Always-On DDoS Protection
All traffic routes through our scrubbing network continuously.
No detection delay, +1ms latency, included free with every plan.
TL;DR
All traffic runs through our scrubbing network 24/7, so attacks are blocked within seconds with no vulnerability window.
- Scrubbing Capacity
- 3 Tbps
- Mitigation Time
- < 30 seconds
- Added Latency
- <1ms
- Scrubbing Locations
- Global anycast network
What is Always-On Protection?
Always-on routes 100% of your traffic through our scrubbing network at all times, so mitigation starts the moment an attack pattern is detected instead of after a detection-and-reroute delay. On-demand protection only diverts traffic through scrubbing once an attack is already underway.
Always-On vs On-Demand Protection
Understanding the trade-offs between protection modes
| Feature | Always-On | On-Demand |
|---|---|---|
| Traffic Routing | Always via scrubbing centers | Direct until attack detected |
| Mitigation Time | < 30 seconds | 30-180 seconds (detection + reroute) |
| Latency Impact | +1ms constant | None normally, +5ms during attack |
| Attack Window | Zero | 30-180 seconds vulnerability |
| Cost | Included free | Included free |
| Best For | Mission-critical, zero-tolerance | Standard workloads, cost-sensitive |
Both modes use the same 3 Tbps scrubbing capacity and protection techniques. The difference is when traffic enters the scrubbing network.
Technical Specifications
- Scrubbing Capacity
- 3 Tbps (global network)
- Added Latency
- <1ms (anycast routing)
- Mitigation Time
- < 30 seconds
- Protection Layers
- Layer 3, 4, and 7 (HTTP/HTTPS)
- Clean Traffic Delivery
- GRE tunnel or direct routing
- Mode Switch Time
- 15 minutes (BGP propagation)
Always-on and on-demand modes are both included free with every Virtuasys service (dedicated servers, colocation, IP transit, cloud). Switch modes anytime via the customer portal, no billing difference, changes take effect within 15 minutes.
What the Scrubbing Network Filters
Layer 3-4 volumetric and protocol attacks stopped before they reach your origin
- SYN Flood
- Half-open TCP connections exhaust connection tables. Dropped at the scrubbing edge before reaching your servers.
- UDP Flood
- Volumetric traffic saturating bandwidth with spoofed UDP packets. Rate-limited and filtered at the network edge.
- ICMP Flood
- Ping-flood volumetric attacks. Filtered by protocol validation at the scrubbing center.
- DNS Amplification
- Reflection attacks abusing open DNS resolvers to multiply attack volume. Mitigated before reaching your origin.
- NTP Amplification
- Reflection attacks using NTP monlist responses. Same mitigation path as DNS amplification.
- SSDP Reflection
- UPnP-based reflection attacks from exposed home and office devices. Filtered at the scrubbing edge.
Frequently Asked Questions
Common questions about proactive DDoS protection
Minimal impact: <1ms added latency due to anycast routing to the nearest scrubbing center. Most applications will not notice this overhead. The trade-off is zero vulnerability window during attacks.
Yes. Change modes anytime via customer portal. BGP routing updates take effect within 15 minutes. No downtime during the switch.
BGP anycast automatically reroutes traffic to the next-closest scrubbing location within seconds. Redundancy is built into the anycast architecture.
Yes. Same protection as on-demand mode: volumetric attacks (UDP/ICMP floods), protocol attacks (SYN floods), amplification attacks (DNS/NTP), and application-layer attacks (HTTP floods). The only difference is timing: always-on mitigates in under 30 seconds.
Always-on protection is included free with all Virtuasys services. No additional charges, no per-Gbps fees, no attack-based billing. Same price as on-demand protection.
Ready to Enable Always-On Protection?
Request a quote for scrubbing capacity on your infrastructure