> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/web-ddos/interface/instances/ddos-mitigation.md).

# DDoS Mitigation

This section defines DDoS mitigation behavior for the selected instance.

***

## **IP Blocking Algorithm**

Enables admins to choose when malicious IPs will be blocked.

<figure><img src="/files/byOpQ9bN7UJdjkLQl4xk" alt=""><figcaption></figcaption></figure>

| Option                 | Explanation                                                                                                                                                                                   |
| ---------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Block Always           | Block mode is permanently enabled. This will always block suspicious/malicious IPs independently of [Attack Mode](/product-guides/web-ddos/introduction.md#three-modes-for-security-posture). |
| Block Only Underattack | Blocks suspicious IPs automatically if an attack is detected.                                                                                                                                 |
| Disable                | Never blocks any IPs.                                                                                                                                                                         |

***

## **GEO-IP Blocking Algorithm**

Enables admins to choose how IPs within specific countries may be handled by the proxy. The countries in question must be specified in the [Geo Blocking](/product-guides/web-ddos/interface/geo-blocking.md) settings.

<figure><img src="/files/4P6V1ub1heJmVoiJoG1H" alt=""><figcaption></figcaption></figure>

| Option                   | Explanation                                                     |
| ------------------------ | --------------------------------------------------------------- |
| Block only Underattack   | Will only block Geo-IPs if Attack Mode is triggered.            |
| Block Always             | Will always block Geo IPs                                       |
| CAPTCHA only Underattack | Will only show CAPTCHA’s to Geo IPs if Attack Mode is triggered |
| CAPTCHA Always           | Will always show CAPTCHA’s to Geo IPs                           |
| Disabled                 | Will disable handling of Geo IPs                                |

***

## **ASN Blocking Algorithm**

Enables admins to choose how specifics ASNs may be handled by the proxy. The ASNs in question must be specified in the [ASN Blocking](/product-guides/web-ddos/interface/asn-blocking.md) settings.

<figure><img src="/files/K6XccbZb80ZKWfJ6fBJs" alt=""><figcaption></figcaption></figure>

| Option                 | Explanation                                         |
| ---------------------- | --------------------------------------------------- |
| Block only Underattack | Will only block an ASN if Attack Mode is triggered. |
| Block Always           | Will always block ASN                               |
| Disabled               | Will disable handling of ASNs                       |

***

## **Max POST Size during Attacks**

Limits the maximum HTTP POST Size during Attack Mode to the determined amount. This will save bandwidth, and limit the amount of data possible attackers may send.

<figure><img src="/files/GlUOIMobSfCprBljou4g" alt=""><figcaption></figcaption></figure>

***

## **CAPTCHA Defense**

If an IP is marked as suspicious (i.e., there are unusual traffic patterns), the client will receive a CAPTCHA challenge. This leads to less false positives, since legitimate website users can proceed to the website after solving the CAPTCHA.

{% hint style="info" %}
This feature only applies captchas to suspicious IPs. There are additional ways to use captchas within Web DDoS:

* To display captchas to traffic sources identified to be bad bots, set the [Default Policy for Bad Bots](/product-guides/web-ddos/interface/instances/general-settings.md#default-policy-for-bad-bots) to "captcha".
* To display captchas to all visitors to specific paths, add those paths to the [Captcha URL list](/product-guides/web-ddos/interface/captcha-url-list.md).
  {% endhint %}

<figure><img src="/files/pM0PwKMsWCNFsuGq3dW0" alt=""><figcaption></figcaption></figure>

***

## **CAPTCHA Template**

Admins can upload a customized captcha page that will be displayed in case of an attack (when [CAPTCHA Defense](#captcha-defense) is enabled). To save bandwidth, the smallest-possible template file is recommended.

<figure><img src="/files/xjRQnzktqEEAK6XDwi5p" alt=""><figcaption></figcaption></figure>

***

## **CAPTCHA Type**

Two CAPTCHA providers are offered by Link11: Google ReCaptcha and a GDPR Compliant provider located in Germany. The Google ReCaptcha option is provided by default, free of additional charge.&#x20;

To use the [GDPR Compliant](/product-guides/web-ddos/faq/what-is-gdpr-compliant-captcha.md) provider, please contact your sales representative about pricing and to enable this feature.

<figure><img src="/files/RbblRJsJYFiiaWNL6dHV" alt=""><figcaption></figcaption></figure>

The GDPR Compliant option comes with the benefit of a “Hands Free” captcha. This is achieved by analyzing the client's browser and actions without asking them to complete any challenges.&#x20;

Additionally, the GDPR Compliant option offers multiple language support. The client's browser language is used to determine the language for displaying the captcha “widget”. The rest of the displayed Captcha page can be customized by admins, but is in English by default.

***

## **DDoS Blocking Reasons**

Link11 WebDDoS mitigation is performed using a wide range of algorithms working together. Each of the algorithms generates a number of “Sumpoints”; DDoS mitigation is enabled when a website or application has accumulated enough points to cross a threshold. Not all algorithms are always active, and the algorithms generate different amounts of points based on the severity of the transgression.

{% hint style="info" %}
The anomalies/errors that will trigger DDoS mitigation are listed [here](/reference/web-ddos-mitigation-reasons.md).
{% endhint %}
