DDoS Protection
Where DDoS mitigation really happens, and how to use Monitoring and the Activity Log to detect and document an attack on your infrastructure.
DDoS protection and your billing platform
Distributed denial-of-service (DDoS) attacks try to overwhelm a server or network with traffic so that legitimate customers can no longer reach it. For a hosting business, DDoS mitigation is handled at the network and server layer — by your upstream provider, your data centre's scrubbing service, or appliances and firewalls in front of your machines. Your billing platform does not sit in the traffic path, so it does not absorb or filter attack traffic itself.
What the platform does give you is visibility into how your servers are behaving and a record of who did what inside your account. This article explains which built-in pages help you spot trouble and respond to it, and how DDoS protection fits into the bigger picture.
Where mitigation actually happens
Keep these three layers separate when you plan your protection. Only the first two stop attack traffic; the platform sits alongside them as your detection and record-keeping layer.
| Layer | What it does | Where it is configured |
|---|---|---|
| Upstream / provider network | Blocks most volumetric (large-traffic) attacks before they ever reach your hardware. This is the most effective layer. | With your transit provider or data centre, not in the billing platform. |
| Server & firewall | Rate limiting, connection limits, and application firewalls on the host itself handle smaller or application-layer attacks. | On the operating system or control panel of each server. |
| Billing platform | Surfaces monitoring signals and an audit trail so you can detect that something is wrong and prove what happened. | Inside the admin panel — see the sections below. |
If you are evaluating a managed DDoS-protection product to resell to your own customers, you can model it as a billable add-on or product in your catalogue like any other service. The platform handles the billing; the actual scrubbing is delivered by your provider.
Spotting a problem: Monitoring
The built-in Monitoring page is the closest thing to a live health view of your infrastructure. Reach it from the left sidebar by clicking Monitoring. The item is visible to administrators whose role permits it, and only when the monitoring feature is enabled for your account.
The page opens on an Overview tab with summary tiles — Devices Up, Unreachable, Active Alerts, and Total Bandwidth — plus panels for your busiest links (Top Talkers) and the most recent Active Alerts. Three more tabs across the top let you dig in:
- Devices — a searchable table of every monitored switch, router, firewall, and similar device, with a status indicator, CPU, temperature, port utilisation, and an alert count per device.
- Alerts — a filterable list of raised alerts by severity (critical, warning, info) and status (active, acknowledged, resolved), where you can acknowledge or resolve items individually or in bulk.
- Topology — a map view of how your devices connect, with live traffic on each link.
Use Monitoring to watch the reachability of your devices, notice when a machine becomes slow or unreachable — one of the first symptoms of an attack in progress — and click into any device to review its current state, port traffic, and health. For a deeper walkthrough of a single device, see Device Detail.
Monitoring tells you that a host is struggling. Deciding it is an attack (rather than, say, a hardware fault or a runaway process) is up to you, using your provider's traffic graphs alongside it.
Knowing what changed: Activity Log
When you are responding to an incident, it helps to know exactly what happened in your account and when. The Activity Log records administrative actions — logins, settings changes, and other significant events — each stamped with a time and the person who performed it. During or after a suspected attack, the Activity Log lets you confirm whether a configuration change played a role and demonstrate what your team did in response.
Practical playbook for an attack in progress
- Confirm the symptom. Open Monitoring and check whether the affected device is reporting as slow or unreachable, then cross-reference your provider's traffic dashboard.
- Engage the right layer. Contact your upstream provider or data centre to enable or escalate their DDoS mitigation, and apply firewall or rate-limit rules directly on the affected host.
- Keep customers informed. If a service is degraded, post an update so affected customers are not left guessing — your support and ticketing tools are the place to do this.
- Record the response. After the incident, review the Activity Log to document the timeline and any changes that were made.
The platform will not automatically null-route traffic or block IP ranges at the network edge for you. Those actions belong to your provider or your server firewall. Treat the billing platform as your detection and record-keeping tool, not your scrubbing appliance.
Related
- Monitoring — live device health, alerts, and traffic.
- Device Detail — drill into a single device.
- Activity Log — audit trail of administrative actions.
