Vai al contenuto
PEERYXNETWORK

Guide Anti-DDoS e ingegneria di rete.

Parti da un sintomo osservato o da una scelta architetturale. Queste cinque sezioni collegano le guide a documentazione, strumenti pratici e servizi Peeryx pertinenti.

Esplora per argomento

Attacchi DDoS

Comprendi sintomi DDoS, flood TCP e UDP, riflessione e amplificazione. Distingui la saturazione dell’accesso dai problemi di filtraggio.

19 guide

BGP e Transito IP

Pianifica Transito IP protetto, annunci BGP e consegna del traffico pulito. Guide su GRE, ritorno, FlowSpec, blackholing e più fornitori di transito.

24 guide

Software di filtraggio

Esplora software di filtraggio, DPDK, VPP, XDP e architetture di scrubbing. Pianifica e qualifica l’hardware prima di distribuire Defense Fabric sui tuoi server.

13 guide

Connettività gaming

Diagnostica FiveM e Minecraft, percorsi UDP, fasi di caricamento e consegna via proxy. Distingui filtraggio, applicazione e problemi di hosting.

15 guide

Gestione di rete

Misura il traffico, dimensiona il filtraggio e analizza latenza o incidenti. Guide operative, documentazione Flow Collector e calcolatori gratuiti.

16 guide

Tutte le guide

87 guide

Alcune guide sono disponibili solo in inglese. La lingua è indicata prima dell’apertura.

87 / 87 guide

Anycast DDoS protection: when it helps, when it does not

Anycast distributes traffic toward several points of presence, but it is not a magic shield. The clean delivery model after mitigation still decides latency, stability and customer experience.

BGP e Transito IP3 min di letturaAggiornato In inglese

DDoS protection: hardware or software?

Compare placement, capacity, filtering policy, failure behavior and operating cost before choosing an appliance, software dataplane or managed protected transit.

Software di filtraggio5 min di letturaAggiornato In inglese

Why a firewall alone may not stop a DDoS attack

Separate link saturation, packet processing, connection state and application load to find where a firewall needs upstream or specialist DDoS protection.

Attacchi DDoS5 min di letturaAggiornato In inglese

DDoS mitigation architecture: design the complete path

Map detection, routing, packet filtering and traffic delivery, then verify capacity, return paths, MTU and recovery before putting an architecture into service.

Software di filtraggio5 min di letturaAggiornato In inglese

High-PPS DDoS mitigation: measure the packet path

Find packet-rate bottlenecks with explicit frame sizes, queue and worker measurements, legitimate-traffic tests and a capacity result you can reproduce.

Attacchi DDoS5 min di letturaAggiornato In inglese

DDoS vs DoS: difference, impact and protection choices

Understand the difference between DoS and DDoS attacks, why it changes the mitigation design and when to choose protected IP transit, a protected server, VPS or gaming proxy.

Attacchi DDoS3 min di letturaAggiornato In inglese

DDoS protection costs: compare the complete service

Build a comparable DDoS budget across protected transit, filtering software, hardware and game delivery, with clear commit, percentile and overage assumptions.

Gestione di rete6 min di letturaAggiornato In inglese

Memcached DDoS: diagnosis and mitigation

Diagnose reflected Memcached replies, distinguish victim-side filtering from securing a cache, and preserve legitimate traffic when choosing where to mitigate.

Attacchi DDoS5 min di letturaAggiornato In inglese

NTP amplification: diagnosis and filtering

Distinguish legitimate time synchronization from reflected NTP traffic, restrict exposed control queries and validate mitigation without breaking your clocks.

Attacchi DDoS5 min di letturaAggiornato In inglese

ACK flood protection: mitigate TCP DDoS attacks without blocking real sessions

An ACK flood targets the part of TCP that should normally look legitimate: packets that appear to belong to established connections. The problem is not only bandwidth. High packet rate, spoofed ACKs and asymmetric paths can exhaust firewalls, load balancers, routers or servers before the application understands what is happening. Good mitigation must reduce the flood early while preserving real sessions that already exist.

Attacchi DDoS5 min di letturaAggiornato In inglese

DDoS amplification attack explained: why small requests can become massive floods

A DDoS amplification attack uses third-party services to turn small spoofed requests into much larger responses sent to the victim. The target does not only receive traffic from the attacker. It receives reflected traffic from many legitimate servers on the Internet, often using UDP-based protocols. Understanding amplification is essential before choosing protected IP transit, a scrubbing model or a gaming proxy, because the failure point is usually upstream capacity rather than the application itself.

Attacchi DDoS3 min di letturaAggiornato In inglese

DNS amplification DDoS mitigation: protect exposed infrastructure without blocking legitimate DNS

DNS amplification is one of the most common UDP reflection patterns because DNS is widely available, response sizes can be larger than requests and spoofed traffic can be directed at a victim. The mitigation challenge is precise: blocking all UDP/53 may stop a graph, but it can also break DNS-dependent services. A serious design separates open resolver abuse, reflected floods and legitimate DNS traffic before the attack reaches the customer edge.

