This network provides us the possibility to expand in any direction, anytime we want. It is built for the purpose of edge delivering data and is protected from DDoS attacks on all edges. Using our high-performance XDP-based protection stack we do not allow any unwanted traffic into our network. Having direct connections to a big amount of Tier 1 providers and IXes, we provide you with fast connectivity and low ping.
TAKE A LOOK AT WHAT OUR MITIGATION PIPELINE CONSISTS OF
Volumetric Protection
With a TTM of just a few seconds, our upstream infrastructure effectively blocks high bandwidth/pps attacks, e.g. fragmented packets or AMP attacks.
ACLs on our upstreams
Applied on all core routers of our upstreams (all PoPs), we use our own rules to reliably block AMP and Reflection based attacks.
Our proprietary XDP filter
Applied on the edge of our anycast nodes, our protocol-based checks filter almost any L4/L7 attack reaching us. Dynamic rules and settings can be created through our API or Panel.
Applications or your network
Only very small attacks will get to this stage. Here, our proxies mitigate more complex layer 7 attacks (e.g., bot attacks). Only legitimate traffic that passes through our proxy will be forwarded.
Our Global Anycast Network
By utilizing proximity-based routing, anycast directs users to our nearest PoP (point of presence), reducing latency and improving response times. This approach enhances reliability through automatic traffic redirection in the event of server failures, ensuring continuous service availability. Additionally, anycast allows us to mitigate large scale Distributed Denial of Service (DDoS) attacks by distributing attack traffic across multiple PoPs.