DDoS protection setup
We connect DDoS protection at the CDN/provider level (Cloudflare and analogs): filtering attack traffic, L3/L4 and L7 protection, load modes, rules and limits. So the site survives attacks and spikes rather than crashing. Honestly upfront: smart protection absorbs most typical DDoS, but no one honestly gives an absolute 'will never go down' guarantee — powerful/sophisticated attacks require more serious (and paid) plans, and part depends on the provider's infrastructure.
DDoS protection setup — overview

DDoS protection setup is a project: we connect the site to protection at the CDN/anti-DDoS provider level, set up filtering at the network (L3/L4) and application (L7) layers, heightened-protection modes, rate-limiting, challenges for suspicious traffic, rules and a waiting page in case of an attack. Honestly about guarantees, this is key: smart setup absorbs most typical DDoS attacks and spikes, substantially increasing resilience — but an absolute 'the site will never go down' guarantee does NOT exist and no one will honestly give it: a sufficiently powerful or sophisticated (especially L7) attack can break through basic protection; countering large attacks requires more serious plans and provider resources. Honestly about layers: L3/L4 (volumetric) protections at a CDN are usually strong; L7 (application, mimicking users) are harder and may require tuning/paid modes. Honestly about cost: DDoS protection is a provider service; basic is often included in the CDN, serious (Magic Transit/Business/Enterprise, etc.) is paid, directly, separate from our work. Honestly about false positives: 'under attack' modes (challenge/captcha) can hinder legitimate users — we tune the balance. Honestly about access: access to DNS/infrastructure is needed. An important boundary: this is DDoS protection, not a WAF against exploits (737 — adjacent, different) and not general security. If you are not under attack and traffic is low, serious protection may be overkill. Picture this: instead of 'the site went down from a flood of junk traffic' — attack filtering at the approaches, within your protection plan. The base price starts from 15,000 ₽ per project; it depends on the provider and level (the protection plan — separate).
Problems we solve
- The site crashes from a flood of junk/attack traffic.
- There is no DDoS filtering at the network and application layers.
- Load spikes take down the server.
- There is no 'under attack' mode and protection rules.
What's included in the DDoS protection setup service
- Connecting to CDN/anti-DDoS provider protection
- L3/L4 filtering and basic L7
- Heightened-protection modes and challenges for suspicious traffic
- Rate-limiting and rules
- A waiting page in case of an attack
- Balance of protection and availability for the legitimate
- A plan recommendation for your risk (payment — separate)
- Handover and review with you
What you get
- Absorption of most typical DDoS and spikes
- Higher site resilience under attack
- Filtering at the approaches, server offload
- Reduced downtime risk (no absolute guarantee)
How the work goes: steps
- We clarify risks, provider, level; collect DNS access
- We connect protection, set up layers, modes and rules
- We check availability for the legitimate, review with you
Why PDV Expert
- Fixed price and timeline — no surprises on the invoice.
- Report and recommendations in plain language — clear without a technical background.
- In touch at every step and answering questions about the result.
FAQ
Do you guarantee the site will never go down from DDoS?
No, and no one will honestly give such a guarantee. Smart protection absorbs most typical attacks and greatly increases resilience, but a sufficiently powerful/sophisticated (especially L7) attack can break through basic protection — countering large attacks requires more serious plans.
Is DDoS protection included in the price?
Basic is often included in the CDN; serious protection levels are a paid provider service, directly, separate from our setup. We advise a plan for your real risk, without pushing the expensive one if it is not needed.
Won't protection hinder ordinary visitors?
'Under attack' modes (challenge/captcha) can add friction for legitimate users. We tune the balance of protection and availability and enable strict modes when needed, not constantly.
About the provider
The «DDoS protection setup» service is provided by PDV Expert — a team specialising in «Site quality». We work under contract and deliver a written report with recommendations.