Pengenalan GarudaShield

GarudaShield adalah mesin mitigasi serangan DDoS Layer 4 & Layer 7 lengkap dengan Web Application Firewall (WAF), verifikasi browser, sinkronisasi cluster antar-node, dan dashboard monitoring real-time.

Semua trafik website Anda diarahkan ke GarudaShield terlebih dahulu. Lalu lintas bersih diteruskan ke origin server, sedangkan serangan dibuang di edge β€” sebelum sempat mencapai infrastruktur Anda.

πŸ›‘οΈ

Multi-layer Protection

Layer 4 (SYN/ACK/UDP flood) dan Layer 7 (HTTP flood, slowloris) dalam satu mesin.

πŸ•ΈοΈ

Verify Browser

Interstitial gaya Cloudflare β€” halaman "Just a moment" untuk pengunjung pertama.

🌐

Cluster Sync

Blokir di satu node langsung ter-enforce di semua node melalui sync aman berbasis secret.

πŸ“Š

Dashboard

Monitoring real-time: traffic, geo, blocklist, challenge, cluster, dan event log.

πŸ””

Webhook Alerts

Notifikasi serangan via Telegram & Discord dengan ambang severity dan cooldown.

πŸ—ΊοΈ

Geo Monitoring

Distribusi negara asal pengunjung dan IP penyerang dihitung otomatis.

Arsitektur

Pengunjung
    β”‚
    β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  GarudaShield Edge (node/cluster) β”‚  ← L3/L4/L7, WAF, verify-browser, rate limit
β”‚  port 8080 Β· proxy ke origin     β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                β”‚ trafik bersih (origin IP disembunyikan)
                β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚          Origin Server         β”‚   ← VPS / dedicated / cloud Anda
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

GarudaShield Introduction

GarudaShield is a Layer 4 & Layer 7 DDoS mitigation engine with a Web Application Firewall (WAF), browser verification, cross-node cluster sync, and a real-time monitoring dashboard.

All website traffic is routed to GarudaShield first. Clean traffic is forwarded to your origin server, while attacks are dropped at the edge β€” before they ever reach your infrastructure.

πŸ›‘οΈ

Multi-layer Protection

Layer 4 (SYN/ACK/UDP flood) and Layer 7 (HTTP flood, slowloris) in a single engine.

πŸ•ΈοΈ

Verify Browser

Cloudflare-style interstitial β€” a "Just a moment" page for first-time visitors.

🌐

Cluster Sync

A block on one node is enforced on every node via secret-based secure sync.

πŸ“Š

Dashboard

Real-time monitoring: traffic, geo, blocklist, challenge, cluster and event log.

πŸ””

Webhook Alerts

Attack notifications via Telegram & Discord with severity thresholds and cooldown.

πŸ—ΊοΈ

Geo Monitoring

Visitor and attacker country distribution computed automatically.

Architecture

Visitor
    β”‚
    β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  GarudaShield Edge (node/cluster) β”‚  ← L3/L4/L7, WAF, verify-browser, rate limit
β”‚  port 8080 Β· proxy to origin      β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                β”‚ clean traffic (origin IP hidden)
                β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚          Origin Server         β”‚   ← your VPS / dedicated / cloud
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Quick Start

Aktifkan proteksi dalam tiga langkah β€” kurang dari 10 menit.

01

Daftarkan domain

Hubungi WhatsApp +62 831-8781-5456 atau gunakan dashboard. Masukkan domain Anda dan alamat IP origin server.

02

Alihkan DNS

Ubah record A / CNAME domain Anda menunjuk ke IP anycast GarudaShield.

03

Filter & aman

SSL diterbitkan otomatis. Trafik mulai difilter di edge. Pantau lewat dashboard monitoring.

Contoh perubahan DNS

# Sebelum (langsung ke origin)
www   IN  A  203.0.113.10

# Sesudah (via GarudaShield)
www   IN  A  165.22.56.21

IP origin Anda otomatis disembunyikan dari hasil dig publik.

Quick Start

Protection live in three steps β€” under 10 minutes.

