New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Any other real CloudFlare alternative in 2022?
Was noticing while some good guy were attacking one of my websites (behind cloudflare) that all the Layer 7 DDos protection solutions are gone or almost.
CloudFlare: shitty / no protection (free plan)
DDoS-Guard: no free plan anymore, min paid jumped from 20$ to 100$
FluxCDN: closed
StackPath: Jumped the prices alot
Bitmitigate: not sure how long will last but the protection is not that great.
Someone know a cheap/free alternative that protects decently?


Comments
Are you sure that your IP behind CF are not leaked? CF can't protect if they attack directly to your IP.
I believe that there is a very active thread about DDOS on LET recently.
https://lowendtalk.com/discussion/179747/massive-layer7-attack-more-than-33-hours/p10
nah is not, it's just that cloudflare challenge get bypassed easly.
Tried https://gcorelabs.com/cdn/free/?
Hi,
we offer a own L7 DDoS Protection solution.
Plans are based on request/quote. So, basing on the website to protect, we’ll create a custom solution.
Thanks for the offer, but I don't really trust hosts that uses the mother VAT to play with servers
Sucuri is an option. I switched out Cloudflare for a while when L7 attacks got really bad.
We have our ddos protection for free for now if you want to give it a try.
you mean you offer free reverse proxy (without hosting) or the one included with the web hostings?
BunnyCDN
Free reverse proxy
and how the order works? from your website I can see it's 25€
Order the service AnycastDNS and add your domain there, if you already have the domain there remove it and add again at the top you will have an IP to use.
EDIT: Forgot to metion this free service is still a work in progress.
If anyone has problems while using cloudflare and our protection at the same time please try to disable cloudflare and see if that solves it since we end up blocking CF IPs because they let DDoS leak through.
If you still have problems with lag or downtime when using only our protection make a ticket or PM me and we will be happy to check it.
If your IPs were at any point in use with the domains before enabling the Cloudflare proxy, it's usually pretty easy with tools like Security Trails to find them. Then there is no need to bypass Cloudflare at all, they can just attack you directly.
Its hard to block attacks if you used your IP publicly before. But Cloudflare has a VPN-Tunnel function in their "Cloudflare Access" offering. So as long as its websites, there would be need to expose your server to the public internet in the first place. The rest could be managed with mesh vpns like zerotier.
Otherwise, if you are in europe, https://fastpipe.io (from @combahton_it ) also has a self developed DDoS solution. Heard good things from it, but unlike Cloudflare you would need to host your stuff there.
Dont use bitmitigate, one of my friends had a server from its owner's other company vanwa. tech.
they paid for 2 extra servers and it didnt deliver, after too many unanswered tickets and no other way to talk to them, they tried contact nick (the owner) via their site's contact form and this is how it went (note: a mass shooting happened around the time this conversation took place):
Friend :
Nick:
Friend:
Nick:
Orange-cloud for every record pointing to the server's IP?
Including the mail.example.com and other records (if hosted on the same server)?
I’m sorry that your friend was screwed over by BitMitigate, but I don’t think anyone here takes Nick Lim seriously. He embarrassed himself (here) a few years ago, and frankly, I’m shocked that the plethora of terrible services under Vanwa still operate.
This, i can't stress this enough, many just keep saying cloudlfare sucks but have email unproxied cause they are hosting email on the same box.
Are you looking for something protecting a VPS or Colo?
With Cloudflare railgun you don't even need to use a nameserver or a valid certificate, just point any domain to an IP.
However I do get hits from other servers with the User Agent Railgun/5.3.3 which makes me wonder how secure the pipe is to Cloudflare
Stackpath, never get problems with this l7!