Remote DDoS Protection & Mitigation

Protect any infrastructure, anywhere. 2Tbps+ scrubbing capacity across 9 global centers. Deploy via GRE, VXLAN, WireGuard tunnel or BGP in minutes — no server migration required. Sub-second attack detection, always-on filtering, from $25/mo. Included FREE on all Sucura hosting.

Quick Answer

Sucura's DDoS protection (SucuraGuard) reroutes your traffic through a GRE, VXLAN, or WireGuard tunnel, or via BGP announcement of your own IP space, into high-capacity anycast scrubbing centers that filter Layer 3/4/7 attacks with sub-second detection — no server migration required. Plans start at $25/mo with a free trial, and it's included free on Sucura-hosted servers.

2Tbps+
SucuraGuard Capacity
9
Active Scrubbing Centers
AS398999
Protection ASN
<1s
Mitigation Time

SucuraGuard Services

SucuraGuard Included Free

All Sucura services (Dedicated Servers, VMs, Colocation) include SucuraGuard protection at no additional cost. All traffic is automatically scrubbed through our 2Tbps+ global network.

Always-On No Extra Cost 2Tbps+ Capacity
FREE with all services

Remote SucuraGuard Protection (GRE / VXLAN / WireGuard Tunnel or BGP)

Don't host with us? No problem. Announce your IP blocks to AS398999 over a GRE, VXLAN or WireGuard tunnel — or a direct BGP session — and get instant SucuraGuard protection. Self-serve deployment in the Nexus panel; a free trial is available.

Starter
100 Mbps clean
$25/mo
Business
500 Mbps clean
$75/mo
Professional
1 Gbps clean
$150/mo
Enterprise
5 Gbps clean
$500/mo
Prefer pay-as-you-go? Usage-based plans available in-panel — from $0.05/GB scrubbed, hourly announce, per-prefix, and 95th-percentile transit billing.
Start Free Trial →

SucuraGuard for IP Transit

Bringing your own transit? Protect your prefixes with per-prefix and 95th-percentile plans — configure and deploy it yourself in the Nexus panel. Custom filtering rules included at no extra cost.

Per-prefix & 95th-percentile billing
Get Started →

SucuraGuard Network

How Remote DDoS Protection Works

1

Announce Your IPs

Announce your IP blocks to AS398999 via BGP. All inbound traffic routes through our scrubbing network first.

2

We Scrub the Traffic

Our XDP/eBPF pipeline inspects every packet at line rate across 9 global centers. DDoS traffic is dropped, legitimate traffic passes.

3

Clean Traffic via GRE

Only clean traffic is forwarded to your origin through a GRE tunnel. Your servers never see attack traffic. No migration needed.

Defense Capabilities

E
Edge Network (AS398999)
Anycast edge - Global traffic distribution
BGP divert / GRE - Flexible traffic routing
Inline scrubbing - Real-time traffic cleaning
Low-latency routes - Optimized network paths
A
SucuraGuard Appliances
Custom-built protection - Designed and built in-house
2Tbps+ capacity - Across 9 active scrubbing centers worldwide
Lightning-fast filtering - Ultra-low latency traffic inspection
Live telemetry - Real-time attack visibility
M
Mitigation
L3/L4 + volumetric - Multi-layer defense
App-layer hardening - L7 protocol protection
Amplification dampening - Reflection attack defense
Botnet fingerprinting - Advanced threat detection
O
Operations
24/7 SOC / NOC - Round-the-clock monitoring
Auto detection - AI-powered threat identification
Reports & API - Comprehensive analytics export
SLA-backed - Guaranteed response times

Add a Firewall to Your Scrubbing

Scrubbing stops the flood. The new Sucura Edge Firewall lets you decide exactly what gets through — write 5-tuple rules (source, protocol, ports, ICMP, TCP flags) that enforce at the same network edge, on every IP you have with us. One ruleset covers your VPS, your DDoS tunnels, your BGP announcements and your dedicated servers at once. Rules run in the same XDP/eBPF pipeline as your mitigation, so filtering and scrubbing are one layer, not two vendors.

Explore Edge Firewall Try it free in the panel