01

Register your domain

Contact us on WhatsApp +62 831-8781-5456 or use the dashboard. Provide your domain and origin server IP.

02

Point your DNS

Change the A / CNAME record to the GarudaShield anycast IP.

03

Filter & secure

SSL is issued automatically. Traffic is filtered at the edge. Monitor via the dashboard.

Example DNS change

# Before (direct to origin)
www   IN  A  203.0.113.10

# After (via GarudaShield)
www   IN  A  165.22.56.21

Your origin IP is automatically hidden from public dig results.

Verify Browser (Interstitial)

Halaman "Just a moment" sebelum pengunjung masuk β€” memblokir bot tanpa mengganggu manusia.

Pengunjung browser pertama kali harus menyelesaikan challenge JavaScript ringan. Setelah lolos, cookie gs_ok diterbitkan sehingga kunjungan berikutnya langsung masuk. Klien non-browser (curl, skrip) diblokir, bukan di-challenge.

Cara kerja

  1. Request pertama tanpa cookie gs_ok β†’ edge membalas halaman challenge (HTTP 200).
  2. Halaman menjalankan JavaScript yang menghitung jawaban dari seed, salt, dan nonce, lalu POST ke /__garuda/verify.
  3. Jawaban valid β†’ server menetapkan cookie gs_ok dengan TTL (default 1800 detik).
  4. Reload β†’ request masuk ke origin dengan normal.

Konfigurasi

{
  "shield": {
    "verifyOnFirstVisit": true,
    "verifyOnFirstVisitHosts": ["protect.garudashield.my.id"],
    "_tokenTTL": 1800000
  }
}
KunciDeskripsi
verifyOnFirstVisitAktifkan interstitial untuk pengunjung baru.
verifyOnFirstVisitHostsDaftar host yang dikenakan interstitial. Host lain tidak terpengaruh.
_tokenTTLUmur cookie gs_ok dalam milidetik (default 1800000).
Tip: IP kantor Anda bisa dimasukkan ke whitelist agar tim internal tidak pernah melihat challenge. Pantau IP yang gagal challenge melalui halaman Challenge di dashboard.

Verify Browser (Interstitial)

A "Just a moment" page before visitors get in β€” blocking bots without annoying humans.

First-time browser visitors must solve a lightweight JavaScript challenge. Once passed, a gs_ok cookie is issued so subsequent visits pass straight through. Non-browser clients (curl, scripts) are blocked, not challenged.

How it works

  1. First request without a gs_ok cookie β†’ the edge replies with the challenge page (HTTP 200).
  2. The page runs JavaScript that computes the answer from a seed, salt and nonce, then POSTs to /__garuda/verify.
  3. Valid answer β†’ the server sets the gs_ok cookie with a TTL (default 1800 seconds).
  4. Reload β†’ the request reaches the origin normally.

Configuration

{
  "shield": {
    "verifyOnFirstVisit": true,
    "verifyOnFirstVisitHosts": ["protect.garudashield.my.id"],
    "_tokenTTL": 1800000
  }
}
KeyDescription
verifyOnFirstVisitEnable the interstitial for first-time visitors.
verifyOnFirstVisitHostsHosts that get the interstitial. Other hosts are unaffected.
_tokenTTLLifetime of the gs_ok cookie in milliseconds (default 1800000).
Tip: Add your office IP to the whitelist so internal teams never see the challenge. Monitor IPs that fail the challenge on the Challenge dashboard page.

Cluster Sync

Satu cluster, satu kebijakan β€” blokir diterapkan di semua node secara otomatis.

Konsep

Setiap node menjalankan GarudaShield penuh. Node-node saling terhubung melalui HTTP dengan shared secret. Ketika satu node memblokir IP, peristiwa tersebut disiarkan ke semua peer dan disinkronkan penuh secara berkala, sehingga IP yang sama langsung diblokir di node lain.

