Satcore Remote Shield

Attacks arrive. Your service stays up.

Remote Shield routes traffic bound for your network through the Satcore network. Attacks are filtered out with stateful L3/L4 packet inspection, adaptive traffic analysis and a hardware-accelerated datapath — clean traffic reaches you over a GRE tunnel or cross-connect.

  • Stateful L3/L4 inspection
  • Hardware-accelerated datapath
  • Distributed filtering
4Tbps+
Mitigation capacity
<1ms
Filtering latency
L3/L4
Protected layers

Included with every Remote Shield plan

DDoS protection

Attack traffic is filtered out before it reaches your network.

NetOps control panel

See what Shield sees: monitor traffic, analyze attacks and manage your rules.

Take a closer look at the panel

Why protection?

One attack can take your whole line down.

Launching a DDoS attack has never been cheaper or easier. On an unprepared network, a few minutes of attack means downtime, lost revenue and lost trust.

A full line beats any firewall

When a volumetric attack exceeds your link capacity, a firewall behind that link can no longer help. Remote Shield stops the attack in the Satcore network, before it reaches your line.

One IP is enough

Even if a single server is targeted, every service sharing that line goes down with it.

Every minute of downtime costs

An unreachable website, game server or API means lost customers and lost trust.

Attacks keep changing

From UDP floods and amplification to SYN floods and carpet bombing across an entire block — attackers keep switching methods.

What’s protected

Everything on your network. Behind one shield.

Remote Shield protects your infrastructure against L3/L4 attacks, from a single IP address to all of your IP blocks.

  • Websites & APIs

    Your web and application servers stay reachable.

  • Game servers

    Latency-sensitive game traffic keeps flowing.

  • DNS, email & VoIP

    Your critical infrastructure services stay up.

  • VPN & remote access

    Your team stays connected, even under attack.

  • Servers & colocation

    Every system you host is protected.

  • Entire IP blocks

    From a single IP to all of your prefixes.

Attack coverage

Every known L3/L4 attack. One shield.

From volumetric floods to protocol attacks, from reflection and amplification to carpet bombing across an entire block — Satcore Shield protects against the attack types seen across the network and transport layers.

Volumetric floods

Try to fill your line with sheer volume.

  • UDP flood
  • ICMP flood
  • GRE flood
  • IP fragment flood
  • Spoofed-source floods

Reflection & amplification

Abuse open servers to multiply traffic and bounce it at you.

  • DNS
  • NTP
  • SSDP
  • Memcached
  • CLDAP
  • SNMP
  • Chargen
  • WS-Discovery
  • ARMS
  • CoAP
  • NetBIOS
  • Portmap
  • TFTP
  • mDNS
  • RIPv1

Protocol & state exhaustion

Try to exhaust the resources of your servers and devices.

  • TCP SYN flood
  • SYN-ACK flood
  • ACK & ACK-PSH flood
  • RST & FIN flood
  • Invalid TCP flags (XMAS, NULL)
  • Connection floods
  • Teardrop & Ping of Death
  • LAND attack

Multi-vector & evasive

Combine methods and keep changing to slip past defenses.

  • Carpet bombing
  • Pulse-wave (hit-and-run)
  • Multi-vector attacks
  • Game & VoIP UDP floods

How Shield stops them

  • Stateful inspection

    Connection state is tracked, so packets that don’t belong to a valid session — ACK, RST or FIN floods — never reach you.

  • SYN protection

    The TCP handshake is validated before a connection is passed on, so SYN floods can’t exhaust your servers.

  • Protocol validation

    Malformed headers, invalid flag combinations and broken fragments are dropped on sight.

  • Reflection filtering

    Unsolicited responses from reflector protocols are recognized by source port and signature and filtered out.

  • Adaptive thresholds

    Shield learns your normal traffic profile and applies dynamic rate limits as soon as traffic turns anomalous.

  • Line-rate filtering

    A hardware-accelerated, distributed datapath filters at line rate, with 4 Tbps+ of mitigation capacity.

Connectivity

Two ways to connect. Clean traffic, delivered.

Your traffic is cleaned in the Satcore network and delivered over whichever path suits your infrastructure.

GRE tunnel

Wherever your network is, clean traffic is delivered through a GRE tunnel over the internet. Latency depends on the distance between your network and our data centers.

  • Connect from any location
  • No physical link to Satcore needed

Cross-connect

If your servers are in one of our data centers, you connect straight to the Satcore network over a direct physical link.

  • Direct link, no tunnel
  • Lowest latency

Our data centers

Where you can cross-connect.

