Carrier-grade IP transit
Ten Tier 1 upstreams blended by our own path-selection logic, measured continuously for latency and loss. You get the mix, not one carrier's view.
Dual-stack transit on a backbone we run ourselves, from a single 1G port to 400G - and every prefix sits behind the same DDoS filtering as our protected ranges from the day it is turned up. Nothing to activate, nothing to re-route when an attack starts.
We announce your prefixes from AS4849 and carry your traffic across a Tier 2 European backbone we engineer ourselves. Being Tier 2 is the point: ten Tier 1 carriers and twenty exchanges mean several ways to any destination, and our own routing logic chooses between them continuously - you never inherit one carrier's single view of the internet.
> show route 203.0.113.1 detail AS 3257 GTT 12.1 ms 0.00 % loss AS 2914 NTT 12.8 ms 0.00 % loss AS 1299 Arelion 13.4 ms 0.00 % loss IX DE-CIX peer 9.6 ms 0.00 % loss << active # preference recomputed continuously, per destination
Take the full table if you run your own policy, a partial table if you only want our peering and customer routes, or a default route if you would rather keep memory and complexity down. All three live on the same port, and changing between them is a request, not a new order.
Prepend, restrict or blackhole per region, per exchange or per upstream - documented large communities, applied on your next update. RTBH and FlowSpec are included, not sold back to you as an incident-response upsell.
# do not announce via Cogent > set community 4849:0:174 # prepend 2x towards DE-CIX peers > set community 4849:2:6695 # blackhole one /32 under attack > set community 4849:666:0
Committed capacity is reserved on every segment it crosses, not a number sold several times over on the assumption you will not all want it at once. Most congestion a transit customer sees is not a fault - it is a contention ratio arriving on a busy evening. Ours is one to one, verifiable by measuring on the worst night of the year rather than the best.
The transit and the scrubbing are the same company, on the same path. No diversion event, no GRE tunnel to somebody else's scrubbing centre, no latency step when the attack starts - your traffic was already going through the filter on a quiet Tuesday.
A transit port here is not bandwidth with a BGP session on top. The network behind it is the product - and every part of it is included from the day the session comes up.
Ten Tier 1 upstreams blended by our own path-selection logic, measured continuously for latency and loss. You get the mix, not one carrier's view.
Traffic to the networks people actually use rides peering, not transit - shorter paths, fewer hops, and nothing billed differently for it.
Every prefix sits behind the same filter as our protected ranges. No activation, no diversion, no per-incident invoice.
Hundreds of direct PNI ports to Google, Meta, AWS, Microsoft, Cloudflare, Akamai, CDN77, ByteDance, OVHcloud, Hetzner and the rest of the heavy destinations - plus thousands of peering sessions over the exchanges. The full mix →
A port on an exchange we are present at, delivered to your rack over our backbone - peering in a city without taking space in it.
The same port can carry Layer 2 circuits or a wavelength between any two of the ten locations, on the same infrastructure and the same invoice.
Everything an engineer would ask before ordering, grouped and folded - open what you need.
A transit port assumes there is a network on your side of it. When there is not yet - or when it is one engineer wearing four hats - that side is work we also do.
Border and edge design from the people who run one: upstream mix, routing policy, redundancy that survives the failure it was drawn for. Measurements first, opinions second. How an engagement runs →
The same Juniper platforms we operate ourselves - specified, configured and kept current by us, on rental rather than capital. For a network taking its first 100G port, the difference between a project and a purchase order.
We can operate the edge we built, monitor it from the same NOC that watches our own, or hand it over documented and tested with your team trained on it. The engagement ends when your people can change it without us.
Included and always on, from the day the session comes up. No activation, no per-incident invoice, no surge pricing - attack traffic is never billed, because charging you for being attacked would make us a beneficiary of the attack.
All three live on the same port, and changing between them is a request, not a new order or a new circuit.
Your committed rate is reserved on every segment it crosses - a 1:1 contention ratio, verifiable by measuring on the busiest evening of the year. Congestion elsewhere is usually a provider's contention ratio arriving on schedule; ours cannot, because it does not exist.
Dual stack on the same BGP session, by default, at no surcharge. RPKI origin validation runs on every session - invalids are dropped, not de-preferenced.
95th percentile with a committed rate and burst above it, or flat-rate on a fixed port - whichever fits how your traffic behaves.
Yes - over a redundant GRE, IPIP or VXLAN tunnel to wherever you are, or via a Layer 2 circuit from a partner facility into our nearest point of presence.
This site sets zero cookies - no analytics, no trackers, no profile of you. The only third-party requests are the fonts, served by Google Fonts, and the spam check on the contact form. Everything else stays between your browser and our network - the full privacy note.