kire@net:~$ uptime since 1997 ddos: armed vhosts: loaded identd: on

$man ddos

This community gets flooded.

So the network is built for that. You keep the nick. The bot keeps ops. We keep the ugly traffic on our side of the fence.

DDoS filter hardware in a dark rack, green and amber status lights, fiber in front of the hosts.

IRC still attracts people who solve arguments with packets. Channel wars, drone armies, bored script kids — the reasons are old and they do not need a diagram. If your bot is the one holding +o, someone will eventually try to knock the host over.

Protection is not a footnote. It is why a shell here is different from a random VPS that is “fine until it is not.” The filter sits in front of the shell, the bouncer, and the vhost. You should not have to learn our internals to stay connected.

No invented throughput numbers. No cartoon of a hooded figure. If you need a specific capacity conversation, ask and bring real requirements.

./filter

$in front, not after

The attack is aimed at the nick, the vhost, or the listener. Scrubbing happens on the way in. Your session should not be the thing that notices first.

$./network

ipv4 + ipv6

Both families

Some nets still stare at IPv4. Some of us prefer the long addresses. You are not stuck in 2004, and you are not forced off v4 either.

redundant

More than one path

A single uplink is how you discover your ISP’s incident Twitter. We do not run a hobby rack behind one cable.

nvme

NVMe boxes

Disk that keeps up with logs, userfiles, and the compile you should have done yesterday. Not a spinning museum.