SERVER PLUS INSIGHTS

How to Select an Anti-DDoS Plan: Protection Scale, Clean Bandwidth, 95th Percentile, BGP, and SLA

Anti-DDoS quotations often combine figures such as 100 Gbps, a 10G port, 50 Mbps at the 95th percentile, one /24 prefix, and a 99.9% SLA. These describe protection scale, interface capacity, legitimate traffic allowance, routing scope, and service commitment. They are not interchangeable. Selecting the largest advertised gigabit figure can still produce a plan that does not fit normal traffic, delivery, or redundancy requirements.

2026-08-30 · Server Plus

Anti-DDoS planClean bandwidth95th percentileBGP prefixDDoS SLATraffic scrubbingEnterprise procurement

Before buying Anti-DDoS, separate protection scale, clean bandwidth, delivery ports, 95th-percentile billing, BGP prefixes, session redundancy, attack reporting, and SLA instead of comparing only gigabits.

The First Mistake Is Comparing Only Protection Gbps

Protection capacity matters, but legitimate traffic must still cross the scrubbing platform, delivery network, and enterprise edge during an attack. If clean bandwidth, the delivery port, a tunnel, BGP, or the customer router is undersized, a large mitigation figure does not guarantee end-to-end service.

A complete comparison includes protection scale, clean bandwidth, delivery port, prefix count, BGP sessions, delivery locations, mitigation policy, reporting, SLA, and support. These fields cover capacity, routing, operations, and incident response.

Protection Scale, Clean Bandwidth, and Delivery Port

Protection scale describes the attack volume a plan is designed to process. Clean bandwidth is the legitimate traffic returned after mitigation. Delivery port speed is the physical or logical interface line rate. A plan can therefore provide 100 Gbps of protection, 50 Mbps of clean bandwidth, and a 10G delivery port without contradiction.

If normal enterprise traffic already reaches 300 Mbps, a 50 Mbps clean-bandwidth plan is unsuitable even without an attack. Conversely, a 10G port does not mean that 10 Gbps of legitimate traffic has been purchased. Use monitoring data for average, 95th percentile, peak, and expected growth.

  • Protection scale: attack-processing envelope
  • Clean bandwidth: billed or committed legitimate traffic after mitigation
  • Delivery port: interface line-rate ceiling
  • Size each independently and define overage behavior

How the 95th Percentile Is Calculated

With 95th-percentile billing, traffic is sampled at the interval defined by contract. Samples for the billing period are sorted from highest to lowest; the top five percent are discarded, and the highest remaining sample becomes the billing value. This accommodates brief bursts, but it does not provide unlimited use for five percent of the month, and it does not define whether the service will rate-limit traffic above the commitment.

Confirm where and how traffic is measured: clean inbound delivery, the higher of two directions, or inbound and outbound separately; one-minute or five-minute samples; and whether overage is billed per Mbps, triggers an upgrade, or is limited. These terms belong in the quotation or contract.

Attack Traffic Exclusion Still Needs a Precise Definition

A precise commitment states that attack traffic identified and blocked by the protection platform is excluded from clean-bandwidth usage. That is safer than saying all attack traffic is free, because only packets classified and stopped at the scrubbing layer are excluded. Unrecognized anomalies, allowed traffic, or legitimate bursts can still become delivered traffic.

Post-event data should include vectors, blocked traffic, peak bps and pps, destination ports, and event duration. This allows operations teams to validate billing, capacity, and policy. A total-traffic graph without pre- and post-mitigation context is often insufficient.

Prefix Count and BGP Sessions Define Scope and Redundancy

BGP prefix count describes how many public networks can be onboarded, not how many servers can be protected. One /24 contains 256 IPv4 addresses, but internal allocation and service design remain the customer responsibility. Multiple /24s, ASNs, data centers, or customer networks directly affect plan requirements.

BGP session count affects route exchange and failover. One session suits simple deployments. Two sessions can connect dual routers, delivery paths, or locations, but they provide meaningful resilience only when the devices, line cards, fibers, cross-connects, and failure domains are independent.

An SLA Is More Than 99.9% or 99.99%

First determine whether the SLA measures the scrubbing platform, tunnel, BGP session, local circuit, or end-to-end service. Customer routers, data-center power, configuration errors, planned maintenance, and third-party circuits may be exclusions.

A complete SLA defines availability, measurement, incident start and end, notification, maintenance, exclusions, claim deadlines, and service credits. Critical services should also confirm attack-response time, policy-change authority, and the 24×7 escalation path.

Which Enterprise Scenario Fits Each Tier?

Server Plus Anti-DDoS separates Shield Lite, Pro, Max, and Ultra by protection scale, clean bandwidth, prefixes, sessions, delivery locations, policy, and support. Company headcount is not the sizing method; public-service criticality and measured traffic are.

  • Shield Lite: one /24, lower legitimate traffic, single delivery, and standard policy
  • Shield Pro: dual BGP sessions, real-time events, and adjustable thresholds
  • Shield Max: multiple prefixes, higher clean bandwidth, multi-location delivery, API, and 24×7 coordination
  • Shield Ultra: multiple data centers, many prefixes, high bandwidth, LAG, multiple PoPs, and dedicated policy

Data to Prepare Before Requesting a Quote

A useful quote starts with network data rather than company size. Better inputs reduce the risk of normal traffic exceeding the plan or purchasing unnecessary capacity.

  • ASN, IPv4 prefixes, ROA or routing authorization, and current upstreams
  • Average, 95th-percentile, peak bps, and peak pps over 30 to 90 days
  • Main TCP and UDP services, ports, and normal source regions
  • Data-center location, routers, interfaces, and cross-connect availability
  • Tolerated downtime and requirements for dual routers or delivery locations
  • Alerting, reporting, API, 24×7 support, and change-control requirements
  • Target date, maintenance window, test method, and rollback plan

FAQ

Does 100 Gbps of protection include 100 Gbps of normal bandwidth?

No. Protection scale describes attack-processing capacity. Check clean bandwidth, 95th-percentile billing, and overage terms for legitimate traffic.

Does a 10G delivery port include 10 Gbps of monthly bandwidth?

No. A 10G port is an interface capability, not a commitment for 10 Gbps of clean traffic.

Does 95th percentile mean the highest five percent is always free?

Not exactly. The highest five percent of samples is discarded, but sampling, direction, overage, and rate-limiting terms still depend on the contract.

Do two BGP sessions automatically provide HA?

No. Confirm independent routers, interfaces, fiber paths, delivery sites, and failure domains. Two sessions sharing one device or circuit can fail together.

Why is plan pricing project-based?

Cost depends on protection and clean bandwidth as well as prefixes, ports, cross-connects, FTTB circuits, locations, redundancy, reporting, and support.

Discuss this requirement