Cloudways should add DDoS protection service
DDoS is a common problem now, maybe Cloudways can add a DDoS Mitigation service and upgrade their Network hardware to secure against Level 3 DDoS attacks
After some difficulties with Cloudflare, we have spoken now with Sucuri (https://sucuri.net/). They offer malware removal, website firewall (providing DDoS protection among other things, requires DNS redirection to point to their firewalls) and site scanning (via local agent). All features independent (we can offer all or some).
We are thinking that a better approach to solving our customers problems when it comes to security and performance will be to offer (as add-ons) Sucuri (security centric and very focused on our most common apps) and MaxCDN (pure CDN focused on performance).
Any one has had experience with Sucuri? We have already tested (and in talks with them) and looks very promising.
Let us know thoughts on this (Sucuri + MaxCDN) approach (vs Cloudfront). We know this is well overdue and want to get it rolling.
cloudways could alternatively implement dropping packets from IPs that persist say more than 20 requests per specific amount of time
keeps networking simpler and removes another layer of complexity.
For all of your not supporting Cloudflare option. Any alternative suggestions?.
CloudFlare is a steaming pile of crap.
Just surfing behind a proxy, you'll encounter many websites behind the 5-10 second wait time while they verify. I do not recommend building an internet that supports the Cloudflare inefficiency.
I'm all for DDOS protection but please NOT Cloudflare. What a horrible service. When I tried Cloudflare Pro, my site was down many times a day, while the server was up and running fine.
I know a lot of others who had the same issues.
Not to mention a drop on Google when I added Cloudflare, all went back to normal when I removed Cloudflare.
Additionally, DDOS attacker know very well how to workaround Cloudflare, it's so easy. There are Cloudflare resolvers everywhere and any kid with a computer knows it.
Thanks Paul for your comments and graph.
Here we are discussing more about security than performance. It is because of this we are researching Cloudflare as an option.
For CDN and speed, we are most probably going to implement MaxCDN as an add-on https://cloudways.uservoice.com/admin/forums/203824-service-improvement/suggestions/6040498-offer-cdn-services-as-an-add-on. We are currently going over API.
Paul Braren commented
Another approach would be partnering with AWS CloudFront and their CDN, if they're willing to handle DDoS protection too, see http://aws.amazon.com/security/. Also nice if using zone apex that Route 53 offers, see http://aws.amazon.com/route53/faqs/ (so you don't need the www).
I temporarily tested AWS CloudFront to run my entire site a couple weeks back, so an nslookup on my site name would show a CloudFront pool of IPs. In the end, we got tripped up with .htaccess issues, and simply ran out of time to resolve it (.htaccess issues were resolved by Cloudways support)
When it was up for a few days though, the speed was excellent, and much improved outside of north america. See this network diagram and follow the numbers to (hopefully) understand make what I'm describing a bit clearer:
Using AWS CloudFront had the nice side effect of automatic CDN'ing of all my site's images, without any re-coding. That also meant URLs then never needed a CNAME like cdn.tinkertry.com/path/filename.png , instead, simply tinkertry.com/path/filename.png worked fine.
Marcus Stafford commented
Good idea. Would be very useful with paid and pro options.
We are considering partnering with Cloudflare and offer it as an application add-on (similar approach we have taken with New Relic and will take with MaxCDN).
At application tab level, you will have the option to enable it (Free or paid Pro version) or disable.
Let us know your thoughts.
Something like this would be perfect http://www.packetviper.com/products/features/ DDos is an increasing problem and something that if Cloudways doesn't soon do something about will mean we'll look for another host.
There is only so much cloudways can do since the servers are technically on DO/AWS.