DDoS Protection

How Anycast Routing and Traffic Scrubbing Keep You Online

The two technologies that quietly absorb a DDoS attack before it reaches your server — anycast routing and traffic scrubbing — explained without the jargon.

On this page
  1. Anycast: one address, many front doors
  2. Scrubbing: cleaning the traffic, keeping the good
  3. Why your server can’t do this itself
  4. What this means for you

When a DDoS attack hits and your server stays online, two pieces of infrastructure usually did the work long before the traffic got anywhere near your machine: anycast routing and traffic scrubbing. Neither is something you configure — but understanding them tells you what “protected hosting” actually buys you.

Anycast: one address, many front doors

Normally a server has one IP that maps to one physical location. If an attacker points a flood at it, all that traffic converges on a single point — and a single point has a limited pipe.

Anycast changes the geometry. The same IP address is announced from many locations around the world at once, and the internet’s routing automatically sends each visitor to the nearest one. For normal users this means lower latency. For an attack, it means the flood gets split across the entire network instead of piling onto one door. A botnet firing from five continents gets spread across five continents’ worth of capacity, and no single location has to absorb the whole thing.

Kerit Cloud runs on the AS203446 network backbone with anycast routing, so traffic is distributed and absorbed at the edge rather than funnelled to one vulnerable point.

Scrubbing: cleaning the traffic, keeping the good

Splitting traffic isn’t enough on its own — you still have to separate the attack from the real visitors. That’s scrubbing. Incoming traffic is routed through scrubbing centres that inspect it in real time, drop the malicious packets, and forward only the clean, legitimate traffic to your server.

Think of it as a filter your traffic passes through on the way in:

  1. Everything arrives at the edge (spread out by anycast).
  2. The scrubbing layer identifies floods, malformed packets and abusive patterns.
  3. Junk is dropped; only clean traffic continues to your server.
  4. Your server only ever sees the legitimate visitors — with no meaningful latency added.

Kerit Cloud combines OVH’s TCP Shield and Cloudflare Magic Transit for a combined 17+ Tbps of scrubbing capacity, plus SMART-NET behavioural filtering that auto-tunes to live traffic to catch attacks that change their shape mid-flight.

Why your server can’t do this itself

A common misconception is that a firewall on the server will stop a DDoS. It won’t — for the same reason a lock on your front door doesn’t help if the street outside is flooded. By the time a volumetric attack reaches your machine, the network link is already saturated; nothing the server does can un-saturate it. Protection has to happen upstream, at the network edge, before the traffic reaches you. That’s exactly where anycast and scrubbing live.

For a breakdown of the different attack types this defends against, see understanding L3, L4 and L7 DDoS attacks.

What this means for you

The practical upshot: on protected hosting, you don’t configure any of this, and you don’t get a bill for “mitigation” during an attack. It’s always on:

  • Anycast spreads incoming traffic across the whole network.
  • Scrubbing removes the attack and forwards only clean traffic.
  • Behavioural filtering adapts as attacks evolve.

Whether you run a Discord bot, a Minecraft server or a VPS, that protection is included on every plan. See exactly how it’s built.