Under attack?
Protection for hosting providers

DDoS protection for hosting providers, without blackholing a customer to save the rack

A hosting network is a single failure domain with hundreds of tenants inside it. One attacked IP can saturate a shared uplink, and the traditional answer - null-routing the target - hands the attacker exactly what they wanted. We filter per destination and per prefix at the same time, so the attacked customer stays reachable and the neighbours never notice.

What an attack on a hosting network actually looks like

Carpet bombing across the allocation

The modern attack does not aim at one IP. It spreads a few hundred thousand packets per second across every address in a /24, so no single host crosses a per-IP threshold and nothing fires, while the aggregate saturates the uplink. We measured exactly this: a prefix taking 1,117,215 pps while its busiest single address sat far below its own budget.

One tenant's attack, everybody's outage

Shared uplinks, shared edge routers and shared scrubbing budgets mean the blast radius of an attack on a €4 VPS is the entire cabinet. Per-customer thresholds are the only honest way to bound it, and a single fleet-wide rate limit cannot express them.

Reflection aimed at your own resolvers

DNS, NTP and CLDAP reflectors inside a hosting range are a permanent liability: they are abused to attack third parties, and the backscatter that returns is indistinguishable from an attack on you.

Why this network suits a hosting provider

Two thresholds at once, /32 and /24

Every destination is budgeted individually and the prefix is budgeted as a whole, evaluated on the same packet. A carpet bomb trips the aggregate even though no host trips its own, and a single-target flood trips the host even though the prefix is quiet.

Your prefixes stay announced

Protected ranges are announced normally and keep working. There is no blackhole community, no null route and no customer taken off the internet as a mitigation step - the thing that makes support tickets and churn.

Per-customer profiles inside one prefix

A game server, a mail host and a backup target in the same /24 have nothing in common in their traffic shape. Thresholds are set per destination against measured baselines rather than one number for the range.

Abuse and reflection controls

Rate limits on answerless DNS responses, suspect query floods and the full reflector set - chargen, CLDAP, rpcbind, memcached, MS-SQL, SSDP, SNMP, NetBIOS, WSD, CoAP - applied per destination /24 so a compromised resolver does not poison the whole range.

Tier 2 European backbone · European DDoS protected network Built, filtered and operated inside the EU · human NOC 24/7, no AI agents
ISO 9001ISO 27001PCI-DSSGDPRNIS2

The rest of the stack, from the same AS

The mitigation is one layer. The same network sells the layers around it - and a stack bought from one operator has nobody in it to blame somebody else.

IP transit

Wholesale transit with the filter built in

Buy the upstream and the mitigation as one thing: 1G-400G ports, full table, 95th percentile billing - and every prefix protected from the day it is turned up. One invoice, one NOC, and no finger-pointing between the carrier and the scrubber. The transit page →

Transport

Your racks in two cities, one network

E-Line or E-LAN between facilities for replication and internal VLANs - or a wavelength when the packet layer should be yours. Growing into a second metro stops being a renumbering project. EVPN-MPLS transport →

Consulting

The border, designed and handed over

Taking your first 100G port is a project: router selection, routing policy, redundancy. We design it, rent you the same Juniper platforms we run if you would rather not buy them, configure everything and stay on support afterwards. How an engagement runs →

How it is delivered

BGP session with your AS, protected prefixes announced through us
GRE, IPIP or VXLAN tunnel where you keep your own upstream
Cross-connect or direct transit at any of our points of presence
Per-customer attack history and packet captures through the portal

Protection for other sectors