Decision guide · Network security
What Anti-DDoS protection do I need for gaming or network services?
There is no single rule for every attack. Document published services, protocols and ports, normal and peak traffic, observed vectors, prefixes, ASN and latency tolerance. ZGH can integrate monitoring, local mitigation and network capabilities, but coverage, thresholds, automation and upstream escalation must be defined for each project.
Use cases
Scenarios that need specific design
Gaming and legitimate UDP
Servers where indiscriminate UDP blocking would interrupt the actual service.
ISPs and BGP networks
Operators that need to protect prefixes and coordinate controlled announcement or diversion policies.
Public platforms
Exposed services where availability, reputation and user experience depend on fast response.
Decision criteria
Layered design
Mitigation should combine evidence, local controls and network coordination without confusing intense traffic with an attack.
-
Baseline
Packets per second, bits per second, flows, countries, protocols and normal time windows.
-
Classification
Separate volumetric, state exhaustion, amplification and application-specific attacks.
-
Local mitigation
Filters and policies targeted to the observed vector while preserving required traffic.
-
Upstream capacity
Define when an attack exceeds local capacity and which escalation mechanism is used.
-
Operations
Alerts, owners, change authorization, evidence, communication and rollback.
Explicit scope
Coverage that must be documented
Components to evaluate
- Network monitoring and alerts
- Protocol or service-specific policies
- Local mitigation according to architecture
- BGP integration where applicable
- Event logs and evidence
- Defined technical escalation
Do not assume without confirmation
- Maximum absorption capacity
- Included and excluded vectors
- Always-on or on-demand mitigation
- Application-layer protection
- Target response time
- Contracted upstream scrubbing or mitigation
AS263702 · Public evidence
An owned and visible network
AS263702 and its interconnections can be reviewed on PeeringDB and BGP.Tools. Network evidence does not replace the contractual definition of a specific protection service.
FAQ
Anti-DDoS questions
Should I block all UDP?
Not when the service requires legitimate UDP, as many games, voice and streaming platforms do. Mitigation must separate required traffic from the attack vector.
Does Basic Anti-DDoS cover every attack?
It should not be read as unlimited coverage. Vectors, capacity, thresholds and escalation must be reviewed per service.
Is BGP required?
It depends on architecture and prefix control. BGP can coordinate announcements or diversion in some scenarios, while others do not require it.
Next step
Design mitigation from real traffic
Share target prefixes or service, protocols, ports, normal peak, previous captures or events and current architecture. We can then define staged protection.