Konfigurasi

{
  "cluster": {
    "enabled": true,
    "nodeId": "edge-ny2",
    "secret": "SHARED-SECRET-RAHASIA",
    "peers": ["146.190.104.237:8080"],
    "heartbeatMs": 10000,
    "syncIntervalMs": 30000
  }
}
KunciDeskripsi
nodeIdNama unik node ini di cluster.
secretShared secret β€” harus sama di semua node.
peersDaftar node lain dalam format host:port.
heartbeatMsInterval heartbeat kesehatan peer (default 10000).
syncIntervalMsInterval sinkronisasi penuh blocklist (default 30000).

Event yang disinkronkan

  • block / unblock β€” peristiwa IP diblokir atau dibuka.
  • whitelist / unwhitelist β€” daftar IP tepercaya.
  • emergency β€” mode darurat diaktifkan/dimatikan.
  • aggressive β€” mode agresif diaktifkan/dimatikan.

Tombstone

Jika sebuah IP sengaja di-unblock/di-remove, node lain "menandai" IP itu (tombstone) selama TTL tertentu agar node yang stale (misalnya karena jaringan terputus) tidak memasukkan kembali IP tersebut saat full-sync.

Penting: Secret harus sama persis antar-node. Periksa status peer, tombstone, dan event di halaman Cluster pada dashboard.

Cluster Sync

One cluster, one policy β€” blocks are enforced on every node automatically.

Concept

Each node runs a full GarudaShield. Nodes connect over HTTP using a shared secret. When one node blocks an IP, the event is broadcast to all peers and periodically fully-synced, so the same IP is blocked everywhere immediately.

Configuration

{
  "cluster": {
    "enabled": true,
    "nodeId": "edge-ny2",
    "secret": "SHARED-SECRET-RAHASIA",
    "peers": ["146.190.104.237:8080"],
    "heartbeatMs": 10000,
    "syncIntervalMs": 30000
  }
}
KeyDescription
nodeIdUnique name of this node in the cluster.
secretShared secret β€” must be identical on all nodes.
peersList of other nodes as host:port.
heartbeatMsPeer health heartbeat interval (default 10000).
syncIntervalMsFull blocklist sync interval (default 30000).

Synced events

  • block / unblock β€” blocked/unblocked IP events.
  • whitelist / unwhitelist β€” trusted IP lists.
  • emergency β€” emergency mode on/off.
  • aggressive β€” aggressive mode on/off.

Tombstone

When an IP is deliberately unblocked/removed, other nodes "tombstone" it for a TTL so a stale node (e.g. after a network partition) cannot re-add it during full-sync.

Important: The secret must be exactly identical across nodes. Check peer status, tombstones and events on the dashboard Cluster page.

Dashboard

Pusat kendali real-time untuk seluruh engine β€” tersedia di port 3000 dengan autentikasi HTTP Basic.

Halaman

HalamanFungsi
OverviewPostur keamanan, mode, dan ringkasan serangan.
AnalyticsGaris waktu threat dan verdict trafik.
TrafficThroughput, sumber request, dan mitigasi.
Geo MapDistribusi negara pengunjung & IP penyerang.
BlocklistKelola IP diblokir.
WhitelistKelola IP tepercaya (dengan info lokasi).
ChallengeStatus interstitial & IP gagal challenge.
ClusterStatus node, peer, tombstone, dan event sync.
RulesModul WAF, custom rule, dan per-path rate limit.
Event LogRiwayat peristiwa keamanan.
SettingsKonfigurasi engine & webhook alert.

Referensi API

GET  /api/stats            ringkasan lengkap (SSE: /api/stats/stream)
GET  /api/blocklist        daftar IP diblokir (dengan geo)
GET  /api/whitelist        daftar IP tepercaya
GET  /api/whitelist/detailed   whitelist + lokasi
GET  /api/rules            custom WAF rules + per-path rules
GET  /api/config           konfigurasi engine
GET  /api/cluster          status cluster
POST /api/block | /unblock /api/whitelist /api/unwhitelist
POST /api/mode | /api/emergency
POST /api/rules            action: add-custom | remove-custom | clear-custom | add-path | remove-path
POST /api/alerts/test      kirim alert uji
POST /api/reset            reset counter rate limiter

Dashboard

Real-time control center for the whole engine β€” available on port 3000 behind HTTP Basic auth.

