Carl
Member
Rack & Stack
- Joined:
- May 2024
- Posts:
- 227
- From:
- Chicago, US
Chicago perspective: I have racked actual scrubbing gear. The power draw alone for a single TMS-3000 is 2.5kW. At retail colo rates that's $300-500/month just in electricity and space before you bought the box or the transit.
So yeah, nobody is eating that cost for your $8 VPS. What they are doing is buying upstream protection on a shared commit and hoping attacks are uncorrelated. When they correlate, everyone gets nullrouted.
OVHcloud can do cheap protection because they own the pipe and the gear and the building. Vertical integration. But even their VPS protection is "best effort" compared to dedicated server plans.
RackNerd does not own anything. They lease from ColoCrossing and others. So their protection is whatever ColoCrossing offers, which is basically nullroute or upgrade to dedicated.
visit twice: install and decom
danfra
Member
OP
- Joined:
- Jun 2024
- Posts:
- 159
- From:
- Frankfurt, DE
Did you try their new "DDoS Protection" branding that replaced Shield?
Same backend, new frontend. I tested in June: 2.3 Gbps UDP mix, handled. 3.1 Gbps, nullroute 12 minutes. Slightly better than my old Shield test but probably just different attack profile and time of day, not infrastructure change.
Their "new" feature is automatic re-announcement after nullroute expires. Used to require ticket. Now it's self-service in robot. Small win for automation, not capacity.
One thing that did change: they added a "permanent mitigation" toggle in the console. Forces all traffic through scrubber always-on. Adds ~2-3ms latency but avoids the sFlow detection delay. Good for known targets, overkill for random personal site.
mitigated 800Gbps before breakfast
GeorgeNmp
Member
AS64512
- Joined:
- May 2024
- Posts:
- 218
- From:
- Ashburn, US
OVHcloud Game protection works for custom UDP ports
OVHcloud Game firewall profiles are pre-configured for specific games (Counter-Strike, Minecraft, etc.) with protocol-specific optimizations. For custom UDP applications you get their "default" profile, which is standard Arbor/TMS scrubbing without game-specific tweaks. Better than nothing, but not the "optimized" path.
You can request custom profile creation via ticket if you have enough volume to justify their engineering time. Unlikely for single small server.
Real talk: if your game is commercially important, $30-50 for proper protection is not crazy. If it is hobby, hidden IP + small community + accept downtime is the rational budget choice. The $10 constraint is doing a lot of work in this thread that maybe should not be there.
iBGP, eBGP, don't care, just peer