Name server DDoS Protection
Name Server (NS) Protection is an always-on service that automatically mitigates DDoS attacks targeting DNS servers.
NS Protection complements other Incapsula DDoS mitigation services to ensure that your application and network infrastructure are protected against denial of service assaults.GET QUOTE
How It Works
Incapsula deploys in front of your DNS server, becoming the first destination for all DNS queries. Acting as a secure proxy, Incapsula then prevents illegal DNS queries from reaching your server while masking it from direct-to-IP network layer attacks.
From Incapsula dashboard you can whitelist specific queries, which always speed through. For additional peace of mind you can also set a threshold for the amount of queries your server receives per second.
Finally, with NS Protection in place you will still be able to manage your DNS zone files outside of Incapsula network.
NS Protection uses a combination of reputation and rate-based heuristics to inspect incoming queries and filter out malicious packets without impacting legitimate visitors.
Improved DNS Performance
Legitimate queries are cached for a set period of time. During that time, all subsequent queries are resolved directly from a nearest location on Incapsula network. This accelerates performance and lessens the load on your own DNS server.
NS protection works in synch with our Infrastructure Protection and Website Protection services. Together they shield Incapsula customers against all DDoS threats.