> For the complete documentation index, see [llms.txt](https://docs.up-network.ch/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.up-network.ch/documentation/en/ddos/swissshield-ddos-protection.md).

# SwissShield: DDoS protection

Standard SwissShield and SwissShield Permanent have different scopes. Your service’s protection also depends on its delivery location and the addresses concerned.

## Standard protection and the permanent option

| Protection                   | Scope                                                                                                                                      |
| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
| Standard SwissShield / Basic | Local mitigation advertised up to 20 Gbit/s in Switzerland, included with eligible plans.                                                  |
| SwissShield Permanent        | Permanent routing of the relevant IPv4 addresses through a scrubbing partner, with an advertised capacity of up to 2 Tbit/s, as an option. |

Scrubbing capacity refers to the partner’s advertised mitigation capacity. It does not correspond to the usable bandwidth of your VPS, port or tunnel, and does not guarantee uninterrupted service.

On VPS plans, the permanent option provides an **additional IPv4 address** dedicated to this routing path. Your primary IPv4 address and your IPv6 do not automatically receive protection through the same permanent routing. Use the address intended for the application to be protected, after confirmation of its activation.

## Protection for network services

In Gland, SwissShield Basic is included and a permanent option may cover supplied IPv4 addresses or an eligible BGP subnet. The price and scope are shown in the configurator and technically validated.

In Zurich, UP-Transport uses an **automatic null-route** in the event of an attack. A null-routed address is no longer accessible while this protection is active. Gland’s behaviour must not be assumed to apply to Zurich.

## Client settings and history

The SwissShield rules, summary and history screens in BILLmanager are still in limited rollout. They are not accessible to all clients who have ordered the permanent option. For a setting change or diagnosis, open a ticket for the service concerned.

## In the event of an incident

Provide the attacked IP address, time and timezone, protocol and observed impact. Maintain an appropriate application firewall and do not change your routes at random.

The [SLA policy](/documentation/en/infrastructure/service-levels.md) excludes downtime caused by DDoS attacks. The second SwissShield Permanent IPv4 address has no availability SLA.

Updated on 3 October 2026. References: [VPS](https://up-network.ch/services/vps-hosting), [network](https://up-network.ch/services/network-solutions), [SLA](https://up-network.ch/sla).
