Comparison
Itnetic is a CDN77 alternative for teams who need application-layer DDoS protection and a WAF in the same edge as their caching — not a delivery network with volumetric filtering bolted on. Every feature is on every plan, including the free one, and signup is self-serve.
CDN77 is a content delivery network first. Its public material describes a video-heavy delivery business with a proprietary DPDK-based DDoS solution at the points of presence, aimed at protocol and volumetric attacks — UDP floods, NTP and DNS amplification, ICMP and SYN floods — alongside token authentication, signed URLs, IP and geo lists, hotlink protection and origin shielding. That is a strong description of delivery-side security.
What its public security page does not document, as checked on 6 August 2026, is the application layer: a managed or custom web application firewall, bot management, per-endpoint rate limiting, or a challenge for suspicious browsers. If your problem is a flood of well-formed HTTPS requests against your login page or your search endpoint, that is the layer that has to answer.
Itnetic runs caching and Layer-7 mitigation in one pipeline on one edge node, not as two products stitched together. Managed OWASP filters, custom WAF rules, IP reputation, a CAPTCHA-free challenge, rate limiting, a waiting room, per-request logs, origin load balancing and the CDN are on every plan — including the free one — and you can sign up without a sales call.
The table below compares capabilities only. It makes no claim about anyone's pricing, speed, capacity or network size — just what you can turn on, and on which plan.
Feature comparison
Availability by plan, from each vendor's public documentation. Capabilities only — no pricing or performance claims.
| Capability | Itnetic | CDN77 |
|---|---|---|
| Global CDN caching | Every plan | Core product |
| Volumetric and protocol DDoS filtering (L3/L4) | Included — upstream backbone | Documented at every point of presence |
| Layer-7 (application-layer) DDoS mitigation | Every plan, including free | Not documented on the public security page |
| Managed OWASP WAF filters | Every plan, including free | Not documented on the public security page |
| Custom WAF rules (path, header, method, country, fingerprint) | Every plan, including free | Not documented on the public security page |
| Bot management / verified-bot allowlist | Every plan | Not documented on the public security page |
| CAPTCHA-free challenge for suspicious clients | Every plan — proof-of-work, no puzzles | Not documented on the public security page |
| Per-endpoint rate limiting | Every plan | Not documented on the public security page |
| IP reputation filtering | Every plan | Not documented on the public security page |
| IP and country allow / block lists | Every plan | Documented |
| Hotlink / referer protection | Every plan — via custom WAF rules | Documented |
| Signed URLs / token authentication | Private bucket origins signed at the edge (SigV4) | Documented — secure tokens and signed URLs |
| Origin shielding | Every plan — origin only ever sees the edge | Documented |
| Waiting room / virtual queue | Every plan, including free | Not documented on the public security page |
| Per-request logs (TLS, client fingerprint, WAF verdict) | Every plan | Plan-dependent |
| Traffic & attack analytics | 24-hour, 7-day and 30-day windows on every plan | Plan-dependent |
| Automatic TLS certificates | Every plan | Documented |
| Origin load balancing with failover | Every plan — up to 8 origins | Plan-dependent |
| Public REST API | Every plan, including free | Documented |
| Free plan (no card) | Yes — Starter, every feature included | Trial by arrangement; no published free tier |
| Self-serve signup without sales contact | Every plan | Plan-dependent — enterprise-oriented onboarding |
| Video encoding / live streaming pipeline | Not offered — Itnetic is protection and caching only | Core product — live and VOD encoding |
| Operator and data controller | Czech Republic (EU) | DataCamp Limited |
Compiled from CDN77's own public product and security pages on 6 August 2026, and describing documented feature availability at that date. "Not documented on the public security page" means exactly that — it is a statement about published documentation, not an assertion that the capability does not exist; ask CDN77 directly. Product contents change — check CDN77's current pages before making a decision. CDN77 is a trademark of its respective owner; Itnetic Technologies is not affiliated with, endorsed by or sponsored by CDN77. This page makes no claim about any provider's pricing, performance, capacity or availability.
