> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/using-link11/how-do-i.../reject-traffic-from-sources-attempting-to-bypass-link11.md).

# Reject traffic from sources attempting to bypass Link11

For Web DDoS customers, Link11 provides a new public IP address for their origin(s). However, if someone knows (or looks up) the customer's old IP addresses, they could send requests directly to the origins, and bypass Link11's filtering.

Rejecting this non-inspected traffic is an important part of using Link11. This is done by creating a [Site Shield](/product-guides/web-ddos/faq/site-shield.md).&#x20;

Note: For Network DDoS, Link11 advertises a route to the IPs themselves. Thus, when Network DDoS is used in ["Always On" mode](/product-guides/network-ddos-v3/architecture-and-setup-options.md#the-recommended-option-always-on-setup), there’s no way to bypass Link11.&#x20;
