# DDoS Protection

import DocButton from '~/components/webkit/DocButton.vue';

**DDoS Protection** is a [Firewall](/en/documentation/products/secure/firewall/) add-on that protects your applications against *Denial of Service (DoS)* and *Distributed Denial of Service (DDoS)* attacks, at the network, transport, presentation, and application layers (layers 3, 4, 6, and 7 of the OSI model, respectively).

At Azion, DDoS Protection is **unmetered** and is automatically enabled in all accounts. It offers protection against DoS and DDoS attacks with unmetered bandwidth. This means that, no matter how much DDoS attack traffic is directed to your applications or the Azion infrastructure, the Azion dedicated network will guarantee that all services are constant and not affected by the attack. As it's unmetered, mitigation using this protection won't appear on *billing*. For more information regarding traffic accounting, see the [pricing](/en/documentation/products/pricing/) page.

It runs specific algorithms directly on Azion's distributed network to detect small attacks from a single IP and large-scale attacks from criminal botnet networks.

The mitigation of DDoS attacks is carried out by Azion and doesn't impact the performance of its applications. It also doesn't require specific configuration, but custom rules can be configured for specific detection, mitigation, and targeted attacks.

---

## DDoS Protection advantages and characteristics

### Always-on mitigation

**DDoS Protection** is *always-on*. It continuously monitors the network flow by inspecting incoming traffic. It also provides advanced traffic analysis and signature algorithms to detect and block malicious traffic in time and with no impact on your applications. It also uses Deep Packet Inspection (DPI) and Artificial Intelligence (AI) algorithms to detect abnormal traffic behavior for accurate detection, reducing false positives.

:::tip
You can also optimize protection against DDoS attacks at the application layer (layer 7) using [Web Application Firewall](/en/documentation/products/secure/firewall/web-application-firewall/), a [Firewall](/en/documentation/products/secure/firewall/) add-on.
:::

### Flexible and customizable protection

Azion will be able to apply customized rules to mitigate sophisticated attacks from the network, transport, presentation, and [application layers](https://www.azion.com/en/learning/ddos/application-layer-attack/). These rules can be applied instantly, allowing you to quickly and efficiently protect your content or application. You can implement custom rules to mitigate specific attacks, using **Firewall**, a programmable firewall at the edge equipped with Network Shield, Rate Limiting, WAF, and Bot Manager.

### Advanced detection

**DDoS Protection** offers advanced detection, inspecting network flows, as well as monitoring each application layer for its resources delivered by Azion using **Firewall** and **Web Application Firewall**. It uses advanced algorithms and *Software-defined Networking (SDN)* for granular detection and mitigation of [DDoS attacks](https://www.azion.com/en/learning/ddos/what-is-ddos-attack/), such as **HTTP Floods**, **HTTP Slow Reads**, **DNS Query Floods**, **SYN/ACK Flood**, and many others.

Azion's network of over 100 edge locations offers built-in DDoS protection and global scrubbing centers, achieving a median latency of less than 30ms across the Americas and Europe. It detects and mitigates attacks in under 3 seconds on average, ensuring an ultra-fast response, even for large-scale attacks.

### Mitigation of complex attacks

**DDoS Protection** offers sophisticated algorithms for automated attack mitigation. It's suitable for medium-sized businesses and companies that use Azion in mission-critical systems, with a direct impact on business results, and that want protection against any volume of attack.

<DocButton href="/en/documentation/products/secure/firewall/ddos-protection/ddos-mitigation/" label="Go to DDoS Mitigation" kind="secondary" target="_blank" size="medium" />

### DNS Protection

**DDoS Protection** provides **DNS Protection**, ensuring the security of your Domain Name System (DNS) service.

**DNS Protection** safeguards your DNS service from DDoS attacks. By keeping your DNS origin server hidden and spreading Azion's DNS servers to the internet, you'll rely on Azion to ensure the continuity of your services. The Azion DNS service is distributed in many different geographic locations and has protection against DDoS attacks.

Azion's DNS servers get their configuration from the customer's origin server, whether it's inside their infrastructure or in the cloud. If your infrastructure already uses the [DNSSEC](/en/documentation/products/secure/edge-dns/dnssec-compatibility/) extension, you can count on DDoS Protection without giving up the guarantee of integrity and authenticity of your records, thus providing security and availability for address resolution for your business. Other TCP/UDP applications encapsulated in HTTP can benefit from the same level of protection via reverse proxy.

### Attack visibility

**DDoS Protection** offers complete visibility of application attacks through [Azion Console](https://console.azion.com) or [Azion API](https://api.azion.com) to be able to view the attack volume. In conjunction with the **Security Response Team (SRT)**, you'll have access to post-event analysis and investigations.

:::tip
Azion offers the [Security Response Team (SRT)](/en/documentation/services/security-response-team/) service, that can be activated during or after a DDoS attack to help track incidents, ascertain the root cause, and implement solutions alongside your business.  For more information on the Security Response Team (SRT), contact the [sales team](https://www.azion.com/en/contact/).
:::

---

## Limits

:::tip
**Increase limits** <br></br>
You can request an increase in the limits based on your plan. Contact the [technical support team](/en/documentation/services/support/) to request it.
:::

These are the **default limits**:

| Scope | Limit |
| ------- | ----- |
| Bandwidth traffic | Unmetered |