Skip to main content

Overview

Custom protection profiles define rules and policies based on network traffic and security requirements.

Step 1. Open protection profiles

  1. In the Gcore Customer Portal, navigate to DDoS Protection > Protection profiles.
  2. Review the list of available profiles:
    • Default profiles
    • Custom profiles
Protection profiles

Step 2. Create a protection profile

  1. Click Add protection profile.
  2. Select a template.
    Templates include preconfigured settings for common use cases.
  3. Enter a profile name.
    Use a clear and descriptive name for easier identification.
Example: High-security web server profile
Protection profiles

Step 3. Configure rules and policies

A protection profile includes two configuration areas:
  • Rules
  • Policies
Protection profiles rules and policies

Configure rules

Rules define traffic-matching criteria and apply a selected policy to matching traffic.

Policy reference

This table provides a consolidated reference of the available policies, including what each policy does.

Add a rule

  1. Click Add rule.
  2. Complete the required fields:
    • Protocol: Select the protocol (for example, TCP, UDP, ICMP).
    • Source IP: Enter a source IP address or range.
    • Destination IP: Enter a destination IP address or range.
    • Source port: Enter a port number or range.
    • Destination port: Enter a port number or range.
    • Policy: Select the policy to apply (for example, tcp-server).
Rules are processed from top to bottom. The first matching rule is applied. Traffic that does not match any rule is dropped. To change the rule priority, drag the rule up or down.
Protection profiles rules order
  1. Click Save.
Protection profiles save rule
Multiple rules can be added to a protection profile. Example
Match TCP traffic on destination port 80 (HTTP) and apply a whitelist policy.

Configure policies

Policies define how matching traffic is handled.
Protection profiles Policy
Available policy settings depend on the selected template and profile type. Common options include:
  • Geo filtering
  • Whitelisting
  • Rate limiting
  • Traffic filtering
  • Anomaly detection thresholds
Protection profiles Policy settings

Example: Configure a whitelist

  1. Add trusted IP addresses or ranges to the whitelist.
  2. Confirm that whitelisted traffic bypasses the required protection mechanisms.
Whitelisting is recommended for trusted partners and internal systems.

Save the profile

  1. Review the configured rules and policies.
  2. Click Add protection profile.
Save the protection profile

Best practices and next steps

  • Start with simple rules and expand them as needed.
  • Test new profiles in a non-production environment first.
  • Document rules and policies for future maintenance.
  • Review and update profiles regularly based on traffic patterns.
  • Next, apply the custom profile to a protected network