DDoS Protection
Where DDoS mitigation really happens, and how to use Monitoring and the Activity Log to detect and document an attack on your infrastructure.
DDoS protection and your billing platform
A distributed denial-of-service (DDoS) attack tries to overwhelm a server or network with traffic so that legitimate customers can no longer reach it. For a hosting business, DDoS mitigation happens at the network and server layer — at your upstream provider, in your data centre's scrubbing service, or on appliances and firewalls in front of your machines. Your billing platform is not in the traffic path, so it neither absorbs nor filters attack traffic.
What the panel gives you instead is detection, evidence and access control: live device health and alerting, an audit trail of everything done inside your account, and controls that block abusive addresses from your panels. This article explains exactly which pages do what, and how they fit around the mitigation your provider delivers.
Where mitigation actually happens
Keep these three layers separate when you plan your protection. Only the first two stop attack traffic; the platform sits alongside them as your detection and record-keeping layer.
| Layer | What it does | Where it is configured |
|---|---|---|
| Upstream / provider network | Blocks most volumetric (large-traffic) attacks before they ever reach your hardware. This is the most effective layer. | With your transit provider or data centre, not in the billing platform. |
| Server & firewall | Rate limiting, connection limits, and application firewalls on the host itself handle smaller or application-layer attacks. | On the operating system or control panel of each server. |
| Billing platform | Surfaces device health and alerts, keeps an audit trail, and blocks abusive addresses from your panels so you can detect trouble and prove what happened. | Inside the admin panel — see the sections below. |
Note: The panel will not null-route traffic, announce a blackhole, or filter packets at the network edge. Those actions belong to your provider or your server firewall. Treat the billing platform as your detection, evidence and access-control tool, not as a scrubbing appliance.
Spotting a problem: Monitoring
The Monitoring page is the live health view of your network hardware. Reach it from the Monitoring icon in the top header bar of the admin panel. The icon appears only for administrators whose role permits it and only when the Monitoring module is enabled and available on your plan.
The page opens on an Overview tab with four summary tiles — Devices Up, Unreachable, Active Alerts and Total Bandwidth — plus a Top Talkers panel for your busiest links and a list of current Active Alerts. Three more tabs across the top let you dig in:
- Devices — a searchable table of every monitored switch, router, firewall, PDU, access point and load balancer, with columns for Status, Name, IP, Type, Ports, CPU, Temp, Utilization, Alerts and Uptime. Status values include Up, Warning, Down, SNMP Unreachable, No SNMP and Unknown. Devices come from Inventory — a switch, router or firewall you have not added there will not appear here.
- Alerts — a filterable list of raised alerts by severity (Critical, Warning, Info) and status (Active, Acknowledged, Resolved). You can acknowledge, resolve or delete alerts one at a time, in a selected batch, or all at once.
- Topology — a map of how your devices connect, with live traffic on each link.
Use Monitoring to watch reachability and link load, and to notice when a machine becomes slow or unreachable — one of the first symptoms of an attack in progress. Click any device to open its detail page, where you can see traffic, CPU, memory and temperature charts over 1 hour, 6 hours, 24 hours or 7 days, a per-port table with in/out rates and utilisation, and the device's own alerts. See DDoS Sensor Detail for how to read that page during an incident, and Monitoring Device for the full walkthrough.
Note: Monitoring tells you that a device is struggling. Deciding it is an attack rather than a hardware fault or a runaway process is your call, using your provider's traffic graphs alongside it.
Blocking abusive addresses: IP Ban
The one place the panel itself blocks traffic is IP Ban, under Settings → IP Ban. This is panel-level access control — it stops the listed addresses reaching your admin panel and client portal. It does not stop packets arriving at your servers, so it will not relieve a volumetric attack; it is the right tool for credential-stuffing, scraping and abusive sign-in traffic.
- IP Ban Enforcement — the main switch. While it is on, banned addresses are blocked from all panels.
- Auto-Block on Failed Logins — bans an address automatically once it fails sign-in too many times. You set Max Attempts, the Window (min) those attempts are counted over, and the Ban (min) that follows.
- Ban IP — ban an address by hand. Enter the address, choose a duration of 6 Days, 1 Month or Permanent, and add an optional reason.
- The Banned IPs table lists each address with its reason, duration, expiry, who banned it (automatic bans show as System) and when. Each row offers View login attempts, which lists the time, email address, panel and outcome of every sign-in tried from that address, and Unban IP.
Hardening the front door: Security settings
Under Settings → Security you can raise the cost of automated abuse before it turns into a flood. See Security for the full reference; the parts that matter during an abuse incident are:
- reCAPTCHA v3 — enable it for Login, Register or both, with a Min Score threshold, to keep scripted traffic off those forms.
- Email 2FA — a code sent by email, with its own Expiry (min), Max Attempts and Cooldown (sec), and an option to require two-factor authentication for everyone.
- Disposable Email Blocking — rejects sign-ups from throwaway inbox services, cutting bot registrations. You can extend the built-in list or exempt domains from it.
- Real Visitor IP — tells the platform which forwarded-IP header your proxies use and which proxies to trust. Getting this right matters during an incident: without it, bans and login-attempt records can point at your proxy instead of the real source.
Knowing what changed: Activity Log
When you are responding to an incident, it helps to know exactly what happened inside your account and when. The Activity Log records sign-ins, settings changes, user and service actions and more, each stamped with a time, the person it is attributed to and, where available, their IP address. During or after a suspected attack it lets you confirm whether a configuration change played a part, spot a burst of failed sign-ins, and demonstrate what your team did in response.
Practical playbook for an attack in progress
- Confirm the symptom. Open Monitoring and check whether the affected device is reporting as slow, degraded or unreachable, then look at its traffic chart and per-port utilisation and cross-reference your provider's traffic dashboard.
- Engage the right layer. Contact your upstream provider or data centre to enable or escalate their mitigation, and apply firewall or rate-limit rules directly on the affected host.
- Shut the door on abusive sign-in traffic. If the pressure is on your panels rather than your network, turn on IP Ban Enforcement, tighten Auto-Block on Failed Logins, and ban the worst offenders by hand from IP Ban.
- Keep customers informed. If a service is degraded, post an update so affected customers are not left guessing — your ticketing tools and an Email Broadcast are the places to do this.
- Record the response. Acknowledge and then resolve the alerts you have dealt with so the Active Alerts count reflects reality, and review the Activity Log afterwards to document the timeline and any changes that were made.
Selling protection to your own customers
If you resell a managed DDoS-protection product, model it as a billable add-on or as a product in your catalogue like any other service. The platform handles the ordering, provisioning workflow and billing; the scrubbing itself is delivered by your provider.
Related
- DDoS Sensor Detail — reading a single monitored device during an incident.
- Monitoring — live device health, alerts, traffic and topology.
- Monitoring Device — the full device detail walkthrough.
- IP Ban — block abusive addresses from your panels.
- Security — captcha, two-factor, disposable-email and proxy settings.
- Activity Log — audit trail of administrative actions.
