations, and port redundancy according to the selected tier.

Attack visibility

Receive monthly reports, event notifications, API access, or real-time telemetry by plan.

Local technical support

Server Plus supports discovery, routing design, migration validation, and incident handling.

PROTECTION PLANS

Select by clean traffic, prefixes, and redundancy

Protection scale is not the same as day-to-day bandwidth. Clean bandwidth is the legitimate traffic returned after mitigation; delivery port speed is the physical or logical interface ceiling.

Shield Lite

Project quotation

Protection scale
100 Gbps
Clean bandwidth
50 Mbps (95th)
Delivery port
10G
Delivery method
Chief Telecom interconnect or Chunghwa Telecom FTTB
BGP prefixes
1 (/24)
BGP sessions
1
Clean-traffic delivery
Taipei
Mitigation policy
Platform standard policy
Attack reporting
Monthly attack and traffic report
Service SLA
99.9%
Technical support
Online ticketing

Recommended for enterprises

Shield Pro

Project quotation

Protection scale
300 Gbps
Clean bandwidth
100 Mbps (95th)
Delivery port
10G
Delivery method
Chief Telecom interconnect or Chunghwa Telecom FTTB
BGP prefixes
2
BGP sessions
2
Clean-traffic delivery
Taipei + Tokyo
Mitigation policy
Adjustable detection thresholds
Attack reporting
Real-time event notification
Service SLA
99.95%
Technical support
Ticketing + messaging group

Shield Max

Project quotation

Protection scale
500 Gbps
Clean bandwidth
300 Mbps (95th)
Delivery port
10G / 25G
Delivery method
Chief Telecom data-center interconnect
BGP prefixes
4
BGP sessions
2
Clean-traffic delivery
Taipei + Tokyo + Hong Kong
Mitigation policy
Customized mitigation policy
Attack reporting
Event notification + query API
Service SLA
99.99%
Technical support
Dedicated 24×7 group

Shield Ultra

Project quotation

Protection scale
1 Tbps+
Clean bandwidth
1 Gbps (95th)
Delivery port
25G / 40G / 100G
Delivery method
Chief Telecom interconnect with optional LAG redundancy
BGP prefixes
8+
BGP sessions
4
Clean-traffic delivery
Multi-region delivery by project
Mitigation policy
Dedicated policy design
Attack reporting
Real-time traffic telemetry
Service SLA
99.99%
Technical support
Dedicated technical manager

95th-percentile clean-bandwidth billing

Clean bandwidth is billed at the 95th percentile. Attack traffic identified and blocked by the protection platform is excluded from clean-bandwidth usage. Legitimate traffic above the committed plan is billed at the agreed overage rate. Delivery ports, cross-connects, and access circuits are quoted separately.

SLA measurement, exclusions, maintenance windows, and service credits are governed by the executed service agreement.

ONBOARDING

From traffic assessment to production cutover

01

Discovery

Confirm ASN, prefixes, traffic, and service locations

02

Architecture

Plan BGP, ports, circuits, and redundancy

03

Policy setup

Configure thresholds, notifications, and delivery routes

04

Cutover validation

Verify routing, health checks, and traffic behavior

05

Production protection

Monitor incidents, reports, and capacity usage

Information required for assessment

Company and technical contacts

ASN and IPv4 prefixes to protect

Normal, 95th-percentile, and peak legitimate traffic

Data-center location or FTTB service address

Current upstream, BGP, and routing architecture

Target go-live date and whether an attack is in progress

FAQ

Anti-DDoS FAQ

Is this a website CDN or WAF?

No. This service focuses on L3/L4 network and transport-layer DDoS protection for an entire IP prefix. Application-layer threats still require CDN, WAF, application security, and vulnerability management.

Why does customer-owned IPv4 generally require a /24?

A /24 is generally the smallest globally accepted IPv4 route on the public Internet. Smaller networks require a separate assessment of IP allocation and delivery options.

Is blocked attack traffic billed?

Traffic identified and blocked by the platform is excluded from clean-bandwidth usage. Legitimate traffic returned after mitigation and any overage are billed under the selected plan and agreement.

Why is clean bandwidth 50 Mbps when the delivery port is 10G?

Port speed describes interface capacity; clean bandwidth is the legitimate traffic allowance included with the plan. They are separate commitments.

Can service be delivered over Chunghwa Telecom FTTB?

Shield Lite and Shield Pro can be assessed for FTTB delivery subject to address, line availability, speed, lead time, and installation charges.

Can you onboard a network during an active attack?

Provide the prefix, ASN, current traffic, and service location for urgent assessment. Onboarding speed depends on routing authority, circuits, and delivery readiness.

PROTECTION ASSESSMENT

Start with prefixes, traffic, and delivery requirements

Share your ASN, prefixes, legitimate traffic, service locations, and target date. Server Plus will plan the appropriate protection scale, BGP redundancy, and clean-traffic delivery.