# DDoS-Protected VPS Explained — What Filtering Actually Covers | NulNet

> Volumetric L3/L4 filtering rides every plan at no extra fee; L7 floods need your application. Where the platform's job ends and yours starts. No ID at signup.

Source: https://nulnet.com/guides/ddos-protected-vps-explained/

[Home](https://nulnet.com/) / [Guides](https://nulnet.com/guides/) / DDoS-Protected VPS Explained — What Filtering Actually Covers How-to

# DDoS-Protected VPS Explained — What Filtering Actually Covers

![NulNet DDoS abstract: cyan shield around racks](https://nulnet.com/img/theme-ddos.png) Volumetric L3/L4 filtering rides every plan at no extra fee; L7 floods need your application. Where the platform's job ends and yours starts.

Published 2026-08-30 · Updated 2026-09-08 · NulNet Editorial

**Short answer** Volumetric L3/L4 filtering rides every plan at no extra fee; L7 floods need your application. Where the platform's job ends and yours starts.

NulNet: VPS from $3/mo and dedicated from $30.80/mo annual. The map spans twenty-one locations — Reykjavik (Iceland) and Zurich (Switzerland) among them, plus Singapore, Dubai, Cape Town and fourteen others. Signup is email plus a 12-character password, or token-only. No KYC. Checkout is crypto-only across BTC, XMR, ETH, BNB, SOL, LTC, TRX, XRP, DOGE, DASH, ADA, GRAM (TON), and USDT (TRC-20/ERC-20/BEP-20/SPL). No payload or guest traffic logs; connection metadata ≤24h. DDoS included. One SKN company, one crypto checkout. Deploy at https://nulnet.com/deploy/.

## The layers that matter

Attack names are layer names. **L3/L4** floods — SYN storms, UDP amplification, ACK abuse — aim at your pipe and your state tables, and upstream scrubbing centers absorb them before a single packet reaches your host. **L7** floods — HTTP hammers, slowloris, API abuse — arrive dressed as legitimate requests, and no network filter can separate them from real users without knowing your application. That separation is the whole story: the platform owns the volumetric layer, the application owns everything that looks like traffic.

VPS from $3* (fund $50+), storage 1–5 TB NVMe from $24/mo annual-eff, dedicated with IPMI from $30.80/mo. Crypto invoice, no KYC.

[Launch now](https://nulnet.com/deploy/?kind=vps&plan=business/)

## What is included on every plan

- VPS and Storage: automatic L3/L4 filtering, always on, no toggle, no extra fee.
- Dedicated: the same filtering plus IPMI access, letting a compromised box be reimaged out-of-band.
- Citadel (top dedicated): an L3/L7 scrubber on the 25 Gbps uplink. ![ddos protected vps — L3/L4 filtering included on every plan](https://nulnet.com/img/art-ddos-shield.webp?v=10)

## Sizing against an attack

- Port speed is your clean-traffic ceiling: unmetered 1 Gbps on entry VPS, 2.5–10 Gbps up the ladder, 1–25 Gbps across the dedicated tiers.
- Carry the stateful defenses in your stack: connection caps, bot scoring, and a CDN in front of HTTP where the surface is web-only.
- Shrink the target — a VPN endpoint or a game server with a community whitelist presents a far narrower face than an open WordPress install.
Is DDoS protection really included, not an upsell? Yes. L3/L4 filtering ships enabled on every VPS, storage and dedicated SKU, with no per-IP fee and no support ticket to request it. The one upgrade is Citadel's L3/L7 scrubber at the top of the metal ladder.

Will filtering block my legitimate users? Volumetric scrubbing is statistical and tuned upstream, so ordinary traffic patterns — browsers, APIs, game clients — pass without notice. What it cannot judge is application-shaped abuse: a slowloris or a valid-looking API flood belongs to your rate limiting or a CDN.

Do Tor exits get DDoS protection? Yes, on the same terms as any server, and exits attract more ambient noise than almost any other workload. Exits are provisioned on request with an abuse contact attached, since the role generates complaints by design.

What happens if an attack still saturates my service? The filters keep the pipe and state tables alive, but an L7 flood that mimics users can still exhaust your application — check connection limits, add caching, or move HTTP behind a CDN. If the box itself wedges, dedicated IPMI lets you reimage without waiting on a KVM ticket.

## Related guides

- [Minimum-data no-KYC checkout](https://nulnet.com/guides/anonymous-vps-crypto-no-kyc/)
- [Buy a VPS with crypto](https://nulnet.com/buy-vps-with-crypto/)
- [No-KYC VPS: requirements and limits](https://nulnet.com/no-kyc-vps/)
- [Pay with Monero](https://nulnet.com/monero-vps/)
- [Offshore VPS](https://nulnet.com/offshore-vps/)
- [VPS vs dedicated bare-metal](https://nulnet.com/guides/vps-vs-dedicated/)
- [Best no-KYC VPS 2026](https://nulnet.com/best-no-kyc-vps-2026/)
- [FAQ: crypto VPS](https://nulnet.com/guides/faq-crypto-vps/)

## Checkout facts

- **Price** VPS from $3/mo. Dedicated from $30.80/mo.
- **Identity** No KYC. Token-only (no email) or email plus a 12-character password. No passport, phone, or card.
- **Payment** Sixteen ways to settle, none of them a card: XMR and BTC lead, ETH, SOL, LTC, BNB and TRX follow, then XRP, DOGE, DASH and ADA, GRAM (TON) for Telegram-adjacent rails, and USDT on four networks — TRC-20, ERC-20, BEP-20, SPL. Live-rate invoice.
- **Logs** No payload / no guest traffic logs. Billing and panel actions retained. Connection metadata ≤24h.
- **Platform** KVM on ECC and local NVMe. DDoS filtering included. Facilities in 21 cities across four continents — the locations table lists each one's tier, uplink and governing law. Need Iceland or Switzerland plus no KYC? Those two carry a published premium (+20% / +35%); every other flag stays at base list. Pay BTC, USDT, XMR, BNB, XRP, GRAM (TON) or 10 more. Open deploy to pick a plan.

## Ready to launch?

Build the box — VPS, storage or bare metal — create the password, pay the invoice that follows.

[Launch now](https://nulnet.com/deploy/?kind=vps&plan=business/)[Dedicated](https://nulnet.com/dedicated/)
