Under attack?
Frequently asked

The questions, and the answers we actually give

Collected from real conversations, grouped by service, and kept in one place - the same answers appear on each service page, so nothing here can drift out of date separately. If yours is missing, the address at the bottom reaches an engineer.

DDoS Protection

The service page →
How fast does mitigation start?

It does not start - it is already running. Filtering is permanently in the path, so there is no activation, no diversion and no BGP convergence to wait out. A new vector goes from first packet to enforced rule in under a second.

Will you ever null-route my prefix?

As our own mitigation step - never. Blackholing completes the attack, so our escalation path ends in a tighter filter, not in your prefix disappearing. RTBH exists as a tool you can trigger for your own reasons; we do not use it on you.

Do I need a GRE tunnel?

Only if your servers stay at another provider. Tunnels (GRE, IPIP, VXLAN) are one delivery method; a cross connect at any of our sites or protected transit are the others. Same filter either way - only where the clean traffic exits changes.

Does the filtering add latency?

Nanoseconds. The decision happens in the NIC driver before the kernel allocates memory for the packet, and there is no scrubbing-centre detour because there is no detour at all - the filter sits on the path your traffic already takes.

What do I get after an attack?

An incident record: which rule fired, what threshold it crossed, what the traffic was made of, and a packet capture you can open in Wireshark. The exact format is on the evidence page - we would rather you checked than trusted.

My traffic is unusual - game servers, VoIP, custom UDP. Will it survive?

That traffic is why the filter judges packets by their bytes, never by their port. Source engine, RakNet, SIP and RTP are recognised as themselves, and thresholds are set against your measured baseline rather than an industry default.

Is DDoS protection really included?

Included and always on, from the day the session comes up. No activation, no per-incident invoice, no surge pricing - attack traffic is never billed, because charging you for being attacked would make us a beneficiary of the attack.

Full table, partial or default - can I change later?

All three live on the same port, and changing between them is a request, not a new order or a new circuit.

What does "no oversubscription" actually mean here?

Your committed rate is reserved on every segment it crosses - a 1:1 contention ratio, verifiable by measuring on the busiest evening of the year. Congestion elsewhere is usually a provider's contention ratio arriving on schedule; ours cannot, because it does not exist.

Do you support IPv6?

Dual stack on the same BGP session, by default, at no surcharge. RPKI origin validation runs on every session - invalids are dropped, not de-preferenced.

How is it billed?

95th percentile with a committed rate and burst above it, or flat-rate on a fixed port - whichever fits how your traffic behaves.

Can you deliver where you have no site?

Yes - over a redundant GRE, IPIP or VXLAN tunnel to wherever you are, or via a Layer 2 circuit from a partner facility into our nearest point of presence.

DWDM Wavelengths

The service page →
Is the wavelength protected?

1+1 optical protection where two physically diverse routes exist between the endpoints. Where they do not, we say so before you order - stated plainly rather than implied - and you decide whether your equipment handles failover instead.

Can I bring my own transponders?

Yes - alien wavelengths are supported. We confirm the route budget carries your modulation, agree the channel, and hand it over: your optics, our amplified line system.

Is the latency figure guaranteed?

It is quoted from the measured fibre of the actual route and written into the order - not estimated from a map. If a shorter path exists, we tell you what moving onto it costs.

What speeds can I hand off?

10G, 100G and 400G client interfaces - 10GBASE-LR, 100GBASE-LR4, 400G LR4, and ZR/ZR+ subject to reach.

How fast can a wave be delivered?

On a corridor we already light, it is a provisioning task measured in days. A new corridor is an engineering conversation first - we will tell you which of the two you are asking for.

EVPN-MPLS Transport

The service page →
Is the circuit really transparent?

Your VLAN tags survive untouched (dot1q and QinQ), your MACs are learned in the control plane rather than flooded, and we neither inspect nor renumber anything. We carry frames; what they mean is yours.

What MTU can I get?

Up to 9000 bytes end to end - path dependent, and confirmed before turn-up rather than assumed, because a jumbo circuit that silently fragments is worse than an honest 1500.

Can a multipoint service grow without downtime?

Yes - E-LAN and E-Tree run on EVPN, so a new site joins the existing domain without touching the endpoints that are already up.

What protection does the circuit get?

Sub-50 ms switching where the route has physical diversity; stated plainly where it does not, so you can decide if your own equipment should handle failover.

Can I monitor it myself?

Y.1731 and 802.1ag OAM, with per-circuit graphs visible to you - the same telemetry we watch, not a monthly PDF.

LIR Services

The service page →
Can I get an ASN without becoming a RIPE member?

Yes - that is exactly what a sponsoring LIR is for. We hold the membership and do the paperwork; the AS number is registered to you and usable within days.

Is there any IPv4 left?

Not in the free pool - it ran out in November 2019 and the waiting list is measured in years. Realistic options are renting from our allocations or buying on the transfer market, where we broker and handle the RIPE paperwork.

If I leave, do I keep the addresses?

Yes. PI space and your ASN are registered to you - portable to any sponsoring LIR, including away from us. We sell that independence on purpose.

Are RPKI and reverse DNS extra?

No - ROAs are created and maintained at no charge, and rDNS delegation is managed for free. Unsigned space increasingly just does not propagate, so signing it is not an upsell, it is hygiene.

A range I rented turns up on a blocklist. Then what?

We monitor reputation on every range and alert you when something changes - and we help with the delisting, because addresses are an asset only while they are clean.

Consulting & Build

The service page →
Are you tied to any vendor?

Neutral by experience rather than by policy: seventeen years across commodity NICs, Solarflare, 400G adapters, Juniper and Cisco - and we have left every one of them behind at some point, for reasons we can explain in the report.

Can you just review a design without building anything?

Yes - an engagement can be one document, one incident post-mortem, or one afternoon of hard questions. Every larger arrangement we run started exactly that small.

Will you operate what you build?

If you want that - yes. We can run the network as a managed role from the same NOC that watches our own, or hand it over documented and tested with your team trained. Both endings are first-class.

Can you work under our compliance regime?

We already do - for financial-sector clients the changes are documented, the incident records are DORA-shaped, and the auditors read our paperwork alongside theirs. NDAs are standard before we see anything.

Not here? Write to [email protected] or use the contact form - the reply comes from an engineer, and if the question is good it ends up on this page.