Skip to content
+1 (813) 212-3723 support@layeronecloud.com
LayerOne Aegis / Network Security

Know your traffic.
Strengthen your defenses.

Your server talks to the world. Understand the conversation. LayerOne Aegis brings traffic visibility, exposed services, and attack activity together so you can make informed decisions about your VPS security.

Understand your network

More context.
Fewer blind spots.

Go from a traffic spike to a better understanding of what changed. Review your account as a whole, or focus on one server and its assigned public IPs.

Live traffic visibility

Follow inbound and outbound bandwidth and total packet rates. Look back over recent history to understand bursts, quiet periods, and changing demand.

Application insights

See identified applications and services with their observed inbound and outbound usage. Understand which traffic belongs to the workloads you expect to run.

Open-port checks

Review observed open TCP and UDP ports on your public IPs, with service and version details where identified. Spot an exposed service that deserves a closer look.

Spot suspicious activity

Review outbound patterns and application usage for unexpected uploads or unfamiliar activity. Aegis gives you the visibility to investigate potential intrusions; you decide what needs attention.

DDoS activity and alerts

Review observed DDoS incidents, severity, and attack history. Choose in-app notifications or opt into email alerts, including updates when an attack ends.

Firewall control

Set inbound and outbound rules at the hypervisor. Allow the services you need and restrict unnecessary connectivity outside the guest operating system.

Observations depend on sensor coverage and scan availability. Aegis shows gaps and stale results so you can judge the evidence; an open-port check is not a vulnerability assessment.

Defense in layers

See the signals.
Control your defenses.

Good security starts with visibility and follows through with control. Aegis helps you investigate network activity, while LayerOne's DDoS mitigation and your firewall policy provide layers of protection.

01 / Observe

Notice the unexpected

Use traffic patterns, identified applications, and exposed services to look for signs of suspicious activity. This is visibility for your own investigation, with no automatic intrusion alerts or blocking.

02 / Protect

Keep network attacks upstream

Always-on L3/L4 DDoS mitigation is included with LayerOne VPS hosting, helping absorb and filter network floods before they reach your server.

03 / Control

Reduce unnecessary exposure

Review exposed services and adjust your inbound and outbound firewall rules. Close what you do not use and limit access to what you do.

Aegis, explained

Know what protects you.

How does Aegis support intrusion detection?

Aegis supports manual intrusion detection through passive network visibility. You can review inbound and outbound traffic, application usage, and exposed services to spot activity that looks suspicious and investigate it. It does not automatically raise intrusion alerts or block suspected intrusions, and it is not an intrusion prevention system (IPS). DDoS notifications and upstream L3/L4 mitigation are separate protections; firewall changes remain under your control.

Can I check open ports and applications?

Yes. Aegis shows observed open TCP and UDP ports and service details when identified by a probe. Its application view shows identified traffic and usage. These views help you review exposure and activity; they do not inventory every installed package or certify that an application is free of vulnerabilities.

Does it monitor outbound connectivity?

Aegis shows observed outbound bandwidth and application usage so you can investigate unexpected changes. You can review one server or your account's eligible public IPs. Application visibility is based on observed network traffic, with names and byte counts rather than a raw connection log.

Does DDoS protection replace application security?

LayerOne's included mitigation protects against network-layer L3/L4 attacks. Keep your OS and applications patched, secure your credentials, and configure your firewall. Add application-layer protection such as a WAF where your workload needs it.

How do I participate in the vulnerability tracker?

Allow LayerOne's scanner IP through the firewalls protecting your instance so it can reach the services you want assessed. After deploying an instance, check Aegis for the scanner IP information. If it is not visible or you are unsure which address to allow, open a support ticket and we will provide it. The Aegis guide explains port scanning, vulnerability assessment, and how to interpret results.

Can I disable LayerOne Aegis?

If you prefer to opt out of LayerOne Aegis you can disable now.

Where do I find LayerOne Aegis?

After deploying an instance, sign in to your client area and open Aegis in the main navigation. Review your servers' available observations, open Applications & ports for scan results, and manage your settings and alert preferences there.

Secured by LayerOne Aegis

Your next VPS.
A clearer security picture.

Build on LayerOne with included DDoS protection, network visibility, and firewall controls you can manage from your client area.