Protect any infrastructure, anywhere. 2Tbps+ scrubbing capacity across 9 global centers. Deploy via GRE, VXLAN, WireGuard tunnel or BGP in minutes — no server migration required. Sub-second attack detection, always-on filtering, from $25/mo. Included FREE on all Sucura hosting.
Sucura's DDoS protection (SucuraGuard) reroutes your traffic through a GRE, VXLAN, or WireGuard tunnel, or via BGP announcement of your own IP space, into high-capacity anycast scrubbing centers that filter Layer 3/4/7 attacks with sub-second detection — no server migration required. Plans start at $25/mo with a free trial, and it's included free on Sucura-hosted servers.
All Sucura services (Dedicated Servers, VMs, Colocation) include SucuraGuard protection at no additional cost. All traffic is automatically scrubbed through our 2Tbps+ global network.
Don't host with us? No problem. Announce your IP blocks to AS398999 over a GRE, VXLAN or WireGuard tunnel — or a direct BGP session — and get instant SucuraGuard protection. Self-serve deployment in the Nexus panel; a free trial is available.
Bringing your own transit? Protect your prefixes with per-prefix and 95th-percentile plans — configure and deploy it yourself in the Nexus panel. Custom filtering rules included at no extra cost.
Announce your IP blocks to AS398999 via BGP. All inbound traffic routes through our scrubbing network first.
Our XDP/eBPF pipeline inspects every packet at line rate across 9 global centers. DDoS traffic is dropped, legitimate traffic passes.
Only clean traffic is forwarded to your origin through a GRE tunnel. Your servers never see attack traffic. No migration needed.
Scrubbing stops the flood. The new Sucura Edge Firewall lets you decide exactly what gets through — write 5-tuple rules (source, protocol, ports, ICMP, TCP flags) that enforce at the same network edge, on every IP you have with us. One ruleset covers your VPS, your DDoS tunnels, your BGP announcements and your dedicated servers at once. Rules run in the same XDP/eBPF pipeline as your mitigation, so filtering and scrubbing are one layer, not two vendors.