DDoS Protection
3 Tbps scrubbing capacity across layer 3, layer 4 and layer 7. Mitigation in under 30 seconds, always-on or on-demand.
Get a quote
Answer within one business day.
At a glance
Scrubbing on AS35661 that absorbs volumetric floods and application-layer attacks before they reach your origin.
- Capacity
- 3 Tbps
- Mitigation
- < 30 seconds
- Routing
- BGP anycast
- Coverage
- L3 / L4 / L7
Specifications
| Scrubbing capacity | 3 Tbps aggregate, up to 500 Gbps per customer |
| Coverage | Layer 3, layer 4 and layer 7 (network, transport, application) |
| Attack types | SYN flood, UDP flood, ICMP flood, amplification, HTTP flood |
| Mitigation time | Under 30 seconds from detection |
| Routing | BGP anycast, IPv4 and IPv6, no IP renumbering |
| Protection modes | Always-on or on-demand activation |
| Filtering | Stateless ACLs, rate limiting, protocol validation, GeoIP |
| Provisioning | Onboarding timeline and contract term confirmed at quote |
Use cases
- Network operators and ISPs
- Announce your prefixes through our scrubbing centers via BGP and absorb volumetric floods aimed at your transit and edge routers.
- Hosting and game infrastructure
- Keep latency-sensitive UDP services online during SYN, UDP and amplification floods without rerouting traffic mid-attack.
- Web platforms and APIs
- Add layer 7 filtering for HTTP floods and bot traffic on top of layer 3/4 volumetric scrubbing.
Delivery and coverage
Traffic is filtered at our scrubbing centers and clean packets are forwarded to your origin over a GRE tunnel or direct connection. Always-on mode keeps all traffic on the scrubbing path with no activation delay; on-demand mode announces your prefixes when an attack is detected. The 24/7 SOC handles escalation and custom filtering rules.
- Capacity
- 3 Tbps
- Mitigation
- < 30s
- SOC
- 24/7
Frequently asked questions
Pricing depends on protected capacity, the number of prefixes announced, and whether you run always-on or on-demand mode. We scope it on the quote against your traffic profile; there is no per-attack surcharge.
Layer 3 and layer 4 scrubbing stops volumetric floods (SYN flood, UDP flood, ICMP, amplification) that saturate bandwidth. Layer 7 filtering handles HTTP floods, Slowloris and bot traffic against web apps and APIs. Most infrastructure runs both; we scope the mix on the call.
Always-on keeps all traffic on the scrubbing path 24/7 with no activation delay. On-demand announces your prefixes via BGP when an attack is detected and mitigates in under 30 seconds. Always-on is recommended for mission-critical infrastructure.
No. We announce your existing IPv4 and IPv6 ranges via BGP, so no renumbering is required. Legitimate traffic passes through unaffected; only attack traffic is dropped at the scrubbing center.
Protect your infrastructure
Send us your traffic profile and we will scope scrubbing capacity and mode.