Your origin infrastructure is exposed when delivering TCP/UDP services such as: custom gaming protocols, remote server access (SSH), secure file transfer services (SFTP), and email (SMTP).
Attackers can directly send volumetric DDoS traffic to those services, degrading performance. Attackers can also snoop unencrypted traffic on those ports to steal confidential data or credentials.
Spectrum extends the power of Cloudflare to protect not just your web traffic, but your other TCP/UDP ports and protocols from layer 3 and 4 DDoS. Further, by enabling TLS encryption for TCP services, Spectrum reduces the ability for attackers to snoop and steal sensitive data.
Bad IP addresses can be blocked through integration with Cloudflare’s IP Firewall. Now you can protect your origin and all TCP/UDP services you expose to the Internet.
When you run Internet-facing services, such as email, remote access to servers, custom gaming protocols, or secure file transfer, you've exposed your origin infrastructure to direct DDoS through those open ports.
Cloudflare’s Spectrum ensures all your TCP/UDP services are protected against Layer 3 and 4 DDoS attacks, remaining online and performant.
If your non-web TCP services include unencrypted sensitive information, your sensitive data is vulnerable to snooping.
Spectrum encrypts services running on TCP to prevent unencrypted data, such as user credentials, from falling into the wrong hands.
Spectrum integrates with Cloudflare’s IP Firewall, allowing you to block or challenge IP addresses or entire IP ranges from reaching your TCP/UDP services.
Spectrum gives control and flexibility with easy configuration on a per-application basis within the Cloudflare dashboard or API.
Configuration options for Spectrum include:
Domain or Subdomain
Origin IP / Port for Service
Edge Port Specification
IP Firewall (I/O)
PROXY Protocol (I/O)
Proxy any TCP/UDP traffic through Cloudflare
Whitelist or blacklist IP addresses
Real-time application-specific analytics
Allow TLS passthrough traffic
Easy setup through dashboard UI or API
Load balance layer 4 traffic across multiple origins
Supports multiple ports on the same hostname or application
Supports log share to public cloud storage buckets
To start using Spectrum, you'll need to be subscribed to a Cloudflare Enterprise plan. By enabling Spectrum, you’ll receive encryption and unmetered mitigation of volumetric DDoS attacks for non-web TCP protocols and ports.