Virtuasys
ConnectivityEnterprise Fiber
  • Multi-site & LAN2LAN
  • SD-WAN
IP & NetworkTier 1 Connectivity
  • DDoS Protection
  • IPv4 / IPv6 / ASN
  • BGP & Peering
All network services→
Datacenter & CloudHousing
  • Cloud
  • Bare Metal Servers
  • VPS SSD NVMe
View All Services→Check eligibility
GuidesAboutContact
Customer Portal
  • Enterprise Fiber
  • Multi-site & LAN2LAN
  • SD-WAN
  • Tier 1 Connectivity
  • DDoS Protection
  • IPv4 / IPv6 / ASN
  • BGP & Peering
  • All network services
  • Housing
  • Cloud
  • Bare Metal Servers
  • VPS SSD NVMe
GuidesAboutContact
View All Services→Check eligibility
Customer Portal
  1. Home
  2. Services
  3. DDoS Protection
  4. Always-On Protection

Always-On DDoS Protection

All traffic routes through our scrubbing network continuously.

No detection delay, +1ms latency, included free with every plan.

Compare Protection Modes

TL;DR

All traffic runs through our scrubbing network 24/7, so attacks are blocked within seconds with no vulnerability window.

Scrubbing Capacity
3 Tbps
Mitigation Time
< 30 seconds
Added Latency
<1ms
Scrubbing Locations
Global anycast network

What is Always-On Protection?

Always-on routes 100% of your traffic through our scrubbing network at all times, so mitigation starts the moment an attack pattern is detected instead of after a detection-and-reroute delay. On-demand protection only diverts traffic through scrubbing once an attack is already underway.

Always-On vs On-Demand Protection

Understanding the trade-offs between protection modes

FeatureAlways-OnOn-Demand
Traffic RoutingAlways via scrubbing centersDirect until attack detected
Mitigation Time< 30 seconds30-180 seconds (detection + reroute)
Latency Impact+1ms constantNone normally, +5ms during attack
Attack WindowZero30-180 seconds vulnerability
CostIncluded freeIncluded free
Best ForMission-critical, zero-toleranceStandard workloads, cost-sensitive

Both modes use the same 3 Tbps scrubbing capacity and protection techniques. The difference is when traffic enters the scrubbing network.

Technical Specifications

Scrubbing Capacity
3 Tbps (global network)
Added Latency
<1ms (anycast routing)
Mitigation Time
< 30 seconds
Protection Layers
Layer 3, 4, and 7 (HTTP/HTTPS)
Clean Traffic Delivery
GRE tunnel or direct routing
Mode Switch Time
15 minutes (BGP propagation)

Always-on and on-demand modes are both included free with every Virtuasys service (dedicated servers, colocation, IP transit, cloud). Switch modes anytime via the customer portal, no billing difference, changes take effect within 15 minutes.

What the Scrubbing Network Filters

Layer 3-4 volumetric and protocol attacks stopped before they reach your origin

SYN Flood
Half-open TCP connections exhaust connection tables. Dropped at the scrubbing edge before reaching your servers.
UDP Flood
Volumetric traffic saturating bandwidth with spoofed UDP packets. Rate-limited and filtered at the network edge.
ICMP Flood
Ping-flood volumetric attacks. Filtered by protocol validation at the scrubbing center.
DNS Amplification
Reflection attacks abusing open DNS resolvers to multiply attack volume. Mitigated before reaching your origin.
NTP Amplification
Reflection attacks using NTP monlist responses. Same mitigation path as DNS amplification.
SSDP Reflection
UPnP-based reflection attacks from exposed home and office devices. Filtered at the scrubbing edge.

Frequently Asked Questions

Common questions about proactive DDoS protection

Minimal impact: <1ms added latency due to anycast routing to the nearest scrubbing center. Most applications will not notice this overhead. The trade-off is zero vulnerability window during attacks.

Yes. Change modes anytime via customer portal. BGP routing updates take effect within 15 minutes. No downtime during the switch.

BGP anycast automatically reroutes traffic to the next-closest scrubbing location within seconds. Redundancy is built into the anycast architecture.

Yes. Same protection as on-demand mode: volumetric attacks (UDP/ICMP floods), protocol attacks (SYN floods), amplification attacks (DNS/NTP), and application-layer attacks (HTTP floods). The only difference is timing: always-on mitigates in under 30 seconds.

Always-on protection is included free with all Virtuasys services. No additional charges, no per-Gbps fees, no attack-based billing. Same price as on-demand protection.

Ready to Enable Always-On Protection?

Request a quote for scrubbing capacity on your infrastructure

Request Quote

Related Services

  • Layer 7 MitigationApplication-layer attack protection with AI-powered detection
  • Layer 3-4 ProtectionNetwork and transport layer DDoS mitigation
Virtuasys

Enterprise connectivity, IP transit and colocation on a 100% European backbone.

AS35661 · RIPE NCC member

Connectivity
  • Enterprise Fiber
  • 10 Gbps Enterprise Fiber
  • FTTO vs FTTH
  • L2, Wavelength & Dark Fiber
  • Multi-Site Connectivity
  • SD-WAN Solutions
  • MPLS Solutions
  • Bandwidth on Demand
  • Tunneling (GRE/VXLAN/IPsec/WireGuard)
IP & Network
  • Tier-1 Connectivity
  • BGP & Peering
  • Internet Exchanges
  • DDoS Protection
  • Always-On DDoS Protection
  • Layer 7 DDoS Mitigation
  • Registry & RIPE
  • IPv4 Allocation
  • IPv4 Leasing
  • IPv6 Allocation
  • ASN Registration
  • RIPE Sponsorship
  • IP Transfer Services
  • Looking Glass
Datacenter & Cloud
  • Housing & Colocation
  • Colocation Paris
  • Colocation Lille
  • Rack Rental
  • Cage Hosting
  • Remote Hands
  • Cloud
  • Bare-Metal Servers
  • VPS SSD/NVMe
  • API Automation
  • Custom ISO Deployment
Company
  • About
  • Peering Policy
  • Contact
  • Abuse
  • Guides
  • Check Eligibility
  • Customer Portal
  • Legal notice
  • Privacy

100% European infrastructure · GDPR compliant · 24/7 NOC

© 2026 Virtuasys. All rights reserved.·Legal notice·Privacy·Part of ma2t holding