DDoS protection that acts in the network
We filter volumetric and application-based attacks before they reach your connection - with multi-terabit capacity, intelligent traffic analysis and 24/7 mitigation.
Why you need DDoS protection
DDoS attacks are cheap to rent and launched in minutes. They saturate your uplink before your own firewall can even react - protection has to act in the network.
Volumetric (L3/L4)
UDP, ICMP and amplification floods fill the link until legitimate users are locked out.
Protocol attacks
SYN floods exhaust the state tables of firewalls, load balancers and servers.
Application (L7)
Disguised HTTP floods hit expensive endpoints and are hard to tell from real users.
How our mitigation works
Detection, diversion and filtering run automatically in the carrier network - no action required on your side.
Detection
Continuous NetFlow/sFlow analysis builds a baseline profile. Deviations are detected within seconds.
Diversion
Suspicious traffic is automatically steered into scrubbing - on demand or always on.
Filtering
Malicious packets are dropped; BGP Flowspec blocks attack vectors precisely.
Clean traffic
Only cleaned, legitimate traffic reaches your connection - with no action on your side.
Standard & Premium
Choose the right protection tier - both are available with IP Transit.
Standard DDoS Protection
Volumetric L3/L4 protection
- Automatic attack detection
- BGP Flowspec support
- Real-time monitoring
Premium DDoS Protection
Advanced L3-L7 protection with intelligent traffic analysis
- Automatic attack detection
- Layer 3-7 protection
- BGP Flowspec support
- Real-time monitoring
- Automated filter rules
Both protection tiers are available with DDoS-protected IP Transit.
Frequently asked questions
Answers to the key questions about IP Transit, DDoS protection, billing and onboarding.
Keep your services online - even under fire
Talk to our engineers about the right protection tier or start a free trial.