Pages

PagePurpose
OverviewSecurity posture, mode and attack summary.
AnalyticsThreat timeline and traffic verdicts.
TrafficThroughput, request sources and mitigation.
Geo MapVisitor & attacker country distribution.
BlocklistManage blocked IPs.
WhitelistManage trusted IPs (with location info).
ChallengeInterstitial status & failed-challenge IPs.
ClusterNode, peer, tombstone and sync event status.
RulesWAF modules, custom rules and per-path rate limits.
Event LogSecurity event history.
SettingsEngine configuration & webhook alerts.

API Reference

GET  /api/stats            full summary (SSE: /api/stats/stream)
GET  /api/blocklist        blocked IPs (with geo)
GET  /api/whitelist        trusted IPs
GET  /api/whitelist/detailed   whitelist + location
GET  /api/rules            custom WAF rules + per-path rules
GET  /api/config           engine configuration
GET  /api/cluster          cluster status
POST /api/block | /unblock /api/whitelist /api/unwhitelist
POST /api/mode | /api/emergency
POST /api/rules            action: add-custom | remove-custom | clear-custom | add-path | remove-path
POST /api/alerts/test      send a test alert
POST /api/reset            reset rate limiter counters

Webhook Alert (Telegram & Discord)

Notifikasi otomatis ke chat pribadi/group Anda saat terjadi peristiwa penting.

Peristiwa yang memicu alert

  • Attack detected / subsided β€” serangan mulai / berakhir.
  • Emergency mode ON/OFF β€” mode darurat.
  • Aggressive mode ON β€” mode agresif diaktifkan.
  • Flood mode ON β€” flood HTTP terdeteksi.
  • Critical log β€” pesan log level critical.

Konfigurasi

{
  "alerts": {
    "enabled": true,
    "minSeverity": "warning",
    "cooldown": 60000,
    "discord": "https://discord.com/api/webhooks/...",
    "telegram": { "botToken": "123456:ABC...", "chatId": "-1001234567890" }
  }
}
KunciDeskripsi
enabledAktif/nonaktifkan seluruh alert.
minSeverityLevel minimum: info | warning | critical.
cooldownJarak minimum antar alert identik (ms).
discordWebhook URL Discord (embed alert).
telegramBot token + chat ID Telegram.
Tip: Konfigurasi ini juga bisa diatur dari halaman Settings β†’ Webhooks & Alerts di dashboard, lengkap dengan tombol Send Test.

Webhook Alerts (Telegram & Discord)

Automatic notifications to your private chats/groups on important events.

Events that trigger alerts

  • Attack detected / subsided β€” attack started / ended.
  • Emergency mode ON/OFF β€” emergency mode.
  • Aggressive mode ON β€” aggressive mode enabled.
  • Flood mode ON β€” HTTP flood detected.
  • Critical log β€” critical-level log messages.

Configuration

{
  "alerts": {
    "enabled": true,
    "minSeverity": "warning",
    "cooldown": 60000,
    "discord": "https://discord.com/api/webhooks/...",
    "telegram": { "botToken": "123456:ABC...", "chatId": "-1001234567890" }
  }
}
KeyDescription
enabledEnable/disable all alerts.
minSeverityMinimum level: info | warning | critical.
cooldownMinimum gap between identical alerts (ms).
discordDiscord webhook URL (embed alert).
telegramTelegram bot token + chat ID.
Tip: This can also be managed from the dashboard Settings β†’ Webhooks & Alerts page, including a Send Test button.

Geo & Monitoring

Lihat dari mana pengunjung dan penyerang Anda berasal.

Data geolokasi

Setiap IP yang terpantau dilengkapi negara, kota, dan koordinat (via database GeoLite). Data dihitung otomatis dari request yang masuk β€” tanpa basis data eksternal tambahan.

Yang bisa Anda lihat

  • Geo Map β€” distribusi negara sumber request dengan bar visual.
  • Top Sources β€” IP teraktif beserta negara & kotanya.
  • Blocklist & Whitelist β€” setiap entri diperkaya lokasi.
  • Challenge failures β€” negara asal IP yang gagal verifikasi.