A delivery network answers the question "how do I serve this file quickly and absorb a packet flood?" A web application firewall answers "how do I stop a request that is perfectly well formed and completely malicious?" Those are different layers, and a well-cached site can still be taken down by 200 requests per second against an uncacheable search endpoint. Itnetic puts both in the same pipeline: the cache is checked, and anything that misses passes the challenge gate, WAF and rate limiter before it is allowed to touch your origin.
When caching and mitigation are separate products, each one has to guess what the other did. Running them in one pipeline means a challenged request is never cached as a real response, an interstitial never poisons a cache entry, and the cache result is recorded in the same log line as the WAF verdict and the origin timing. Origins can be a single upstream, a pool of up to eight with passive health checks and failover, or a private S3-compatible bucket signed with SigV4 at the edge.
Caching does nothing for the requests that must reach your application: checkout, login, seat selection, stock queries. When those are the bottleneck, the only honest answer is to meter admission. Itnetic includes a waiting room on every plan. You set the number of concurrent sessions your origin can carry; everyone above it gets a queue page with their position and an estimated wait, ordered identically across every point of presence, and a queue position costs a bot the same proof-of-work a challenge does.
Signup takes no sales call and no card. The Starter plan is free and runs on the same edge, the same pipeline and the same protections as every paid plan, including the WAF, the waiting room, the API and per-request logs. Plans differ by domain count, subdomain count and delivered bandwidth — and attack traffic is never metered against that quota.
This comparison is not an argument that Itnetic replaces CDN77 for everyone. If your business is video — live and VOD encoding, RTMP ingest, a delivery pipeline built around large-scale streaming — that is a product category Itnetic does not sell and is not trying to. Itnetic is for web applications, APIs and e-commerce that need the security layer and the cache to be the same system.
Migration is a DNS change: add the domain, verify it, point two records, and your nameservers and registrar stay where they are. You can move one hostname at a time — which also means you can keep a media hostname on a delivery network you are happy with while putting the application hostname behind Itnetic. What you should not do is chain two proxying edges on the same hostname: two challenge layers, doubled caching decisions, and per-IP defenses on the inner edge seeing the outer edge's addresses instead of your visitors'.
FAQ
It depends on which half of the product you are there for. If you need application-layer protection — a WAF, bot handling, rate limiting and a challenge — in the same edge as your caching, Itnetic includes all of it on every plan including the free one. If you are there for the video pipeline, live and VOD encoding and RTMP ingest, Itnetic does not offer those and you should stay with a delivery specialist.
As checked on 6 August 2026, CDN77's public security page documents DDoS filtering against protocol and volumetric attacks, token authentication and signed URLs, IP and geo lists, hotlink protection and origin shielding, but does not document a managed or custom web application firewall, bot management or rate limiting. That is a statement about their published documentation rather than about what may be available on request — ask them directly. On Itnetic, managed and custom WAF rules are on every plan including the free one.
Yes. The Itnetic Starter plan is free, needs no card, and includes one domain with 2 GB of delivered traffic per month — with the same CDN caching, Layer-7 DDoS mitigation, WAF, waiting room, per-request logs and API as every paid plan. Attack traffic is not counted against that quota.
It stops the loud half. A cache absorbs repeated requests for the same cacheable asset, and a large network absorbs packet floods. Neither helps against a moderate flood of well-formed requests aimed at endpoints that cannot be cached — login, search, checkout, an API write path. Those need request-level defenses: fingerprinting, challenges, rate limits and WAF rules, applied before the request reaches your origin.
For a single hostname, chaining two proxying edges is rarely what you want: two challenge layers, doubled caching decisions, and the inner edge seeing the outer edge's IP addresses instead of your visitors', which degrades every per-IP defense. Splitting by hostname works well, though — media on one, the application on the other.
No. Setup is two DNS records at whatever DNS provider you use today, so you can migrate one hostname at a time.
It caches and serves HTTP content including video files, and can pull from a private S3-compatible bucket signed at the edge. It does not offer an encoding or live-streaming pipeline. If your requirement is a managed video workflow rather than protection plus delivery, a media-specialist CDN is the right tool.
No. Scrubbed attack traffic is never metered, on any plan. Only legitimate, delivered traffic counts toward your quota.
Same method, different provider — feature availability by plan, with the date it was checked.
Two DNS records, no nameserver change, free plan with no card.