Websites face attacks at two layers: volumetric Layer 3/4 DDoS floods that try to drown your bandwidth, and Layer-7 application attacks — exploits, bots, credential stuffing, HTTP floods — that abuse the application itself. SucuraGuard covers both on one AS398999 anycast network across Toronto, Chicago, Frankfurt, and Singapore: DDoS scrubbing (2Tbps+ capacity) handles the flood, the WAF filters what's left. One vendor, one bill, keep your DNS — add one A-record and you're covered at both layers. WAF free to start, from $20/mo.
Complete website protection means covering two different layers of attack, not one. SucuraGuard DDoS scrubs volumetric Layer 3/4 floods at the network edge; SucuraGuard WAF filters Layer-7 attacks, bots, and abuse at the same edge, on the same AS398999 anycast network. Traffic hits the anycast edge, gets scrubbed, gets filtered, and only clean requests reach your origin — one vendor, one bill, and you keep your existing DNS.
"Website protection" gets talked about as one thing, but attacks against a website arrive in two genuinely different shapes. The first is volumetric Layer 3/4 DDoS — UDP floods, reflection and amplification attacks, SYN floods, and other traffic that tries to saturate your bandwidth or exhaust connection state before a single HTTP request is even parsed. This is a network problem, and it's solved with scrubbing capacity and packet-level filtering, not application logic.
The second is Layer-7 application attack traffic: known-CVE exploits, vulnerability scanners, credential-stuffing attempts against a login form, scraping bots, and HTTP floods that look like real connections but abuse the application behind them. This is a request-level problem, and it's solved by inspecting and filtering HTTP traffic — which is what a web application firewall does.
A DDoS scrubber that only inspects packets has no visibility into a slow credential-stuffing attack running over legitimate-looking connections. A WAF that only inspects HTTP requests has no way to absorb a multi-gigabit flood before it saturates the link. Covering "website protection" honestly means covering both layers — which is why SucuraGuard is built as two products running on one network, not a single product claiming to do both jobs by itself.
One request, one network, two checks — in order.
Traffic to your hostname routes to the nearest of our four PoPs over AS398999.
Volumetric and protocol-level DDoS traffic is dropped at the network edge, at line rate.
What's left is inspected by the WAF — managed rules, custom rules, bot management, rate limiting.
Only filtered, clean traffic is forwarded to your origin server. Your server never sees either layer of attack.
Both layers are configured self-service in Nexus against the same account and the same hostname. There's no second dashboard to log into and no second vendor's support queue to open if something needs tuning across the two layers.
SucuraGuard WAF is a reverse proxy: it filters, caches, and terminates TLS in front of your origin. It is not a full CDN.
SucuraGuard DDoS is network scrubbing, on the same anycast network as the WAF above — it isn't a CDN or an application feature, it's line-rate packet filtering.
SucuraGuard's established scrubbing capacity figure applies here too — the same DDoS layer already used across Sucura's hosting and remote-protection customers backs this bundle.
UDP floods, reflection/amplification, SYN floods, and other L3/L4 attack traffic are dropped at the anycast edge before reaching the WAF or your origin.
Toronto, Chicago, Frankfurt, and Singapore — the identical anycast footprint the WAF runs on, so there's no separate routing path to reason about.
DDoS protection is sized and billed against clean-traffic throughput, separately from the WAF's rule-based pricing — see the pricing section below.
The usual way sites end up with "complete" protection is by stitching together two vendors: a WAF provider that wants your nameservers, and a separate DDoS provider with its own onboarding, its own dashboard, and its own invoice. Two support queues, two sets of credentials, two things to keep in sync when you change something about your origin.
SucuraGuard runs both layers as one product family on AS398999. You register your hostname and origin once in Nexus, add one A-record at whatever DNS provider you already use, and both the WAF and the DDoS scrubbing sit in front of that same hostname. Your nameservers, registrar, and other DNS records stay exactly where they are.
It's one account, one panel, and — for customers who take both products — one invoice, instead of reconciling charges from two unrelated vendors for two halves of the same job.
The WAF is priced per account, unlimited domains, flat monthly fee. DDoS protection is priced separately by clean-traffic throughput.