DDoS attack on a Friday evening. The host announces "anti-DDoS included". Legitimate traffic drowned — mitigation active on network side, but HTTP flood passes, API down. Support: "add CDN/WAF". Included protected backbone IP, not your application layer.
"Anti-DDoS included" ranges from basic datacenter scrubbing to multi-Tbps branded system — rarely documented at the same level across products.
Two attack families — two responses
Volumetric (L3/L4). Saturate bandwidth — UDP, SYN flood. Target: host network mitigation.
Application (L7). HTTP flood, expensive requests — target: WAF, rate limit, CDN.
| Common included | Covers | Does not cover |
|---|---|---|
| DC scrubbing | Large L3/L4 flood | Fine L7 HTTP |
| Null route | Infra protection | 100% client availability |
| VPS best effort | Major incident | Client SLA |
OVHcloud, Hetzner, Leaseweb — different profiles
OVHcloud — Anti-DDoS historically central to messaging, documented network capacity.
Hetzner — Protection included, rather autonomous infrastructure profile.
Leaseweb — Anti-DDoS and CDN at scale segment.
Always read exact product: game dedicated ≠ entry VPS.
Included = network safety net. L7 = Cloudflare or managed WAF budget.
Questions to ask in contract
What Gbps threshold before null routing? Is HTTP flood filtered or only volumetric? Overage cost beyond attack volume? Does client SLA cover unavailability during mitigation? Also ask if your IP can be isolated (null route) without notice — some contracts protect global network at the expense of your individual availability.
Scenarios where included is not enough
E-commerce with public checkout, API without authentication, exposed webhooks, admin without IP restriction — all remain vulnerable to HTTP flood even when the datacenter absorbs massive SYN flood. Application attacks target expensive URLs: search, cart, CSV export. Without rate limiting and CDN, network included does not filter load at the right layer.
In practice, stack three layers: host network anti-DDoS (included), CDN or edge WAF for L7, application rate limit on sensitive routes. Test abnormal load scenario in staging before Black Friday — you will quickly see if only backbone holds up.
The peak: unlimited describes the network, not your SLA
Decide and move forward without blind spots
Map your attack surface: public API, admin, DNS, webhooks. If service is critical, stack CDN or WAF at layer 7 even with included anti-DDoS. Ask in writing for Gbps threshold and null route behaviour. Compare via the directory and article security upsell to decode commercial messaging.
Frequently asked questions
Does included anti-DDoS protect my web application?
Partially. Included coverage mainly handles network volumetric attacks (UDP flood, SYN) on host IP. HTTP L7 attacks, slowloris, sophisticated bots often need additional WAF/CDN.
What attack volume is covered?
Variable: OVH/game hosting announces high scrubbing capacity; entry VPS may be "best effort" without contractual figure. Ask Gbps threshold and behaviour beyond (null route, billing).
Included anti-DDoS vs Cloudflare Pro?
Included = host network protection on IP; Cloudflare = global edge + L7 + cache. Complementary — partial overlap on volumetric.
Can a DDoS attack suspend my account?
Yes if neighbours impacted or AUP — even when "protected". Read abuse clause and null routing before relying on included alone.
Anti-DDoS included? Ask if HTTP flood is covered — not just UDP.