Attacchi DDoS3 min di letturaAggiornato In inglese

SYN flood protection: mitigate TCP DDoS attacks without blocking real connections

A SYN flood is not only about sending many packets. It abuses the TCP opening phase to create pressure on connection queues, stateful firewalls, load balancers and exposed servers. Effective protection must filter early, avoid state exhaustion and keep legitimate users able to establish sessions.

Attacchi DDoS7 min di letturaAggiornato In inglese

UDP flood mitigation: stop a UDP DDoS without breaking legitimate traffic

A UDP flood is not just “a lot of UDP packets”. Depending on the service, it can saturate a link, exhaust a firewall, trigger useless responses or disrupt a real-time protocol such as gaming, VoIP, DNS, VPN or a UDP-based application. Good mitigation is not about blocking UDP everywhere. It is about separating obvious noise from useful traffic, protecting upstream capacity and delivering clean traffic with low latency.

Attacchi DDoS7 min di letturaAggiornato In inglese

Volumetric vs application-layer DDoS: differences, risks and the right mitigation model

A volumetric DDoS attack and an application-layer DDoS attack do not break a service in the same way. The first mainly tries to saturate network capacity, ports, packet rate or upstream paths. The second targets service logic: HTTP, APIs, authentication, game proxies or expensive requests. Understanding the difference helps choose a mitigation design that actually works instead of relying on a generic Anti-DDoS promise.

Attacchi DDoS6 min di letturaAggiornato In inglese

Custom XDP for DDoS: when it is worth building

Decide whether custom XDP solves your bottleneck, distinguish its execution modes and define the traffic, measurements and rollback needed before deployment.

Software di filtraggio5 min di letturaAggiornato In inglese

Why low latency still matters under DDoS mitigation

Under attack, staying online is not enough. Useful Anti-DDoS protection must also preserve stable latency, controlled jitter and clean delivery for legitimate traffic.

Gestione di rete3 min di letturaAggiornato In inglese

L3, L4, L7 protection: the real differences in Anti-DDoS

L3, L4 and L7 are often used as sales labels, but they do not protect the same part of the traffic path. This guide explains the real differences between network, transport and application filtering, and how to choose a coherent Anti-DDoS design with protected IP transit, tunnels, reverse proxy or router VM.

Attacchi DDoS5 min di letturaAggiornato In inglese

What to do when your hoster’s Anti-DDoS is no longer enough

When your hoster’s Anti-DDoS is no longer enough, the worst decision is often to migrate in a hurry. This guide explains how to identify the real limit, keep the existing server when possible, then add specialised protection with tunnels, reverse proxy, router VM or protected IP transit.

Gestione di rete7 min di letturaAggiornato In inglese

FiveM stuck loading: find the failing join stage

Separate resource downloads, server builds, loading-screen scripts and network failures with a staged FiveM diagnosis and a complete join acceptance test.

Connettività gaming5 min di letturaAggiornato In inglese

FiveM at OVHcloud: check the offer and the evidence

Distinguish OVHcloud network protection from its Game profiles, verify your server’s actual configuration and diagnose a FiveM incident before changing providers.

Connettività gaming4 min di letturaAggiornato In inglese

FiveM cURL error 56: diagnose the failed receive

Find which FiveM request failed, correlate client, proxy and server evidence, and distinguish a receive error from a timeout or a DDoS diagnosis.

Connettività gaming3 min di letturaAggiornato In inglese

FiveM getinfo failure: check the UDP connection path

Diagnose the FiveM getinfo retry failure, distinguish UDP information exchange from HTTP metadata and identify the failing endpoint before changing protection.

Connettività gaming5 min di letturaAggiornato In inglese

FiveM “Fetching info”: what to check first

A practical triage checklist for players and server staff: identify the stalled stage, save useful evidence and hand the incident to the right operator.

Connettività gaming3 min di letturaAggiornato In inglese

How to choose an Anti-DDoS provider without getting trapped

Choosing an Anti-DDoS provider should not be reduced to a Tbps number or a promise of unlimited protection. What matters is how traffic enters the mitigation layer, how it is filtered, how clean traffic is delivered back, what visibility you get during an attack and which limits actually exist.

Gestione di rete6 min di letturaAggiornato In inglese

Asymmetric routing and Anti-DDoS: what you need to know

Asymmetric routing is not automatically a problem in Anti-DDoS. The real question is which functions require strict symmetry, how clean traffic returns to production, and whether the provider depends on mechanisms such as SYN proxy. This guide explains when asymmetry truly becomes an issue, why some providers tolerate it poorly, and why at Peeryx it does not degrade filtering quality.

BGP e Transito IP5 min di letturaAggiornato In inglese

Low-latency DDoS protection in Europe: why Marseille is strategic

For low-latency DDoS protection in Europe, the location of the scrubbing point matters as much as raw capacity. This guide explains why Marseille is strategic for southern France, Iberia, Italy, the Mediterranean and traffic entering Europe from the south.