Connect directly to the Satcore network in our data centers in Germany and Istanbul — low-latency, resilient and secure.

1 Langen · Germany
2 Başakşehir · Istanbul
3 Sancaktepe · Istanbul
Points of Presence
3Data Centers 2Countries
  1. 1 Germany Active
    Langen · Germany Tornado DC
  2. 2 Türkiye Active
    Istanbul · Başakşehir Datacasa DC
  3. 3 Türkiye Active
    Istanbul · Sancaktepe Zenix DC

Pricing

Transparent pricing. Per Mbps.

Pick the bandwidth you need and see the monthly price instantly. The price per Mbps drops as capacity grows, down to €0.60 from 5 Gbps.

Bandwidth

1 Gbps1,000 Mbps

Monthly

€800/ month

€0.80 per Mbps

60% less per Mbps

Request this plan

In every plan

Prices are monthly, in euros (€). For more than 10 Gbps, get in touch.

Satcore Shield · NetOps Panel

Your protection. In full view.

Every Satcore Shield service comes with the NetOps panel. Watch your protected network’s traffic live, analyze every attack in detail and take action instantly. All included with Shield.

Already a Shield customer? Sign in to NetOps

NetOps Traffic Flow view with clean and blocked traffic charts

01Monitor

Don’t guess. See.

The Traffic Flow view splits everything reaching your network in two: clean traffic and the attacks Shield blocks. The ports and countries an attack comes from are right there on the same page.

  • Switch between Mbit/s and pps in one click
  • Breakdown by protocol and TCP flag
  • Top attacking source ports and countries
  • IP filtering and auto-refresh
Top attacking source ports and the countries attacks come from

02Analyze

Every attack, on record. Every record, the full story.

Every attack Shield detects is recorded in NetOps: target IP, duration, peak traffic and packet rate. Carpet-bombing attacks spread across a whole block are flagged separately. One click takes you into the details.

NetOps Attack Records list
Attack detail view with traffic chart, source countries and carrier networks
Blocked attack 9 min 20 s · Ended
873Gbit/s
Peak traffic
326M pps
Peak packet rate
35.4TB
Traffic blocked
105.9billion
Packets blocked

03In depth

Know your attacker.

See which countries and carrier networks an attack comes from, which ports it targets and which protocol it uses. Then drill down to raw packet samples.

Attack connection flow and raw packet samples
  • Country & ASN

    Where traffic originates, down to the carrier network.

  • Port analysis

    Destination and source ports, by volume and share.

  • Protocol & flags

    UDP and TCP SYN, ACK and RST, broken out.

  • Raw packet samples

    Each one with source IP, VLAN, MAC and ASN.

04Control

Take action. Yourself.

No ticket, no waiting. Set rules and limits and edit PTR records yourself, right in the panel.

Add traffic limit dialog

The right speed for every IP.

Set download and upload limits for a single IP or an entire block. Presets from 1 Mbps to 1 Gbps — or type in any higher value.

IP Management with blackhole, whitelist and international blocking

Blackhole, whitelist and more.

Blackhole any IP or CIDR range, whitelist addresses that should bypass filtering, keep custom IP lists and shut off international traffic in one click.

RDNS PTR record management view

PTR records, on one screen.

Edit the hostname record of every address in your IP blocks — one by one or in bulk.

05Get notified

When there’s an attack, be the first to know.

When Shield detects an attack — and again when it ends — NetOps alerts your team, with target IP, peak values, duration and flow samples right in the message.

  • Webhook support (e.g. Discord)
  • Start and end notifications
  • Total blocked volume and flow samples
NetOps attack notifications delivered to Discord

Included with Shield

Everything you need. In one panel.

Traffic Flow

Clean and blocked traffic, as it happens.

Attack Records

Automatic detection, complete history.

Attack Analysis

Country, ASN, port and packet detail.

Firewall Log

See exactly what your rules are doing.

IP Management

Blackhole, whitelist and custom IP lists.

Block International

Cut off traffic from abroad in one click.

Traffic Limiting

Rate limits per IP and prefix.

RDNS

Edit PTR records one by one or in bulk.

ARP Usage

Keep track of ARP usage on your network.

Sub-users

Give your team access with their own accounts.

Recent Activity

A record of every action taken in the panel.

Webhook Alerts

Alerts your team when an attack is detected.

Already a Shield customer? Sign in to NetOps

Get in touch

Put your network under protection.

Tell us your capacity and preferred connection, and we’ll prepare your Remote Shield quote.

Our customers

Companies that choose Satcore.