WebGee
Always-on — what you get here
- Filtering is permanently in the traffic path
- Zero activation delay — nothing has to be noticed first
- No routing change, so no propagation wait
- Your IP never changes mid-incident
- Included on every plan at no cost
Included on every plan
Filtering sits in front of every WebGee service, in every location, at no extra cost. There is no add-on to buy, no ticket to raise when an attack starts, and no IP change to push out to your DNS mid-incident.
Cost
Included — no add-on, no surcharge
Activation
Always on, nothing to enable
Coverage
Network, protocol, and application layers
Scrubbing
Upstream, before traffic reaches your port
Locations
All six datacenters
Your IP
Stays the same during an attack
What it stops
Most outages are not sophisticated. They are volume, aimed at whatever is cheapest to exhaust — your bandwidth, your connection table, or your PHP workers.
UDP floods, ICMP floods, and fragmented-packet attacks that try to fill the pipe before anything reaches your server. Dropped upstream, where there is capacity to absorb them.
SYN and ACK floods, and connection-exhaustion attacks that leave your server holding thousands of half-open sockets. Filtered before your connection table fills.
HTTP floods and slowloris-style attacks that look like real visitors and cost real CPU. This is the layer where an uncached WordPress page is most expensive to serve.
DNS, NTP, and memcached reflection, where a small forged request returns a very large response aimed at you. Recognised by shape, not just by volume.
Several of the above at once, rotating as each is blocked. Each vector is mitigated independently, so stopping one does not open another.
Attacks deliberately kept under obvious thresholds to avoid tripping a volume alarm. Caught on behaviour rather than on a packets-per-second line in the sand.
How it works
Your service does not change during an attack. The same IP, the same DNS records, the same server — the difference is what never arrives.
Everything bound for your service passes through mitigation on the way in. Because it is always in path, there is no window between an attack starting and protection engaging.
Signature matching catches known attack patterns; behavioural analysis catches the ones that have not been seen before. Both run continuously rather than on a trigger.
Attack packets are discarded on a network built to absorb them, far from your port. Your bandwidth, CPU, and connection table never see them.
Real visitors reach your site on the same IP they always used. In most incidents the first you hear of it is the report, not the downtime.
Plenty of hosts include mitigation that only routes through scrubbing once an attack is detected. That detection window is precisely when your site is down.
WebGee
Elsewhere
Six emplacements de datacenter
La distance, c'est de la latence qu'aucune optimisation ne rattrape. Choisissez l'emplacement le plus proche de votre audience à la commande — ou demandez-nous de déplacer gratuitement un site existant quand votre trafic évolue.
Europe
Idéal pour: Les audiences européennes et les données résidentes dans l'UE
Amérique du Nord
Idéal pour: La côte ouest américaine, et le saut le plus court vers l'Asie-Pacifique
Amérique du Nord
Idéal pour: Une latence équilibrée sur tout le territoire américain
Asie-Pacifique
Idéal pour: L'Asie du Sud-Est, l'Australie et le sous-continent indien
Moyen-Orient
Idéal pour: Le trafic du Golfe et les entreprises qui doivent garder leurs données dans le Royaume
Moyen-Orient et Afrique du Nord
Idéal pour: L'Égypte et l'Afrique du Nord, sans détour par l'Europe
Tous les emplacements font tourner la même pile : LiteSpeed, stockage NVMe, SSL gratuit, sauvegardes quotidiennes et filtrage DDoS permanent.
DDoS filtering stops floods. It is not a web application firewall, and it will not save you from a problem inside your own application.
SQL injection, cross-site scripting, and vulnerable plugins are application problems. Filtering sees a valid request and passes it through, because it is valid.
Credential stuffing against wp-login.php is low volume by design. Rate limiting, two-factor authentication, and the malware scanning already on your plan are the right tools.
If legitimate traffic is what is taking your site down, that is a capacity problem with a happier cause. Talk to us about a bigger plan rather than a bigger shield.
It is genuinely included on every plan, in every location, at no extra charge. There is no protected tier and unprotected tier — filtering is part of the network, not a line item.
No. There is no switch in the control panel because there is nothing to switch. Protection is in the traffic path from the moment your service is provisioned.
No. Filtering happens upstream of your service, so your IP, your DNS records, and your certificates all stay exactly as they were.
Not in any way your visitors will notice. Traffic passes through mitigation continuously rather than being diverted when something goes wrong, so there is no re-routing penalty and no sudden change in path when an attack begins.
Very large or sustained attacks against a single customer are handled case by case with our team, and larger dedicated mitigation can be arranged for deployments that are repeatedly targeted. Open a ticket and we will size it with you.
Not directly — that is a different job. DDoS filtering stops floods; malware scanning, intrusion prevention, and the firewall tooling included with your plan handle intrusion attempts. The two work alongside each other.
Every plan, every location, no add-on and no activation. Choose the hosting that fits and the filtering comes with it.