DDoS-Guard has introduced a series of updates across its security services. The latest changes add new traffic-filtering parameters, expand bot access controls, improve Twin Tunnel monitoring, extend API capabilities and introduce additional SSL configuration options.

Rather than arriving as one oversized release, the changes have appeared as a collection of smaller updates. In network security, that approach makes some sense: one setting rarely solves every problem, and a security dashboard can accumulate controls almost as quickly as an administrator can accumulate reasons to open it.

Traffic filtering gets a geographic upgrade

DDoS-Guard has added country and broader regional conditions to its protection rules. Administrators can use these parameters to apply different traffic-processing rules depending on where requests originate.

The company has also added a separate regional traffic chart to its general statistics. DDoS-Guard's protection platform analyzes incoming traffic and filters suspicious requests before legitimate traffic is forwarded to the protected resource.

A new country map has also been added to the regional requests module. It shows which countries belong to each region, making the geographic structure easier to understand when configuring protection rules. Geography has therefore acquired another job in the dashboard besides making maps look reassuringly colorful.

Twin Tunnel gets a test mode and more detailed statistics

DDoS-Guard has introduced an automated two-day trial period for its Twin Tunnel service with a 99% discount. The trial can now be activated without assistance from a manager.

Twin Tunnel Rate Limiter has also received a new rule-trigger graph. It shows the amount of traffic discarded by each rule in both bytes and packets, giving administrators a clearer picture of how individual filtering rules perform.

Twin Tunnel is designed as a network protection solution, while DDoS-Guard's wider platform provides protection across Layers 3 through 7 of the OSI model. Its filtering infrastructure analyzes traffic for anomalous and suspicious activity before forwarding it to customer resources.

AI bots now come with an access control list

The "Bot List" section now supports individual access settings for several popular AI services, including ChatGPT, Claude, ShapBot, Direqt, Mistral, Kimi and Perplexity.

Administrators can decide which of these AI crawlers and services are allowed to access a website and which should be blocked. For sites receiving significant volumes of automated traffic, the feature provides a way to distinguish wanted machine traffic from requests that the operator does not intend to serve.

L7 rules gain an AS category parameter

DDoS-Guard has added an "AS Category" parameter to its Layer 7 protection rules. The parameter identifies the type of autonomous system associated with the source of a request.

This provides another way to classify incoming traffic and apply stricter rules to potentially risky categories of autonomous systems. An individual IP address can reveal only so much, while the autonomous system behind it can provide a broader view of where the traffic originates.

The company has also introduced a new "Log" action. It records statistics about matching requests without changing how those requests are processed.

This allows administrators to test new rules against live traffic and measure how many requests would match them before actually changing traffic handling. In other words, the rule can spend some time observing rather than immediately getting involved in the argument.

SSL settings gain additional controls

DDoS-Guard has added new options for managing Let's Encrypt certificate issuance. A new "Only by rules" mode prevents certificates from being issued for subdomains unless a corresponding rule has been configured in advance.

The mechanism is intended to help protect against attempts to exhaust Let's Encrypt issuance limits by requesting certificates for nonexistent subdomains. Administrators can also define the maximum domain level for which certificates may be issued.

Another new option allows the maximum TLS version to be restricted. DDoS-Guard says this can help diagnose compatibility problems with older software and maintain website availability when a newer protocol version causes connection issues.

API capabilities have been expanded

The DDoS-Guard API can now be used to manage the Bot List and retrieve logs related to free SSL certificate issuance. The company has also reworked API functionality for its DNS and L7 Attack modules.

These changes are particularly relevant to environments where security settings form part of automated infrastructure workflows rather than being managed manually through a web interface. The fewer routine operations that require a person to hunt through several dashboard screens, the fewer opportunities there are for configuration archaeology.

Dedicated server configuration gets a redesign

DDoS-Guard has redesigned the dedicated server page and introduced a configurator that lets customers select the required server parameters instead of choosing from a long list of predefined configurations.

The company's software library for protected servers has also been expanded. Available preinstallation options now include Proxmox VE and Docker, as well as S3-compatible storage platforms such as MinIO, SeaweedFS and Garage. GitLab, Gitea and Gogs have also been added.

The expanded software selection covers several infrastructure scenarios, from virtualization and container environments to self-hosted storage and source-code management platforms.

More controls, fewer one-size-fits-all rules

Taken together, the updates add several new layers of control. Regional filtering provides geographic classification, the AS Category parameter adds another way to identify traffic sources, and AI bot controls give website operators a dedicated mechanism for managing automated access.

The changes also extend the operational side of the platform through additional diagnostics, API functions, SSL controls and preinstalled software options.

DDoS-Guard says its infrastructure uses a geographically distributed filtering network with data-center locations across Russia, Europe, the Americas and Asia. The company states that its filtering network has a capacity of up to 4 Tbit/s and supports protection against attacks across Layers 3 through 7.

The latest changes therefore look less like one major product launch and more like a gradual expansion of the security toolbox. In network security, that can be the more practical approach: sometimes one precise filtering parameter is worth more than another giant button labeled "Protect Everything."

Share This Story