> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/network-ddos-v3/faq/general-questions.md).

# General Questions

#### How do I start being protected?

1. Ensure your network prefixes are in the protected prefix list configured by Link11.
2. Announce your network(s) in BGP to Link11.

Contact Link11 Support at <support@link11.com> if you need to change your protected prefixes.

#### How does mitigation work?

Network DDoS continuously builds and maintains a baseline of normal traffic behaviour for each protected prefix and for active destination IPs. Deviations from this baseline generate **signals** — individual traffic anomalies such as a spike in unique source IPs, an elevated SYN ratio, or unusual UDP concentrations.

A single signal does not trigger mitigation. When multiple correlated signals align to indicate a specific attack type, the system produces a **high quality signal** and activates only the mitigation strategies relevant to that attack vector. Mitigation uses an escalation ladder, starting with the most targeted intervention and escalating only if the current level proves insufficient. The system also automatically de-escalates as the attack subsides.

Known legitimate sources — automatically identified from the traffic baseline — are never blocked, even during an active attack.

For a full technical description, see [How Detection and Mitigation Work](https://app.gitbook.com/o/-LuRgnkbMDIP90l_Osrd/s/9MtEFVuk9jM1JPR68VKk/~/edit/~/changes/5/product-guides/network-ddos-v3/faq/how-detection-and-mitigation-work).

#### How quickly does mitigation activate?

Under 3 seconds from the point a high quality signal is confirmed.

#### What is an Attack ID and how do I reference it in a support ticket?

When mitigation activates, an Attack ID is assigned to the event (e.g., `ATK-2026-0043`). This ID links all related events, the Attack Report, and Explorer entries for that attack. Include the Attack ID when raising a support ticket about a specific attack.

Attack IDs are visible in the Attack Events list, in each Attack Report header, and throughout the Explorer.

#### Does Link11 support IPv6?

Yes. IPv4 and IPv6 traffic are handled with equal effectiveness throughout detection, baselining, and mitigation. Dual-stack and IPv6-only customer infrastructure is fully protected.

#### Can I prevent specific sources from triggering mitigation?

Yes, using Access Control rules:

* **Whitelist** — guarantees a source is never blocked under any circumstances, including during active mitigations.
* **Greylist** — excludes a source from signal tracking, so its traffic cannot contribute to high quality signals or trigger mitigation activation. Note that greylisted sources may still be blocked if other traffic activates a mitigation and their packets match its criteria.
* **Blacklist** — always denies traffic from a source, regardless of current system state.

Rules are self-service and take effect immediately.

#### Can I send routing announcements to Link11 and other providers simultaneously?

Yes. This is standard practice and can provide additional redundancy. Avoid making routing changes during an active attack.

#### What if the amount of traffic being mitigated during an attack is not sufficient?

Contact Link11 Support at <support@link11.com>. Our support team will review the situation and determine what further action can be taken.

#### Is null routing possible?

Null routing is possible but should be a last resort. In almost every case, DDoS mitigation is preferable to null routing traffic.

#### Does Link11 age out connections?

Link11 does not actively age out connections. Connection age is used as part of the mitigation algorithms, but no option is offered for proactive connection aging.
