PRODUCTS / DDOS PROTECTION

DDoS protection

CrownWall absorbs volumetric and application-layer attacks at the edge — before they reach your origin — using rate-based rules and managed IP reputation in the same inline pipeline as WAF and bot control.
Layered edge defence

Shed attack volume before origin impact.

Rate limiting, reputation labels, WAF inspection and bot control share one inline engine — so clean traffic stays low latency while hostile traffic is absorbed at the edge.
L3/L4
network edge
L7
rate limits
Labels
policy chain

Rate-based protection

Stop floods and brute-force bursts at Layer 7 with granular rate limits. Scope any limit with optional match conditions so only suspicious traffic counts toward the threshold.
Exceeded limits trigger block, challenge, or captcha — absorbing application-layer DDoS without starving legitimate users on other routes.

Granular limit keys

Client IP

Per client IP for volumetric abuse.

IP + URL path

Protect login, checkout and search endpoints.

IP + query string

Control enumeration and scraping patterns.

Composite keys

Mix IP, path, method and named headers.

Composite-key example

Cap POST to /api/login per IP independently of GET traffic. Rate limits run in-line with every other security check — no separate appliance or detour.

Managed IP & network reputation rules

Complement rate limits with operator-maintained reputation rule groups that classify traffic from known-bad networks before a flood builds momentum.

Suspicious hosting

Datacenter ranges commonly used for HTTP floods and credential-stuffing campaigns.

Scraper networks

Known scraper and automation networks that drive low-and-slow exhaustion.

High-risk IP space

CrownWall-maintained threat signals updated centrally without tenant redeploys.

Custom CIDR lists

Partner, geo restriction, or emergency takedown lists you maintain.

Semantic labels, not blind blocking

Default actions attach semantic labels such as suspicious-network and hosting-network. Chain policy downstream so you can verify humans, shed bots, block repeat offenders and allow known partners.
Reputation labels flow into access logs and later WAF rules. Audit who was tagged, why, and what action was taken — without assembling forensics by hand after an incident.

First hit from flagged network

Challenge or captcha — verify humans, shed bots.

Repeat offenders after rate limit

Block with Request ID for support triage.

Verified monitors and partners

Allow via label-based exceptions.

Layered defence at the edge

Because reputation, rate limiting, WAF inspection, and bot control share one engine, attackers cannot slip through gaps between separate products — and you pay for legitimate traffic, not attack volume.

L3/L4 volumetric

Attack traffic absorbed at the network edge; origin bandwidth stays available for legitimate users.

L7 application floods

Rate limits cap burst volume per IP, path, and composite key.

Low-and-slow abuse

Reputation rules flag suspicious sources; bot control and WAF rules handle disguised automation.

Policy chaining

Reputation labels + rate-limit-exceeded labels drive block, challenge, or captcha.

Absorb attacks before they reach your origin.