> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/web-ddos/faq/site-shield.md).

# Site Shield

### What is a Site Shield? <a href="#id-webddos-siteshield-whatisasiteshield" id="id-webddos-siteshield-whatisasiteshield"></a>

A site shield is a protective mechanism that Web DDoS customers should implement to safeguard their Origin IP Address. This defense ensures that attackers cannot discover the IP, either manually or using tools like malicious bots and search engines.

<figure><img src="/files/ShEnfSjVbtKqzVxCeKjU" alt=""><figcaption></figcaption></figure>

### How Does it Work? <a href="#id-webddos-siteshield-howdoesitwork" id="id-webddos-siteshield-howdoesitwork"></a>

Link11's Site Shield operates on the idea that only approved Link11 Source IPs can access the original public IPs of a customer's application servers. Link11 keeps a list of these approved IPs, enabling customers to specifically whitelist these Site Shield IPs and deny all other traffic on their application servers. Consequently, neither regular clients nor potential attackers can directly engage with the customer's servers. All traffic is channeled through Link11's cloud service, where it's scrutinized, potential threats are identified, and any malicious activities are blocked

{% hint style="info" %}
***This is more than a simple firewall rule!***
{% endhint %}

{% hint style="danger" %}
Site Shield is **NOT** a ‘nice-to-have’ but very **important** to set up!
{% endhint %}

### How to use it? <a href="#id-webddos-siteshield-howtouseit" id="id-webddos-siteshield-howtouseit"></a>

Customers can choose to implement the provided whitelists on their perimeter devices, such as routers and firewalls, or they can delegate this task to their Internet Service Providers (ISPs) to implement it before it reaches their own infrastructure. It's also feasible to employ a hybrid approach, leveraging both methods, as illustrated here:

<figure><img src="/files/Su9amEDfaShYU8swlTAL" alt=""><figcaption></figcaption></figure>

### If a customer doesn't set up Site Shield Protection properly, the following potential risks and issues could arise: <a href="#id-webddos-siteshield-ifacustomerdoesntsetupsiteshieldprotectionproperly-thefollowingpotentialrisksa" id="id-webddos-siteshield-ifacustomerdoesntsetupsiteshieldprotectionproperly-thefollowingpotentialrisksa"></a>

* **Direct Access to Origin:** Even though the customer switches to Link11 and gets a new IP for the proxy, the old Origin IP (of) is still known. If the Site Shield Protection isn't activated, attackers or any visitor familiar with the original IP can bypass the Link11 proxy and access the origin server directly.
* **Vulnerability to DDoS Attacks:** Without Site Shield Protection, the original server remains exposed. Attackers could target the old Origin IP with DDoS attacks, causing downtime and potential data breaches.
* **No Filtering of Malicious Traffic:** Since traffic isn't being exclusively routed through Link11's cloud service, there's no mechanism in place to analyze, detect, and block potential threats. This exposes the customer's infrastructure to a variety of cyber threats, including malware and bot attacks.
* **Loss of Performance Optimization:** Link11 not only provides security but also performance optimization. Direct access to the origin means that users might not benefit from any performance enhancements offered by the proxy service.

In essence, by not activating Site Shield Protection, the customer could be forfeiting many of the security and performance benefits of using Link11, leaving their system vulnerable to direct threats.

```
### Link11 ddosproxy net (FFM, LON, ZRH, SGP)
31.214.214.0/24
31.214.215.0/24
80.95.144.0/20
85.131.128.0/18
85.131.137.0/24
128.65.208.0/20
185.169.192.0/22
```
