Help
Back

Network & Security

We owe you more than just remote access. That’s why we operate our independent network (AS60362), and we let you manage your domains directly from your control center. Everything needs to be simple.

A secured, independent, network

Our own network

We choose to operate our network to ensure full independence. No intermediaries means more trust in our infrastructure, network included. All our network equipment, switches, routers, operate in pairs. Their hardware come from two separate manufacturers. In case of hardware or software failure, we guarantee service continuity.

Four fully redundant operators ensure our connectivity. This means no risk of interruption, nor limitation. It also guarantees net neutrality.

Firewalls

Every server runs its own dedicated firewall, with a set of well-customized blocking rules to keep your services safe. Only ports for running servers and apps are open. We monitor and block unwanted traffic to your accounts. Plus, we choose not to filter output, leaving you free to use what you want in term of outsourcing traffic. Running your apps in a high-security environment is easy!

To be sure you won’t be affected by a malicious intrusion, we also include a Web Application Firewall. Set at the site level, it filters requests based on the OWASP recommended ruleset using an intrusion detection engine. Your apps are well-protected against malicious intrusions like XSS, SQL-injection, and more. Natively.

Anti-DDoS

We take care of attacks, especially DDoS. Every server is configured to automatically resist average level attacks. In case of a massive attack, anti-DDoS protections are automatically activated through our access providers, using two redundant implementations.

When complexly formed attacks happen, our engineers can define personalized blocking rules. If necessary, they coordinate with our network providers.

In case of extremely massive attack — hundreds of GB per sec — a DNS re-routing strategy to a third-party provider can be set up. The scenario is regularly simulated and tested.

IPv6

We natively support IPv6 for all our services. All your customers with an IPv6 address provided by their ISP can access your services and web apps through this protocol. You’re Internet future-proofed by design!

Start with alwaysdata

Sign up on the platform is fast and easy. It gives you access to all available services. You can then have a preview of our service for free. You are also free to choose another premium plan whenever you need to.

See also

Web Application Firewall (WAF)

We had deployed on our production servers a new version of our HTTP reverse-proxy engine. It embeds a lot of new features. We cover them in this collection of blog posts. Here, we want to introduce you to the Web Application Firewall (WAF) that is now built-in our reverse-proxy.

Read more...

SaaS, PaaS, IaaS: what are the differences and what does it matter?

We often get legitimate questions from people who don’t know the alwaysdata solution in-depth. Among those, a recurrent one is about our pricing, which is often due to users not understanding our offerings. We’re aware that this happens because what we do isn’t typical for hosts. So1), let’s take a look at what we’re doing here.

Read more...

Secured remote access, the hard way

Securing remote access goes from trivial things to less-understandable points for non-experts. Consider this article as primary guidance, and feel free to browse some links to more in-depth articles.

Read more...