Geo & Monitoring

See where your visitors and attackers come from.

Geolocation data

Every monitored IP is enriched with country, city and coordinates (via the GeoLite database). Computed automatically from incoming requests β€” no extra external database required.

What you can see

  • Geo Map β€” country distribution of request sources with visual bars.
  • Top Sources β€” most active IPs with country & city.
  • Blocklist & Whitelist β€” every entry enriched with location.
  • Challenge failures β€” countries of IPs that failed verification.

Proteksi Layer 4

Menangkal serangan volumetrik dan protokol di level jaringan & transport.

Vektor serangan yang ditangani

  • SYN Flood β€” proteksi setengah-open connection per IP.
  • UDP Flood β€” analisis paket dan pembatasan laju per IP.
  • ACK / RST Flood β€” validasi state koneksi TCP.
  • Amplification β€” DNS, NTP, SSDP, dan refleksi lain.
  • ICMP Flood β€” pembatasan paket ICMP.

Pengaturan bawaan

ParameterNilai default
Max half-open connection per IP10
Max koneksi per detik per IP50
Max koneksi aktif per IP100
Bogon filteraktif
Deteksi port scanaktif
UDP amplification protectionaktif

Layer 4 Protection

Stops volumetric and protocol attacks at the network & transport layer.

Attack vectors handled

  • SYN Flood β€” half-open connection protection per IP.
  • UDP Flood β€” packet analysis and per-IP rate limiting.
  • ACK / RST Flood β€” TCP connection state validation.
  • Amplification β€” DNS, NTP, SSDP and other reflections.
  • ICMP Flood β€” ICMP packet rate limiting.

Defaults

ParameterDefault
Max half-open connections per IP10
Max connections per second per IP50
Max active connections per IP100
Bogon filterenabled
Port scan detectionenabled
UDP amplification protectionenabled

Layer 7 & WAF

Melindungi aplikasi dari serangan yang meniru trafik manusia.

Proteksi Layer 7

  • HTTP / HTTPS Flood β€” deteksi perilaku request abnormal.
  • Slowloris, Slow POST/Read β€” batasi koneksi idle dan lambat.
  • Brute-force login β€” rate limiting per path dan per IP.
  • Web scraping β€” deteksi headless browser dan pola otomatisasi.

Aturan WAF bawaan

ModulKeterangan
SQL InjectionDeteksi pola injeksi pada parameter.
XSSBlokir skrip berbahaya pada input.
Path TraversalCegah akses ke path di luar direktori.
Command InjectionBlokir eksekusi perintah via input.
LFI / RFICegah include file lokal & remote.
Shellshock & scannerBlokir eksploitasi dan probing otomatis.

Custom WAF Rules

Tambahkan aturan regex Anda sendiri yang diterapkan ke path, query, body, header, dan cookie. Skor β‰₯ 50 akan memblokir request.

{
  "defense": {
    "waf": {
      "customRules": [
        { "name": "block-bad-bot", "pattern": "/badbot/i", "score": 60, "type": "custom" }
      ]
    }
  }
}

Per-Path Rate Limit

Atur ambang RPS spesifik per path, misalnya membatasi endpoint login. Gunakan * untuk prefix.

{
  "defense": {
    "rateLimit": {
      "perPathRPS": 1000,
      "pathRules": [
        { "path": "/api/login", "rps": 20 },
        { "path": "/api/*", "rps": 200 }
      ]
    }
  }
}

Layer 7 & WAF

Protects your app from attacks that mimic human traffic.

Layer 7 protection

  • HTTP / HTTPS Flood β€” abnormal request behavior detection.
  • Slowloris, Slow POST/Read β€” idle and slow connection limits.
  • Login brute-force β€” per-path and per-IP rate limiting.
  • Web scraping β€” headless browser and automation detection.

Built-in WAF rules

ModuleDescription
SQL InjectionInjection pattern detection on parameters.
XSSBlocks malicious scripts on input.
Path TraversalPrevents access outside allowed directories.
Command InjectionBlocks command execution via input.
LFI / RFIPrevents local & remote file inclusion.
Shellshock & scannersBlocks exploits and automated probing.

