---
name: cis-ddos-about
title: About DDoS protection in CIS
description: CIS provides DDoS protection through DNS ingestion, traffic inspection, unlimited mitigation, and integrated Layer‑7 security features.
last-updated: 2026-02-06
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/cis?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# About DDoS protection in CIS
{: #about-ddos}

CIS provides DDoS protection through DNS ingestion, traffic inspection, unlimited mitigation, and integrated Layer‑7 security features.
{: shortdesc} 

## How CIS ingests and protects traffic
{: #cis-on-demand-anti-ddos}
 
IBM Cloud Internet Services ingests traffic by returning a CIS IP address on the DNS lookup for a domain, instead of the actual record for the origin server’s IP address. This allows CIS to ingest, single‑pass inspect, and re‑encrypt data before sending it to the origin server destination.

CIS can also act in DNS-only mode, returning the actual DNS record without obfuscating the IP, which disables DDoS and the other functions of CIS. To enable CIS protections, switch the "proxy" slider next to each DNS record to **on**; to disable protections, switch to **off**.

## Unlimited DDoS mitigation
{: #cis-unlimited-ddos-mitigation}
 
DDoS mitigation is typically an expensive service that can grow in cost when under attack. Unlimited DDoS mitigation is included with CIS at no additional cost.

## Layer‑7 mitigation options available in CIS
{: #cis-mitigate-layer7-attacks} 

Though DDoS is enabled by default in CIS, you can further configure Layer 7 security by:

* Configuring WAF ruleset sensitivity and response behavior
* Adding rate limiting
* Adding firewall rules

Use these features to customize Layer 7 mitigation of both volumetric and non-volumetric attacks.

## Mitigating non-volumetric attacks
{: #cis-mitigate-non-volumetric-attacks}
 
CIS WAF contains rulesets to mitigate non-volumetric attacks, including cross-site forgery, cross-site-scripting (XSS), file inclusion, and SQL injection. For additional information about WAF, see [Web Application Firewall concepts](https://cloud.ibm.com/docs/cis?topic=cis-waf-q-and-a&format=markdown).

## Related links
{: #about-ddos-related-links}
 
* [DDoS attack concepts](https://cloud.ibm.com/docs/cis?topic=cis-ddos-attack-concepts&format=markdown)
* [Preventing DDoS attacks](https://cloud.ibm.com/docs/cis?topic=cis-preventing-ddos-attacks&format=markdown)
* [Responding to DDoS attacks](https://cloud.ibm.com/docs/cis?topic=cis-responding-to-ddos-attacks&format=markdown)
* [Using Defense mode for DDoS attacks](https://cloud.ibm.com/docs/cis?topic=cis-defense-mode-attack-ddos&format=markdown)
* [Third-party services and DDoS protection](https://cloud.ibm.com/docs/cis?topic=cis-third-party-ddos&format=markdown)
* [HTTP DDoS Attack Protection managed ruleset](https://cloud.ibm.com/docs/cis?topic=cis-http-ddos&format=markdown)