HomeProductsDDoS Protection
Products / DDoS Protection · D1 · D2 · D3

Always-on protection for infrastructure that is exposed by design.

Every Joy server is behind volumetric and L3–L7 scrubbing at no extra charge. Networks that run their own routers get the same filtering as DDoS-protected transit or Virtual Connect over GRE — detected by NeuroMesh NetFlow, diverted by BGP, delivered clean.

BetaBeta — ordered by ticket, pricing final, SLA applies
Joy DDoS Protection — product tile with the D1, D2 and D3 feature boxes
Overview

Attacks against game hosts, ISPs and SaaS platforms in India are routine, not exceptional, and a filter that has to be switched on after the flood begins is already too late. Joy's scrubbing is always on. NeuroMesh NetFlow collects encrypted flow telemetry from every edge of AS152565, scores anomalies in real time and triggers BGP diversion for the affected prefixes; clean traffic returns to the customer over the backbone, or through a GRE tunnel to a router anywhere on the internet.

Volumetric floods, amplification (DNS, NTP, SSDP, memcached), SYN/ACK storms and L7 request floods are handled automatically. Customers can request custom rules for game protocols, use the 152565:666 community to blackhole a single /32 at every edge, and see mitigation events on the status page when they affect a component. For HTTP origins the CDN adds bot filtering and an optional managed WAF ruleset.

Protection is included with every VPS, bare-metal server and colocation port. Networks that are not in a Joy facility buy it as DDoS-protected transit or as Virtual Connect — BGP over GRE that puts Joy scrubbing in front of infrastructure you already own, from any provider that gives you a public IP with GRE pass-through.

What makes it Joy

D1 · D2 · D3

The three things this product line is built around — the same three boxes you see on the tile.

D1

Filtering built for floods, protocol abuse and L7

Volumetric floods, amplification vectors, SYN/ACK storms and HTTP request floods are classified by flow telemetry and dropped at the edge; legitimate sessions keep their state and their latency.

D2

Built to absorb and mitigate at scale

Scrubbing capacity at every edge of AS152565 with BGP diversion per prefix, so an attack on one customer never fills the port of another; mitigation events are published on the status page.

D3

Always-on for exposed infrastructure

No activation delay and no per-attack charges. Game servers, DNS, VPN concentrators and public APIs are protected from the first packet, on Joy hardware or on your own router through Virtual Connect.

What you get

Specification

CoverageAlways-on volumetric and L3–L7 filtering for every Joy VPS, dedicated server and colocation port at no extra charge
DetectionNeuroMesh NetFlow: encrypted flow telemetry from every edge, real-time anomaly scoring, automatic BGP diversion
VectorsUDP/ICMP floods, DNS/NTP/SSDP/memcached amplification, SYN/ACK storms, HTTP request floods
DeliveryClean traffic over the backbone to Joy servers; DDoS-protected transit on a Joy port; Virtual Connect (BGP over GRE) to your router anywhere
Customer controlsBlackhole community 152565:666 per /32 or /128; per-upstream communities; custom rules for game protocols on request
HTTP originsCDN bot filtering on every resource; managed WAF ruleset $10 per hostname per month
Pricing (networks)DDoS-protected transit from $700 / Gbps (95th percentile), 5% discount per doubling of commit; Virtual Connect from $200 for 100 Mbps
VisibilityMitigation events on the status page; traffic graphs and session state on the Network page for transit customers
How it works

Three steps

Traffic is measured at every edge

Flow telemetry from all of AS152565 is scored continuously against per-prefix baselines by NeuroMesh NetFlow.

Attack traffic is diverted and scrubbed

BGP diverts the affected prefix into scrubbing; floods, amplification and request storms are dropped while legitimate sessions pass.

Clean traffic is delivered

Over the backbone to your Joy server, on a protected transit port, or through a GRE tunnel to your own router — with the event visible on the status page.

Use cases

Where DDoS Protection fits.

Game server hostsMinecraft, FiveM, Rust and CS2 communities on Mumbai and Noida compute with rules tuned for UDP game traffic.
ISPs and downstream networksAnnounce your prefixes through AS152565 and receive clean traffic on a protected transit port.
Infrastructure you already ownPut Joy scrubbing in front of servers at another provider with Virtual Connect over GRE.
Public DNS and VPN endpointsServices that must answer every packet, protected without state-breaking filters.
SaaS and payment APIsAbsorb request floods at the edge and keep the origin reachable for real customers.
Events and launchesTicket sales, exam portals and live streams where a predictable attack window is part of the plan.
FAQ

Questions about DDoS Protection.

Is protection really free on a VPS?
Yes. Always-on scrubbing is part of every VPS, dedicated server and colocation port on AS152565 with no add-on and no traffic cap for protection. Charges apply only to networks buying protected transit or Virtual Connect for their own infrastructure.
What is Virtual Connect?
DDoS-protected transit delivered to a router that is not in a Joy facility. You announce your prefixes to AS152565 over BGP inside a GRE tunnel; the internet reaches you through Joy, attacks are scrubbed at our edge and clean traffic arrives through the tunnel. Minimum commit is 100 Mbps from $200; above 1 Gbps it is priced as protected transit.
Can I blackhole an address myself?
Transit customers tag a /32 or /128 with community 152565:666 and it is dropped at every edge. VPS customers open an Urgent ticket and the on-call engineer applies it within minutes.
Will I be told about attacks?
Mitigation events that affect a component appear on the status page and in status.json. Transit customers see session state and traffic graphs on the Network page; larger events get a ticket from the NOC.

More answers in the full FAQ — billing, network, DDoS, backups, support and legal.

Pricing

Included with every server · from $700 / Gbps for networks

VPS and dedicated servers are protected at no charge. DDoS-protected transit and Virtual Connect for your own routers are priced per Gbps on the peering page.

Product family

Works with

All ten products
Get started

Build DDoS Protection into your stack.

Create an account and deploy in under ninety seconds, or talk to sales about a design for your workload — regions, sizes, timelines and a quote within one business day.

One console, one wallet, one API for every product line
Always-on DDoS scrubbing on AS152565 — no add-on
Prices in USD, shown in USD; GST invoices for India
24/7 help desk staffed by the engineers who run the network