> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/network-ddos-legacy/faq/general-questions.md).

# General Questions

## **How to enable** Network **DDoS protection?**

1. Make sure your network(s) are in the [protected prefix list](/product-guides/network-ddos-v3/interface/bgp-sessions.md#protected-prefix)&#x20;
2. Announce the network(s) in BGP to Link11&#x20;

***

## **Does Link11 have standard settings for UDP in** Network **DDoS?**

Link11 has standard settings for UDP in Network DDoS Protection. Our system is equipped with standard algorithms used in Attack mode.

***

## **Can customers send the routing announcement to Link11 and to other customers (peering partners) at the same time?**

Yes, customers can send routing announcements to Link11 as well as to other customers (peering partners) at the same time. This is a common practice in networking, and can provide additional redundancy and stability to your network.

Please avoid doing this during a DDoS attack.

***

## **How can you disable or enable Attack mode for a prefix manually?**

To disable or enable [Attack Mode](/product-guides/network-ddos-v3/introduction.md#three-modes-of-security-posture) for a prefix manually, you will need to open a support ticket with Link11. Our support team will assist you in making these changes to your network configuration.

***

## **What can you do if you need more than the amount of traffic mitigated during attack mitigation?**

If the amount of traffic being mitigated during an attack is not sufficient, it is recommended to open a support ticket with Link11. Our support team will be able to review the situation and determine if any further actions can be taken to increase the amount of traffic being mitigated.

***

## **Should I set up a suitable route object for the announcements towards Link11 to work properly?**

Yes.

***

## **What are the risks if the route object is missing?**

If the route object is missing, it can increase the risk of IP prefix hijacking, where an attacker can announce a false route for a specific IP address range and redirect traffic to their own network, and/or our upstream providers may not accept it.

***

## **Are there any limitations on the origin AS for the route to be announced by Link11?**&#x20;

A public ASN is required.

***

## **What is the smallest prefix which can be announced to Link11?**

You can only announce /24 prefixes. Smaller prefixes are not accepted on the internet - therefore, an announcement won't work. More on this [here](/product-guides/network-ddos-v3/faq/routing-ranges-smaller-than-24.md).

***

## **How long does it take for a new route object to be taken into consideration by the internet?**

Usually, up to 48 hours.

***

## **Where can I set up route objects?**

Route objects need to be set up with the appropriate authoritative RIR, like RIPE or ARIN.

***

## **Does Link11 offer Active IP Verification?**

Mitigation at Link11 works by modeling "legitimate" traffic. By building a baseline of "good" traffic, aka\
traffic that falls within the parameters that Link11 defines as normal and at a level that is not interrupting the operation of the customer infrastructure, Link11 can then profile traffic that is outside this norm.&#x20;

IP addresses that perform actions or display behaviors that seem malicious are added to a suspicious IP list. If an individual IP generates enough "suspicion" it will be blocked, and if a DDoS attack is detected, all the IPs on the suspicious IP list will be blocked.

***

## **Does Link11 offer Anti-Spoofing options?**

Link11 does not explicitly prevent IP spoofing. A DDoS attack would be mitigated regardless of whether the source IPs are legitimate or spoofed. If there are ranges of source IPs that should never be blocked during a DDoS attack, these can be whitelisted within our application.

***

## **Can Traffic be Null Routed?**

Null routing is possible but should be a last resort. In almost every case, DDoS mitigation can be offered instead of null routing traffic

***

## **Does Link11 offer Connection Aging?**

Link11 does not actively age out connections. Connection age is used as part of the DDoS mitigation algorithms, but no option is offered for proactive connection aging.

***

## **Why do I experience Latency Issues and Packet Losses with Link11 Services?**

If customers decide to do asynchronous routing and do not use Link11 as an upstream provider, these issues can occur. Otherwise this should not happen.
