Doug
Member
New Jersey
- Joined:
- Jul 2024
- Posts:
- 271
- From:
- New Jersey, US
2Gbps and they FOLDED
My home connection handles more
ALL CAPS LIES for sale
But the null-route is not protection, is surrender
grabs popcorn, checks /r/drama
tomchan
Member
- Joined:
- Jul 2024
- Posts:
- 202
- From:
- Bristol, UK
It actually works, mostly.
Then someone on my network pissed off a Minecraft kid. 300Mbps reflection attack. GreenCloudVPS's "protection":
14:32:01 alert: potential DDoS detected
14:32:03 action: traffic scrubbing initiated
14:32:45 alert: scrubbing capacity exceeded
14:32:46 action: null-route 203.0.113.47/32
14:32:46 status: protection successful
"Protection successful" because the attack stopped hitting their router. My server was unreachable for 6 hours. They called this "mitigation."
Moved to a dedi at HostHatch, no "protection" advertised, just fat pipe. Same attack, no null-route, survived. Sometimes the honest absence of feature beats the lie.
works on my bench ¯\_(ツ)_/¯
kate3
Member
- Joined:
- Jul 2024
- Posts:
- 208
- From:
- Utrecht, NL
Virtualization tax applies here too. Budget "DDoS protection" is often just Voxility or similar upstream, marked up 400%, with no actual configuration. The provider buys a port with basic filtering and resells it as "protection."
OpenVZ makes this worse: no custom iptables, no XDP, no kernel-level mitigation. You're paying for a cgroup limit that dies under load. KVM at least lets you run your own filtering, though the network path remains shared.
Real protection requires:
- Sufficient upstream bandwidth (not oversold)
- Actual scrubbing center with clean pipe return
- Anycast dispersion
None of this exists at $5/month. The virtualization tax on honesty is what kills these offerings.
virsh list --all | wc -l: 47
Doug
Member
New Jersey
- Joined:
- Jul 2024
- Posts:
- 271
- From:
- New Jersey, US
Which upstream? Voxility, or did they refuse to name it?
grabs popcorn, checks /r/drama
sofialund
Member
homelab heatstroke
- Joined:
- Jul 2024
- Posts:
- 140
- From:
- Buenos Aires, Argentina
Same story at my last host. "Protection" meant automatic null-route.
hot air, steady hand, magic smoke
kate3
Member
- Joined:
- Jul 2024
- Posts:
- 208
- From:
- Utrecht, NL
Which upstream? Voxility, or did they refuse to name it?
They never name it. I asked GreenCloudVPS support once, got "we use multiple premium upstreams." Asked KnownHost, "proprietary blend of carriers." It's all NDA theater. The actual upstream is usually whoever owns the IP block lease, and the budget provider has zero SLA leverage.
The real tell: check the ASN path during normal traffic. If it hits Cogent or Telia and then disappears into a /24 with no route diversity, there is no scrubbing center. Just a pipe and a prayer.
virsh list --all | wc -l: 47
Doug
Member
New Jersey
- Joined:
- Jul 2024
- Posts:
- 271
- From:
- New Jersey, US
A null-route with branding
BEST DESCRIPTION
I want that on a shirt
grabs popcorn, checks /r/drama