Quick answer: Open a support ticket (or email [email protected]) with: the target IP and service, exact start time in UTC, what stopped working, and any evidence — connection counts, log excerpts, traffic graphs. The more precise the report, the faster NOC can confirm and filter the attack.
Overview
Network-level mitigation happens on Cloud2Y's side, and it starts from your report. A vague "site is slow" takes several diagnostic round-trips; a precise report with timestamps and symptoms lets engineers correlate your service against network telemetry immediately.
Before you start
Collect what you can safely gather while affected (skip anything that costs you time under fire):
- Target IP(s) and port(s), exact start time (UTC), whether it is ongoing.
- Connection snapshot:
ss -sand top talkers (identify suspicious traffic). - Access-log sample if it looks like an HTTP flood; bandwidth graphs if you run monitoring.
Step-by-step guide
- Log in to the Client Area and open Support Tickets → Open Ticket (or email [email protected]).
- Subject: "DDoS attack on <IP> — started <time UTC>".
- Body: service ID, symptoms (link saturated / connections exhausted / HTTP flood), evidence collected above, and what you already tried.
- Stay reachable on the ticket — NOC may ask for confirmation while applying filters.
- After mitigation, consider adding the DDoS protection option permanently if you were unprotected.
Common issues
- No timestamps: "since this morning" is hard to correlate — use exact times and state your timezone or use UTC.
- Screenshots of text: paste logs as text so engineers can search them.
- Reporting only after days of attack: report early; short probing attacks often precede bigger ones.
When to contact support
Immediately, whenever availability is affected and you suspect a flood — even if you are not sure it is DDoS. For non-attack network anomalies use the network issue reporting guide instead.
Frequently asked questions
What should a DDoS report include?
The target IP and port, the exact start time in UTC, the symptoms you observe, and any evidence such as connection counts, log excerpts or bandwidth graphs from your monitoring.
How do I reach Cloud2Y during an attack?
Open a ticket from the Client Area or email [email protected] — both reach the same team. Stay reachable on the ticket, as NOC may need confirmations while applying filters.
Related articles
- What is a DDoS attack?
- Cloud2Y DDoS protection overview
- How to identify suspicious traffic
- How to report network issues to support
Need a hand? Contact Cloud2Y support →
