LightYear
/Docs
DocsNetworkingDDoS Protection Overview

DDoS Protection Overview

Understand LightYear's built-in DDoS protection and how to enable advanced mitigation for your servers.

beginner
5 min read
LightYear Team
Updated April 24, 2026
ddossecuritynetworkingprotection
Ready to get started?

Built-In Protection

All LightYear servers include basic DDoS mitigation at no extra cost. This protects against common volumetric attacks up to 10 Gbps.

Advanced DDoS Protection

For mission-critical workloads, enable Advanced DDoS Protection (+$10/month per server):

  • Mitigation capacity: up to 1 Tbps
  • Automatic traffic scrubbing
  • Real-time attack dashboards
  • SLA-backed uptime during attacks

Enabling Advanced Protection

  1. Go to Servers → [Your Server] → Settings.
  2. Toggle Advanced DDoS Protection to On.
  3. Confirm the additional charge.

How Scrubbing Works

Internet → Scrubbing Centre → Clean Traffic → Your Server ↓ Attack Traffic ↓ Dropped

Traffic is routed through a scrubbing centre that filters malicious packets before forwarding clean traffic to your server. Latency overhead is typically < 2 ms.

Attack Types Mitigated

Attack TypeBasicAdvanced
UDP flood
SYN flood
HTTP flood
DNS amplification
Slowloris
Application layer (L7)

Best Practices

  1. Use a Load Balancer as the public entry point — it absorbs attacks before they reach your servers.
  2. Enable Firewall Rules to block unused ports.
  3. Use Anycast for DNS to distribute attack traffic geographically.

Was this article helpful?

Your cookie choices for this website

This site uses cookies and related technologies, as described in our privacy policy, for purposes that may include site operation, analytics, and enhanced user experience. You may choose to consent to our use of these technologies, or manage your own preferences. Cookie policy