Cutter 8
- vCPU
- 4 × dedicated
- RAM
- 8 GB
- Storage
- 160 GB NVMe SSD
- Transfer
- 10 TB
- IPv4 / IPv6
- 1 / /64 routed
Solution
DDoS protection has to be always-on and upstream of your instance to be useful — mitigation that activates after an attack starts has already let you go down. OnionVPS includes up to 12 Tbps of L3/L4 edge scrubbing at every tier, with optional L7 filtering. The most-attacked workloads are game servers, and they are exactly the ones sold "protection" as an upgrade elsewhere.
| Resource | What you actually need |
|---|---|
| Mitigation | Always-on L3/L4 at the edge, not triggered on detection |
| Capacity | Headroom measured in terabits, not gigabits |
| L7 | Optional application-layer filtering for HTTP floods |
| Behaviour | Filtering, not null-routing — null-routing is the attacker winning |
Location is usually the decision that matters most for this workload — either because latency dominates, or because jurisdiction does.
Every core region carries the full filtering stack.
Most successful attacks start with an origin leak, not a clever technique.
Layer 7 floods look like traffic, so they need a different filter.
Edge scrubbing stops volume; your application must stop expensive requests.
Know who to contact and what to change before the first attack, not during it.
Always-on L3/L4 scrubbing is included at every tier, including the $4 Skiff 1. Only application-layer L7 filtering is a paid add-on.
Filtering comes first — null-routing means the attacker achieved their goal. We null-route only when an attack exceeds what the edge can absorb without harming other customers, and we tell you when we do.
A fraction of a millisecond in normal operation. Traffic passes through the scrubbing layer continuously rather than being diverted when an attack begins, so there is no failover spike either.