DDoS Protection is Cloudo’s unified HTTP / application-layer mitigation on the Edge. Modes: Automatic (default), Standard, and Under Attack. (High remains available for existing configurations.)
Automatic keeps standard protection and escalates locally on the Edge when sustained abnormal traffic is detected. Configured mode stays Automatic; only the effective Edge mitigation state changes. Escalation may temporarily apply managed challenges, rate limiting, or blocking.
Standard keeps baseline protections without automatic aggressive Human Verification. Explicit firewall or rate-limit Managed Challenge rules still work.
Under Attack enables aggressive temporary L7 protection and uses the shared Human Verification engine for browser traffic. Legitimate visitors may be challenged. Prefer Automatic unless you are actively under attack.
Challenge passage on the same card sets how long a visitor remains verified after completing a challenge (default 30 minutes). Configured mode and effective Edge mitigation are separate concepts.
Save draft stores mode and challenge passage in the Control Plane only. Save & Deploy stores those settings and queues the normal Edge config deployment. Live visitor mitigation changes only after each Edge validates and activates the new release. If a deploy fails validation, Edges keep the previous working configuration.
Cloudo protects traffic that reaches Cloudo Edge nodes (application-layer / L7). Very large network-layer volumetric attacks that saturate uplink capacity need upstream/provider mitigation. This is not unlimited DDoS protection.
If the Control Plane is offline, Edges keep serving with their last valid configuration and local protection. Automatic mitigation waits for traffic to stay normal for a cooldown before relaxing, to avoid flapping.
Recent attack events appear on Domain → Security → DDoS Protection. SSL, ACME, and existing cache bypass rules are unchanged by DDoS settings.