Gestione di rete5 min di letturaAggiornato In inglese

Anti-DDoS IP transit for hosting providers and service providers

For hosters, MSPs and exposed service providers, Anti-DDoS IP transit is a network building block that protects prefixes, preserves commercial continuity and returns clean traffic to production. This guide explains how to evaluate it with an operator mindset instead of a simple marketing angle.

BGP e Transito IP4 min di letturaAggiornato In inglese

Anti-DDoS protection for VoIP, gaming, web and latency-sensitive services

VoIP, gaming, interactive web, APIs and real-time services need Anti-DDoS protection built around latency, jitter, false positives and clean traffic delivery. This guide explains how to protect sensitive services without degrading their normal quality.

Gestione di rete7 min di letturaAggiornato In inglese

How to protect a multi-site infrastructure against DDoS attacks

Protecting a multi-site infrastructure against DDoS attacks requires a full architecture: routing, protected IP transit, clean handoff, role segmentation between sites and credible failover paths. This guide helps design multi-site protection that stays usable in real operations.

Gestione di rete4 min di letturaAggiornato In inglese

Dedicated Anti-DDoS filtering server: what is it really for?

A dedicated Anti-DDoS filtering server separates production from the decision layer, enables more precise logic and keeps the existing stack behind it. This guide explains when the model makes sense, when it does not and how to place it cleanly inside the architecture.

Software di filtraggio4 min di letturaAggiornato In inglese

DDoS protection over VXLAN or IPIP: when should you use them?

VXLAN and IPIP do not solve exactly the same clean traffic delivery problem after DDoS mitigation. This guide explains when each one makes sense, which limits matter and how to choose a model that matches your topology, edge design and operations.

BGP e Transito IP4 min di letturaAggiornato In inglese

Filtered traffic delivery: an acceptance checklist

Validate the handoff after mitigation: addressing, routes, MTU, both traffic directions, application behavior and recovery on each delivered path.

BGP e Transito IP5 min di letturaAggiornato In inglese

Build a filtering stack behind upstream mitigation

Assign transport protection, early packet checks, connection policy and application controls distinct duties, with a measurable path through each layer.

Software di filtraggio5 min di letturaAggiornato In inglese

Buying DDoS protection: an operator’s checklist

Compare the actual traffic path, packet workload, delivery limits and acceptance evidence before committing to a DDoS service or filtering platform.

Gestione di rete5 min di letturaAggiornato In inglese

PPS and Gbit/s: build a network test plan

Define packet sizes, legitimate traffic and measurement points before comparing filtering configurations.

Gestione di rete1 min di letturaAggiornato In inglese

How do you mitigate a DDoS attack above 100Gbps?

Mitigating a DDoS attack above 100Gbps requires far more than a large headline capacity number. This guide covers link saturation, PPS, CPU, upstream pre-filtering, dedicated filtering servers and clean traffic handoff to build a credible design.

Software di filtraggio5 min di letturaAggiornato In inglese

BGP Flowspec for DDoS: useful or dangerous?

BGP Flowspec can be extremely effective to coarse-filter a DDoS attack, protect links and buy time for deeper mitigation. This guide explains where it creates real value, where it becomes dangerous and how to integrate it into a serious layered strategy.

BGP e Transito IP4 min di letturaAggiornato In inglese

Upstream Anti-DDoS pre-filtering: when to use it and why it changes everything

Upstream Anti-DDoS pre-filtering is meant to relieve pressure early, protect links and reduce load before fine-grained decision layers take over. This guide explains when to use it, what it should actually do and why it changes the global cost/performance ratio.

BGP e Transito IP4 min di letturaAggiornato In inglese

Anti-DDoS clean traffic delivery: why the handoff matters as much as mitigation

In Anti-DDoS architecture, mitigation alone is not enough: legitimate traffic still has to be delivered back correctly. This guide explains why clean traffic handoff matters as much as scrubbing, how to choose the right delivery model and which mistakes break daily operations.

BGP e Transito IP3 min di letturaAggiornato In inglese

Gaming Anti-DDoS: why generic filtering is not always enough

Gaming needs Anti-DDoS protection built around sessions, latency, false positives and real protocol behaviour. This guide explains why generic filtering is not always enough and how to design a more serious gaming protection model.

Connettività gaming4 min di letturaAggiornato In inglese

XDP vs DPDK for Anti-DDoS filtering: which one should you choose?

The XDP vs DPDK Anti-DDoS question comes up all the time. This guide gives a practical answer for network and security teams: what XDP does extremely well, when DPDK becomes the right tool and which approach usually offers the best cost, performance and operations ratio.

Software di filtraggio5 min di letturaAggiornato In inglese

DDoS protection over a GRE tunnel: benefits, limits and use cases

GRE remains one of the most practical ways to return clean traffic after Anti-DDoS mitigation. This guide also helps compare GRE tunnels, protected IP transit and clean handoff with real architecture, operations and buying logic.

BGP e Transito IP4 min di letturaAggiornato In inglese

Documentazione, strumenti e servizi