How inetHost DDoS mitigation works
Understand monitoring, detection, active mitigation and rules, and learn how to verify the actual status of an IP address.
Updated 8/3/20264 min read
The four parts of the flow
| The four parts of the flow | Meaning | Where to verify |
|---|---|---|
| Monitoring | The IP is observed without active protection | Disabled badge on IP detail |
| Detection | The provider reports attack-like activity | Under attack badge and Attacks tab |
| Mitigation | The IP reports active protection | Enabled badge and Disable Mitigation button |
| Rules | Handle matches by protocol and port | Rules tab |
Related guide: How to tell whether an IP is under attack
What happens when mitigation is enabled
The panel checks the selected address and requests the configured provider to change its mitigation state. It then refreshes the status. The interface confirms success by showing Enabled. Latency, packet loss, or an existing rule are not substitutes for that confirmation.

How rules participate
Rules match an IP, protocol, countermeasure type, and port or range. A allows the match, B blocks after the configured threshold, and R rate-limits to the PPS value. B and R require a positive limit. A rule change can affect traffic when protection uses it, but it does not toggle mitigation.
- Configure TCP, UDP and ICMP separately
- Overlapping ports are validated per protocol
- 0–0 means all ports only for compatible options
- Verify status and rules separately
Frequently asked questions
Does creating a rule enable mitigation?
No. The rule is saved, while mitigation status is checked and changed through the IP-detail control when your service allows it.
Does Disabled mean the service is down?
No. It means the panel reports monitoring without active mitigation for that IP; it does not establish application availability.
