What it is
Cloudflare sits in front of your application and absorbs DDoSDDoSDistributed Denial of Service โ an attack that floods a site with junk traffic from many sources to knock it offline. attacks across a network with hundreds of Tbps of capacity. Always-on, Cloudflare-managed rulesetsmanaged rulesetA set of security rules that Cloudflare writes and keeps up to date for you, so you don't have to maintain them. detect and mitigate both network-layerL3/4Layers 3 and 4 โ the Internet's โplumbingโ layers, where raw volumetric network floods happen. (L3/4) and application-layerL7Layer 7 โ the application (HTTP) layer, where smart, web-specific attacks happen. (L7) floods automatically โ with unmetered mitigation on every plan.
Why it helps the client
- Automatic, always-on mitigation โ attacks are stopped at the edge before reaching origin.
- Unmetered protection โ you're never billed more for being attacked.
- Coverage across all layers, from volumetric network floods to sophisticated HTTP attacks.
- Tunable sensitivity and actions so legitimate traffic keeps flowing.
Why they'd want it
- Confidence that a headline-grabbing attack won't take them offline.
- No emergency scaling scramble or surprise bills during an attack.
- Protection that's on by default, backed by one of the world's largest networks.
๐ฌ How it actually works
- Protection is always-on and automatic across L3/4L3/4Layers 3 and 4 โ the Internet's โplumbingโ layers, where raw volumetric network floods happen. (network floods) and L7L7Layer 7 โ the application (HTTP) layer, where smart, web-specific attacks happen. (HTTP floods). Attack traffic is absorbed at the edgethe edgeโThe edgeโ means Cloudflare's servers spread across the world, close to your users โ as opposed to one central data center. across a network with hundreds of Tbps of capacity, dispersed over many data centers instead of hitting a single chokepoint.
- Cloudflare-managed DDoSDDoSDistributed Denial of Service โ an attack that floods a site with junk traffic from many sources to knock it offline. rulesets fingerprint attack traffic in real time. L3/4L3/4Layers 3 and 4 โ the Internet's โplumbingโ layers, where raw volumetric network floods happen. mitigation is fully automatic; the HTTP DDoS ruleset can be tuned for sensitivity and action (block vs managed challenge).
- Mitigation is unmetered on every plan โ you're never billed more for being attacked โ and there's no 'reroute to a scrubbing center' delay because every PoPPoPPoint of Presence โ a physical Cloudflare data center location where our servers process traffic. More PoPs means we're closer to more users. is a scrubbing center.
- Adaptive DDoSDDoSDistributed Denial of Service โ an attack that floods a site with junk traffic from many sources to knock it offline. protection learns your normal traffic profile to spot app-specific anomalies, and Advanced TCP Protection defends against stateful / state-exhaustion attacks.
๐ Key terms on this page hover any underlined term anywhere on the site for its definition
- the edge
- โThe edgeโ means Cloudflare's servers spread across the world, close to your users โ as opposed to one central data center.
- DDoS
- Distributed Denial of Service โ an attack that floods a site with junk traffic from many sources to knock it offline.
- origin
- Your own web server or host where your website actually lives. Cloudflare sits in front of it.
- managed ruleset
- A set of security rules that Cloudflare writes and keeps up to date for you, so you don't have to maintain them.
- L3/4
- Layers 3 and 4 โ the Internet's โplumbingโ layers, where raw volumetric network floods happen.
- L7
- Layer 7 โ the application (HTTP) layer, where smart, web-specific attacks happen.
- PoP
- Point of Presence โ a physical Cloudflare data center location where our servers process traffic. More PoPs means we're closer to more users.
Live demo walkthrough
5 stepsScreens below are annotated recreations of the Cloudflare dashboard. The numbered orange pin marks exactly where to click.
Select the website
Websites
Select a website to manage its configuration.
๐ Do this
Open the site you want to protect.
๐ฌ Say this
โDDoS protection turns on the instant traffic is proxied through Cloudflare. Let me show where the controls live.โ
Open Security โ DDoS
Security
DDoS
๐ Do this
Expand Security and click DDoS.
๐ฌ Say this
โHere's the DDoS protection surface. Notice it's already enabled โ there's nothing to switch on and no attack size you need to plan capacity for.โ
Review the managed ruleset
Security
DDoS
๐ Do this
Click Configure on the HTTP DDoS Attack Protection ruleset.
๐ฌ Say this
โThe HTTP DDoS managed ruleset is operated by Cloudflare and always on. We can tune sensitivity and the action it takes, but most customers never need to touch it โ network-layer L3/4 protection is fully automatic.โ
Adjust sensitivity if needed
Security
DDoS
๐ Do this
Point to the sensitivity and action controls (Essentially Off / Low / Medium / High).
๐ฌ Say this
โThe only knobs most teams ever touch: sensitivity and action. If a legitimate traffic spike ever looks attack-shaped, we dial sensitivity down or switch the action to a challenge instead of a block โ all without opening a support ticket.โ
Show mitigations in Events
Security
Events
๐ Do this
Open Events to show real, mitigated attack traffic.
๐ฌ Say this
โAnd every mitigation is fully visible in Security Events with source, service, and rule โ great for the post-incident report that proves the attack never reached the origin.โ