I used to run on-prem appliance. A10 Thunder. Bought it used for cheap, ran it two years, sold it for more. The hardware was fine but the licensing was a nightmare. Every feature was a separate subscription. "Oh you want SSL inspection? That is another $4K/year." Never again.
Poll: what's your actual DDoS filtering setup?
Anycast is great until it is not. I know a guy who ran his own anycast on three Vultr locations. Worked fine until Vultr had a routing issue in Amsterdam and 40% of his European traffic got blackholed. The "automatic" failover became automatic fail. You still need monitoring and manual override.
ARM Ampere at Oracle Cloud Seoul. Their DDoS protection is included and actually decent for the price. I run upstream scrubbing there plus a small on-prem filter on a local dedicated line for latency-sensitive stuff. The Oracle layer handles volumetric. The local box handles application nonsense. Best of both if you can afford the hardware.
I am reading this and I do not understand most of it. I run two WordPress sites on a shared host. Is that upstream scrubbing? Should I be doing something else? They have never gone down that I know of.