Wholesale capacity with communities that work
Full table, documented large communities, RPKI validation enforced on every session and no oversubscription - an upstream that publishes what it does instead of asking you to trust it. The transit page →
When an attack crosses your network toward a downstream customer, you carry every packet of it and your own upstreams may blackhole you for it. Buying mitigation should not mean surrendering your routing - you keep your AS, your prefixes and your policy, and divert only what you choose to divert.
Attack volume toward a downstream customer transits your core, fills your transit commits and is billed at 95th percentile like anything else.
Carriers protect themselves first. A large enough attack toward your ranges gets null-routed upstream of you, and the decision is taken without you.
Blackholing the destination stops the flood and completes the attack. For a retail ISP this is a support call; for a wholesale one it is a contract.
Protected prefixes can stay in your announcements with traffic steered through us, or be announced by us during an event and returned afterwards. Both are BGP, both are reversible in a session.
Rules that match a vector rather than a destination, so mitigation removes the attack and not the customer. Published communities for traffic engineering and per-prefix control of what is diverted.
Our border marks every packet with the upstream it arrived on, so when a destination exceeds its budget we can identify and block the path carrying the flood while the other paths keep the full budget. Your legitimate traffic over a clean upstream is untouched.
Public looking glass, published peering policy and BGP communities, PeeringDB and bgp.tools entries. You can verify the network before you buy it and inspect it while you use it.
The mitigation is one layer. The same network sells the layers around it - and a stack bought from one operator has nobody in it to blame somebody else.
Full table, documented large communities, RPKI validation enforced on every session and no oversubscription - an upstream that publishes what it does instead of asking you to trust it. The transit page →
Wavelengths between our metros for your own backbone spans - or bring your transponders and take just the channel. Latency per route is quoted from the measured fibre, not from a map. DWDM wavelengths →
Hand traffic to us in one metro, collect it in another: QinQ-transparent E-Line and E-LAN over the same EVPN-MPLS core that carries our own filtering, with protection stated per route. EVPN-MPLS transport →
Route policy, RTBH and FlowSpec design, and equipment selection for the next upgrade - advice from an operator that runs its own border, not from a reseller with a quota. How an engagement runs →
Protection for other sectors
This site sets zero cookies - no analytics, no trackers, no profile of you. The only third-party requests are the fonts, served by Google Fonts, and the spam check on the contact form. Everything else stays between your browser and our network - the full privacy note.