Bandwidth exhaustion
UDP amplification and volumetric floods can consume Internet capacity before legitimate sessions arrive.
SERVER PLUS ANTI-DDOS
Built on a Cloudflare Magic Transit protection architecture to identify and mitigate network-layer attacks across a global Anycast network, with clean traffic delivered by Server Plus to your data center or office.
100 Gbps
Entry protection scale
1 Tbps+
Maximum plan scale
10G–100G
Delivery ports
NETWORK-LAYER RISK
When volumetric attacks fill upstream capacity first, on-premises firewalls and appliances have no room to process legitimate traffic. L3/L4 protection must act before attack traffic reaches the enterprise edge.
UDP amplification and volumetric floods can consume Internet capacity before legitimate sessions arrive.
SYN floods and abnormal TCP traffic consume firewall, load-balancer, and server connection resources.
Attackers can shift between UDP, TCP, ICMP, and destination ports faster than static rules can adapt.
Websites, APIs, VPNs, games, hosting platforms, and data-center services can all become unreachable.
PROTECTION ARCHITECTURE
Cloudflare uses BGP and its global Anycast network to receive inbound traffic for protected prefixes and apply L3/L4 detection and mitigation. Server Plus handles local onboarding, routing, and clean-traffic delivery.
01
Legitimate and attack traffic enters the global network
02
Anycast ingestion and L3/L4 attack mitigation
03
Routing, delivery points, and circuit integration
04
Clean traffic reaches the data center or office
SERVICE CAPABILITIES
The service covers more than filtering. It includes BGP, delivery redundancy, mitigation thresholds, event notifications, and capacity planning.
Detect and mitigate UDP floods, SYN floods, ICMP floods, and abnormal network-layer traffic.
Protect publicly routable IPv4 prefixes; customer-owned space is generally onboarded as /24 or larger.
Traffic enters the protection platform at distributed network edges instead of a single centralized scrubbing site.
Plan one or more BGP sessions, delivery locations, and port redundancy according to the selected tier.
Receive monthly reports, event notifications, API access, or real-time telemetry by plan.
Server Plus supports discovery, routing design, migration validation, and incident handling.
PROTECTION PLANS
Protection scale is not the same as day-to-day bandwidth. Clean bandwidth is the legitimate traffic returned after mitigation; delivery port speed is the physical or logical interface ceiling.
Project quotation
Recommended for enterprises
Project quotation
Project quotation
Project quotation
Clean bandwidth is billed at the 95th percentile. Attack traffic identified and blocked by the protection platform is excluded from clean-bandwidth usage. Legitimate traffic above the committed plan is billed at the agreed overage rate. Delivery ports, cross-connects, and access circuits are quoted separately.
SLA measurement, exclusions, maintenance windows, and service credits are governed by the executed service agreement.
ONBOARDING
01
Confirm ASN, prefixes, traffic, and service locations
02
Plan BGP, ports, circuits, and redundancy
03
Configure thresholds, notifications, and delivery routes
04
Verify routing, health checks, and traffic behavior
05
Monitor incidents, reports, and capacity usage
Company and technical contacts
ASN and IPv4 prefixes to protect
Normal, 95th-percentile, and peak legitimate traffic
Data-center location or FTTB service address
Current upstream, BGP, and routing architecture
Target go-live date and whether an attack is in progress
FAQ
No. This service focuses on L3/L4 network and transport-layer DDoS protection for an entire IP prefix. Application-layer threats still require CDN, WAF, application security, and vulnerability management.
A /24 is generally the smallest globally accepted IPv4 route on the public Internet. Smaller networks require a separate assessment of IP allocation and delivery options.
Traffic identified and blocked by the platform is excluded from clean-bandwidth usage. Legitimate traffic returned after mitigation and any overage are billed under the selected plan and agreement.
Port speed describes interface capacity; clean bandwidth is the legitimate traffic allowance included with the plan. They are separate commitments.
Shield Lite and Shield Pro can be assessed for FTTB delivery subject to address, line availability, speed, lead time, and installation charges.
Provide the prefix, ASN, current traffic, and service location for urgent assessment. Onboarding speed depends on routing authority, circuits, and delivery readiness.
PROTECTION ASSESSMENT
Share your ASN, prefixes, legitimate traffic, service locations, and target date. Server Plus will plan the appropriate protection scale, BGP redundancy, and clean-traffic delivery.