Custom WAF Rules

Add your own regex rules applied to path, query, body, headers and cookies. Score β‰₯ 50 blocks the request.

{
  "defense": {
    "waf": {
      "customRules": [
        { "name": "block-bad-bot", "pattern": "/badbot/i", "score": 60, "type": "custom" }
      ]
    }
  }
}

Per-Path Rate Limit

Set a specific RPS ceiling per path, e.g. to throttle a login endpoint. Use * for prefix matching.

{
  "defense": {
    "rateLimit": {
      "perPathRPS": 1000,
      "pathRules": [
        { "path": "/api/login", "rps": 20 },
        { "path": "/api/*", "rps": 200 }
      ]
    }
  }
}

Layanan API Custom

Selain proteksi DDoS, GarudaShield membangun API sesuai kebutuhan bisnis Anda. Konsultasi dan order langsung via WhatsApp.

Yang bisa kami bangun

REST API & Backend

Backend siap produksi dengan dokumentasi lengkap.

Payment & E-wallet

Integrasi payment gateway, e-wallet, virtual account.

Bot & Automation

WhatsApp/Telegram bot, auto-reply, scraper.

Integrasi Pihak Ketiga

SMS, AI, OCR, pelacakan paket, dan lainnya.

Alur order

  1. Hubungi WhatsApp +62 831-8781-5456 dan jelaskan kebutuhan Anda.
  2. Diskusikan spesifikasi, estimasi biaya, dan timeline.
  3. Kami kerjakan, uji, lalu serahkan dengan dokumentasi.

Custom API Service

Beyond DDoS protection, GarudaShield builds APIs to fit your business. Consultation and orders via WhatsApp.

What we can build

REST API & Backend

Production-ready backends with full documentation.

Payment & E-wallet

Payment gateway, e-wallet, virtual account integration.

Bot & Automation

WhatsApp/Telegram bots, auto-reply, scrapers.

Third-party Integration

SMS, AI, OCR, shipment tracking and more.

Order flow

  1. Contact us on WhatsApp +62 831-8781-5456 and describe your needs.
  2. Discuss specifications, cost estimate and timeline.
  3. We build, test and deliver with documentation.

Paket & Harga

Tanpa kontrak panjang, tanpa biaya setup. Batalkan kapan saja.

FiturStartupBusinessEnterprise
HargaRp350k/blnRp1.250k/blnCustom
Kapasitas mitigasi20 Gbps100 GbpsTanpa batas
Domain terproteksi13Tak terbatas
WAF Layer 7β€”βœ“βœ“
Verify Browserβ€”βœ“βœ“
Cluster multi-nodeβ€”βœ“βœ“
Load balancing & failoverβ€”βœ“βœ“
Notifikasi real-timeE-mailTelegramTelegram + TAM
SLA tertulisβ€”β€”99.99%

Semua paket termasuk SSL otomatis (Let's Encrypt) dan dashboard monitoring. Hubungi kami untuk trial 7 hari.

Plans & Pricing

No long contracts, no setup fees. Cancel anytime.

FeatureStartupBusinessEnterprise
PriceRp350k/moRp1.250k/moCustom
Mitigation capacity20 Gbps100 GbpsUnlimited
Protected domains13Unlimited
Layer 7 WAFβ€”βœ“βœ“
Verify Browserβ€”βœ“βœ“
Multi-node clusterβ€”βœ“βœ“
Load balancing & failoverβ€”βœ“βœ“
Real-time notificationsE-mailTelegramTelegram + TAM
Written SLAβ€”β€”99.99%

All plans include automatic SSL (Let's Encrypt) and a monitoring dashboard. Contact us for a 7-day trial.

