Anti-DDoS mitigation with auto-discovery
Hostealo Shield in Madrid (+200 Gbps), PletX in Eygelshoven and W&D Shield + PletX in Mainhausen (up to 1 Tbps). The system detects your traffic and applies the right filter, no setup needed.
PletX in NL · W&D Shield + PletX in DE
Our own L3/L4 system with advanced control
Heuristics + signatures, no manual intervention
Volumetric and protocol (SYN/UDP/ICMP, amplification, reflection)
Auto-discovery in all DCs
The system observes traffic on your ports, identifies the protocol and automatically applies the right filter. You don't need to open tickets, you don't need to configure rules, you don't need to know what A2S spoofing or RakNet flood is.
- 1Your service is provisioned
VPS or dedicated server active at your IP in the chosen DC.
- 2The scrubbing observes traffic
Heuristics + signatures over the first connection window.
- 3The right filter is applied
Counter-Strike, Minecraft, FiveM, RakNet, OpenVPN… or generic L4 if none matches.
- 4Fine-tuning during an attack
The NOC monitors 24/7 and tightens rules in real time when a sustained attack warrants it.
Filter catalog per datacenter
Each DC runs a different stack. Madrid (Hostealo Shield, in-house) carries the broadest catalog. EU (PletX / W&D Shield) covers the main presets plus a Custom filter where you define your own TCP values.
Madrid
Eygelshoven
Mainhausen
New York runs Basic Anti-DDoS (generic volumetric protection, no public catalog of per-application filters).
Advanced panel. Hostealo Shield
Because it's our own system, in Madrid we expose direct control over the scrubbing behavior per IP. Useful for customers with mixed traffic, persistent attacks or specific geo-filtering needs.
Per-IP rules
Drop by default, asymmetric or symmetric. Configure traffic behaviour for each IP in the block.
Custom filters
Create your own L4 rules over TCP/UDP when none of the presets covers your case.
ASN or country block/whitelist
Filter traffic by geographical origin or whole autonomous system. Useful to contain waves from specific regions.
IP lists
Whitelist or blacklist specific IPs or whole ranges, managed from the panel.
IP Transit with Anti-DDoS
Operate your own AS? We become your upstream BGP with scrubbing applied to all incoming traffic. Announce your prefix through AS215691 and your network, as a downstream customer, only receives clean traffic.
- Announce your IPv4 prefix with AS215691 as your upstream BGP
- Hostealo Shield applied to all incoming traffic
- ASN / country blocking and IP lists managed by you
- Managed LOA + RPKI, valid if you re-announce to your own BGP customers
- Compatible whether or not you have your own LIR
Internet
Mixed traffic + attacks
AS215691 · Upstream
Hostealo, your BGP provider
Hostealo Shield
L3/L4 scrubbing · ASN/country · IP rules
Your AS · Downstream
Receives clean traffic
What's included (and what isn't)
Included at no cost
- • L3/L4 mitigation on all services
- • Per-application filter auto-discovery
- • Advanced per-IP panel (Madrid)
- • 24/7 NOC monitoring sustained attacks
- • No attack traffic surcharge
Not included
- • L7 mitigation (HTTP flood, bots, scraping); handled server-side or with a WAF
- • Basic Anti-DDoS in NY doesn't expose a per-application filter catalogue
- • IP Transit with Anti-DDoS quoted case by case (not included with VPS/dedicated)
- • Manual tweaks outside Madrid (closed catalogue)
Frequently asked questions
What a sysadmin or CTO actually asks before trusting their network to an Anti-DDoS: coverage, mitigation latency, visibility, AI integrations and what happens with false positives. Yours missing? Drop us a line.
Get in touch →We cover the main vectors at L3 (network) and L4 (transport): SYN flood, UDP flood, ICMP flood, amplification (DNS, NTP, memcached, SSDP), reflection, fragmentation, spoofed IP, ACK flood and TCP reflect. Profiles are applied per application (gaming UDP, voice/VoIP, web, infra, VPN). In Madrid the catalog is extended with 40+ filters manageable from the panel.
L3/L4 Anti-DDoS included, no tickets, no extras
Every Hostealo VPS, dedicated server or colocation includes L3/L4 Anti-DDoS protection from minute one, at no extra cost and no paperwork.