Cloudflare Magic Transit in front of every server. Not an add-on.
Every IP we announce is routed through Cloudflare Magic Transit, so volumetric DDoS is scrubbed at the edge before it reaches the datacentre. No null-routes, no attack-traffic overage, no "premium protection" tier — the same protection on the smallest hourly VM as on the largest.
- Null-route
- hours offline
- Attack bandwidth
- billed per GB
- Clean-pipe add-on
- ₹ per IP per month
- Here
- ₹0 · included
Scrubbed before it reaches the datacentre
Announced through Cloudflare
Our prefixes are advertised to the internet via Cloudflare's anycast network, so every packet to your server first arrives at one of 300+ edge locations.
Scrubbed at the edge
Floods are detected and dropped at the edge in seconds, close to their source. Only clean traffic continues to Noida over private tunnels.
Always on, no tickets
There is no "under attack" switch to flip and nobody to phone. Protection is on before your VM finishes booting.
Never buy bandwidth that is not behind scrubbing
Cheap unprotected transit looks fine until the first flood. Then it is your provider's uplinks at risk, and their fix protects them, not you.
| Unprotected transit | Scrubbed transit (here) | |
|---|---|---|
| A volumetric flood arrives | Saturates the port or the provider's uplink | Absorbed at Cloudflare's edge; your port sees clean traffic |
| Your uptime | Down until the attack stops — or your IP is null-routed for 24 h | Stays up; players, EAs and customers notice nothing |
| Bandwidth bill | Attack gigabytes count toward metered egress or a burstable cap | Not metered; attack bytes never reach you |
| Reputation | You explain the outage to players, clients or the CFO | Nothing to explain |
| Cost of protection | Per-IP add-on, "DDoS tier" or a separate scrubbing vendor | ₹0 — included in every plan |
| Setup | Ticket, waiting, re-IP | Nothing to configure |
The workloads that get attacked
What it does not do — and what to do about it
- Application-layer (HTTP) floods against a website need a reverse proxy or WAF in front of the VM. Cloudflare's free proxy in front of your domain is the usual answer; we can help configure it.
- Your own firewall is still yours. Close ports you do not use; the scrubbing layer does not replace host hardening.
- Legitimate traffic spikes are not attacks and are never filtered. A viral day is a good day.
DDoS protection questions
Is DDoS protection really included on every plan?
Yes. Every prefix we announce goes through Cloudflare Magic Transit, so every VM on every plan sits behind it from the moment it boots. It is not a per-IP add-on and not a tier.
What kinds of attack does Magic Transit stop?
Network- and transport-layer floods: UDP and SYN floods, DNS/NTP/SSDP amplification, fragment and protocol abuse — the volumetric attacks that take unprotected servers offline. Application-layer floods against a website need a reverse proxy or WAF in front (Cloudflare's proxy works well); we can help you set that up.
Will I get null-routed during an attack?
No. Null-routing is what a provider does when attack traffic threatens its own uplinks. Because scrubbing happens at Cloudflare's edge, the flood never reaches our routers, so there is nothing to null-route.
Do attack bytes count against my bandwidth?
No. Attack traffic is dropped before it reaches the datacentre, and there is no metered bandwidth line on our rate card in the first place.
Can I still open any port and run UDP game servers?
Yes. Filtering targets attack signatures and volumes, not your ports. UDP game ports, VoIP, VPNs and custom protocols work as normal.
Do I need to configure anything?
Nothing. Protection is always on at the network layer; there is no dashboard toggle to forget and no "attack mode" to enable.
Deploy behind Magic Transit
Every plan, every size, from the first hour. Nothing to enable.