Changelog & Versi

Catatan perubahan mesin GarudaShield.

v2.2.0 2026
  • Webhook Alert β€” notifikasi Telegram & Discord (attack, emergency, aggressive, flood) dengan severity + cooldown.
  • Geo Monitoring β€” distribusi negara, geo pada blocklist/whitelist, dan IP gagal challenge.
  • Custom WAF Rules β€” kelola aturan regex dari dashboard / API.
  • Per-Path Rate Limit β€” ambang RPS spesifik per path (prefix *).
  • Dashboard baru β€” halaman Geo Map, Cluster, Challenge, Whitelist; Rules & Settings diperbarui.
  • Dokumentasi β€” desain baru, versi bahasa Inggris, changelog.
v2.1.0 2026
  • Verify Browser β€” interstitial "Just a moment" dengan cookie gs_ok per host.
  • Headless detection & challenge flow diperkuat di lapisan L7.
v2.0.0 2026
  • Cluster Sync β€” sinkronisasi blocklist antar-node dengan shared secret & tombstone.
  • Mesin WAF, rate limiter, dan analyzer ditulis ulang dengan performa tinggi.

Changelog & Version

GarudaShield engine change log.

v2.2.0 2026
  • Webhook Alerts β€” Telegram & Discord notifications (attack, emergency, aggressive, flood) with severity + cooldown.
  • Geo Monitoring β€” country distribution, geo on blocklist/whitelist, and failed-challenge IPs.
  • Custom WAF Rules β€” manage regex rules from the dashboard / API.
  • Per-Path Rate Limit β€” path-specific RPS ceilings (* prefix).
  • New dashboard β€” Geo Map, Cluster, Challenge, Whitelist pages; Rules & Settings updated.
  • Documentation β€” new design, English version, changelog.
v2.1.0 2026
  • Verify Browser β€” "Just a moment" interstitial with per-host gs_ok cookie.
  • Strengthened headless detection & challenge flow on the L7 layer.
v2.0.0 2026
  • Cluster Sync β€” cross-node blocklist sync with shared secret & tombstones.
  • Rewritten high-performance WAF, rate limiter and analyzer.

FAQ

Apa itu serangan DDoS?

Distributed Denial of Service adalah serangan yang membanjiri server dengan trafik palsu hingga layanan tidak dapat diakses pengguna asli. Serangan terjadi di layer jaringan (L3/4) atau layer aplikasi (L7).

Seberapa cepat serangan dideteksi?

Ambang deteksi di bawah 3 detik. Mesin mitigasi langsung aktif di edge tanpa intervensi manusia.

Apakah GarudaShield memperlambat website?

Tidak β€” umumnya lebih cepat, karena trafik diarahkan ke PoP terdekat melalui jaringan anycast. Optimalisasi SSL dan HTTP/3 aktif secara default.

Apakah IP origin saya terlihat?

Tidak. Hanya IP anycast GarudaShield yang tampil di DNS publik. Alamat IP origin dienkripsi dan tidak pernah diekspos.

Apa itu Verify Browser dan apakah pengunjung terganggu?

Verify Browser adalah interstitial ringan untuk pengunjung pertama. Manusia lolos otomatis dalam < 2 detik tanpa interaksi. Setelah cookie gs_ok terpasang, kunjungan berikutnya langsung masuk.

Bagaimana cara memesan?

Hubungi WhatsApp +62 831-8781-5456. Tim kami membantu pilih paket, proses trial 7 hari, dan pandu setup hingga selesai.

FAQ

What is a DDoS attack?

A Distributed Denial of Service attack floods a server with fake traffic until real users can no longer reach the service. Attacks happen at the network layer (L3/4) or the application layer (L7).

How fast are attacks detected?

Detection threshold is under 3 seconds. The mitigation engine activates at the edge automatically with no human intervention.

Does GarudaShield slow my website down?

No β€” usually it is faster, because traffic is routed to the nearest PoP via the anycast network. SSL and HTTP/3 optimization are on by default.

Is my origin IP visible?

No. Only the GarudaShield anycast IP appears in public DNS. The origin IP address is encrypted and never exposed.

What is Verify Browser and do visitors get bothered?

Verify Browser is a lightweight interstitial for first-time visitors. Humans pass automatically in under 2 seconds with no interaction. Once the gs_ok cookie is set, subsequent visits go straight through.

How do I order?

Contact us on WhatsApp +62 831-8781-5456. Our team helps you pick a plan, runs the 7-day trial, and guides you through setup.