Anti-DDoS mitigation with auto-discovery

Hostealo Shield in Madrid (+200 Gbps), PletX in Eygelshoven and W&D Shield + PletX in Mainhausen (up to 1 Tbps). The system detects your traffic and applies the right filter, no setup needed.

✓ L3 / L4 included at no extra cost✓ Per-application auto-discovery✓ Our own Hostealo Shield✓ 24/7 NOC
+1 Tbps
Per-DC capacity in EU

PletX in NL · W&D Shield + PletX in DE

+200 Gbps
Hostealo Shield (Madrid)

Our own L3/L4 system with advanced control

< 1s
Automatic detection

Heuristics + signatures, no manual intervention

L3 / L4
Covered layers

Volumetric and protocol (SYN/UDP/ICMP, amplification, reflection)

Universal

Auto-discovery in all DCs

The system observes traffic on your ports, identifies the protocol and automatically applies the right filter. You don't need to open tickets, you don't need to configure rules, you don't need to know what A2S spoofing or RakNet flood is.

  1. 1
    Your service is provisioned

    VPS or dedicated server active at your IP in the chosen DC.

  2. 2
    The scrubbing observes traffic

    Heuristics + signatures over the first connection window.

  3. 3
    The right filter is applied

    Counter-Strike, Minecraft, FiveM, RakNet, OpenVPN… or generic L4 if none matches.

  4. 4
    Fine-tuning during an attack

    The NOC monitors 24/7 and tightens rules in real time when a sustained attack warrants it.

Filter catalog per datacenter

Each DC runs a different stack. Madrid (Hostealo Shield, in-house) carries the broadest catalog. EU (PletX / W&D Shield) covers the main presets plus a Custom filter where you define your own TCP values.

Spain

Madrid

+200 Gbps
Hostealo Shield
Gaming
TCPAltVTCPFiveM Ultra StrictTCPMinecraft JavaTCPTibiaUDPAltVUDPArk: Survival AscendedUDPArk: Survival EvolvedUDPArma ReforgerUDPCounter-Strike: Global OffensiveUDPDayZUDPFactorioUDPFiveMUDPHurtworldUDPLeft 4 Dead 2UDPMulti Theft AutoUDPPalworldUDPPath of TitansUDPRakNetUDPSCP: Secret LaboratoryUDPSan Andreas MultiplayerUDPSource Engine / A2SUDPSource Engine 2 / A2SUDPSource Engine Strict / A2SUDPThe IsleUDPASE Query
Voice
UDPTeamSpeak 3TCPTS3 Query/Filetransfer
Web / TLS
TCPHTTPTCPHTTP StrictTCPTLSTCPSSL Strict
Infra
TCPFTPTCPSSHTCPRDPTCPRemote Desktop ProtocolUDPRDPUDPDNSUDPNTP
VPN
UDPOpenVPNUDPWireGuard
Netherlands

Eygelshoven

+1 Tbps
PletX
Gaming
TCPFiveMTCPMinecraftTCPMetin 2 ChannelTCPMetin 2 AuthTCPNovalifeTCPGrowtopiaUDPSource EngineUDPRakNetUDPSAMPUDPGrowtopia
Voice
UDPTeamSpeakUDPPlasmoVoice
Infra
TCPSSHTCPRDP
VPN
UDPOpenVPNUDPWireguard
Custom
TCPCustomUDPDisable Automatic Learning
Germany

Mainhausen

+1 Tbps
W&D Shield + PletX
Gaming
TCPFiveMTCPMinecraftTCPMetin 2 ChannelTCPMetin 2 AuthTCPNovalifeTCPGrowtopiaUDPSource EngineUDPRakNetUDPSAMPUDPGrowtopia
Voice
UDPTeamSpeakUDPPlasmoVoice
Infra
TCPSSHTCPRDP
VPN
UDPOpenVPNUDPWireguard
Custom
TCPCustomUDPDisable Automatic Learning

New York runs Basic Anti-DDoS (generic volumetric protection, no public catalog of per-application filters).

Madrid only

Advanced panel. Hostealo Shield

Because it's our own system, in Madrid we expose direct control over the scrubbing behavior per IP. Useful for customers with mixed traffic, persistent attacks or specific geo-filtering needs.

Per-IP rules

Drop by default, asymmetric or symmetric. Configure traffic behaviour for each IP in the block.

Custom filters

Create your own L4 rules over TCP/UDP when none of the presets covers your case.

ASN or country block/whitelist

Filter traffic by geographical origin or whole autonomous system. Useful to contain waves from specific regions.

IP lists

Whitelist or blacklist specific IPs or whole ranges, managed from the panel.

For external networks

IP Transit with Anti-DDoS

Operate your own AS? We become your upstream BGP with scrubbing applied to all incoming traffic. Announce your prefix through AS215691 and your network, as a downstream customer, only receives clean traffic.

  • Announce your IPv4 prefix with AS215691 as your upstream BGP
  • Hostealo Shield applied to all incoming traffic
  • ASN / country blocking and IP lists managed by you
  • Managed LOA + RPKI, valid if you re-announce to your own BGP customers
  • Compatible whether or not you have your own LIR
Pedir presupuesto IP Transit

Internet

Mixed traffic + attacks

AS215691 · Upstream

Hostealo, your BGP provider

Hostealo Shield

L3/L4 scrubbing · ASN/country · IP rules

Your AS · Downstream

Receives clean traffic

AttackLegitimate trafficClean traffic

What's included (and what isn't)

Included at no cost

  • L3/L4 mitigation on all services
  • Per-application filter auto-discovery
  • Advanced per-IP panel (Madrid)
  • 24/7 NOC monitoring sustained attacks
  • No attack traffic surcharge

Not included

  • L7 mitigation (HTTP flood, bots, scraping); handled server-side or with a WAF
  • Basic Anti-DDoS in NY doesn't expose a per-application filter catalogue
  • IP Transit with Anti-DDoS quoted case by case (not included with VPS/dedicated)
  • Manual tweaks outside Madrid (closed catalogue)

Frequently asked questions

What a sysadmin or CTO actually asks before trusting their network to an Anti-DDoS: coverage, mitigation latency, visibility, AI integrations and what happens with false positives. Yours missing? Drop us a line.

Get in touch →

We cover the main vectors at L3 (network) and L4 (transport): SYN flood, UDP flood, ICMP flood, amplification (DNS, NTP, memcached, SSDP), reflection, fragmentation, spoofed IP, ACK flood and TCP reflect. Profiles are applied per application (gaming UDP, voice/VoIP, web, infra, VPN). In Madrid the catalog is extended with 40+ filters manageable from the panel.

L3/L4 Anti-DDoS included, no tickets, no extras

Every Hostealo VPS, dedicated server or colocation includes L3/L4 Anti-DDoS protection from minute one, at no extra cost and no paperwork.