Under attack?
IP & routing

IP transit with the filter already in front of it

Dual-stack transit on a backbone we run ourselves, from a single 1G port to 400G - and every prefix sits behind the same DDoS filtering as our protected ranges from the day it is turned up. Nothing to activate, nothing to re-route when an attack starts.

The blend

Ten ways to reach every destination

We announce your prefixes from AS4849 and carry your traffic across a Tier 2 European backbone we engineer ourselves. Being Tier 2 is the point: ten Tier 1 carriers and twenty exchanges mean several ways to any destination, and our own routing logic chooses between them continuously - you never inherit one carrier's single view of the internet.

route-server · frankfurt
> show route 203.0.113.1 detail
AS 3257  GTT       12.1 ms   0.00 % loss
AS 2914  NTT       12.8 ms   0.00 % loss
AS 1299  Arelion   13.4 ms   0.00 % loss
IX  DE-CIX peer     9.6 ms   0.00 % loss  << active
# preference recomputed continuously, per destination
Your session

You choose what you receive

Take the full table if you run your own policy, a partial table if you only want our peering and customer routes, or a default route if you would rather keep memory and complexity down. All three live on the same port, and changing between them is a request, not a new order.

FULL~1.0M routes · you run policy
PARTIALpeering + customer routes only
DEFAULT0.0.0.0/0 + ::/0 · minimal RIB
Traffic engineering

Communities, not support tickets

Prepend, restrict or blackhole per region, per exchange or per upstream - documented large communities, applied on your next update. RTBH and FlowSpec are included, not sold back to you as an incident-response upsell.

your router
# do not announce via Cogent
> set community 4849:0:174
# prepend 2x towards DE-CIX peers
> set community 4849:2:6695
# blackhole one /32 under attack
> set community 4849:666:0
Capacity

No oversubscription - arithmetically

Committed capacity is reserved on every segment it crosses, not a number sold several times over on the assumption you will not all want it at once. Most congestion a transit customer sees is not a fault - it is a contention ratio arriving on a busy evening. Ours is one to one, verifiable by measuring on the worst night of the year rather than the best.

1 : 11 : 20 is the industry's quiet habit contention ratio - any port, any hour
Under attack

The filter was already in your path

The transit and the scrubbing are the same company, on the same path. No diversion event, no GRE tunnel to somebody else's scrubbing centre, no latency step when the attack starts - your traffic was already going through the filter on a quiet Tuesday.

elsewhere: you → detect → divert → GRE → scrubber → internet +30 ms
here: internet → filter → you same path, every day
One port

Everything the port carries, without a second order

A transit port here is not bandwidth with a BGP session on top. The network behind it is the product - and every part of it is included from the day the session comes up.

Transit

Carrier-grade IP transit

Ten Tier 1 upstreams blended by our own path-selection logic, measured continuously for latency and loss. You get the mix, not one carrier's view.

Peering

Twenty exchanges on-net

Traffic to the networks people actually use rides peering, not transit - shorter paths, fewer hops, and nothing billed differently for it.

Protection

DDoS filtering, already on

Every prefix sits behind the same filter as our protected ranges. No activation, no diversion, no per-incident invoice.

Content

CDN and cloud, one cable away

Hundreds of direct PNI ports to Google, Meta, AWS, Microsoft, Cloudflare, Akamai, CDN77, ByteDance, OVHcloud, Hetzner and the rest of the heavy destinations - plus thousands of peering sessions over the exchanges. The full mix →

Reach

Remote exchange access

A port on an exchange we are present at, delivered to your rack over our backbone - peering in a city without taking space in it.

Transport

Between our sites

The same port can carry Layer 2 circuits or a wavelength between any two of the ten locations, on the same infrastructure and the same invoice.

Port speeds1G-400GAt every one of our ten European sites
Familiesv4 + v6Dual stack on the same session, no surcharge
FilteringAlways onIncluded, not an add-on or an activation
NOC24/7Answered by an engineer, never by a model
A named engineer, not a queue. Every transit customer gets a personal account manager and a network engineer who know the circuit, the policy and the history of it. During an incident you are talking to somebody who already has your session open - not explaining your topology from the beginning to whoever answered.

The specification

Everything an engineer would ask before ordering, grouped and folded - open what you need.

Routing
Route options
Full table, partial (peering and customer routes only) or default. Changeable on the same port without a new order.
Address families
IPv4 and IPv6 on the same BGP session, dual stack by default.
Sessions
Single or multiple sessions, eBGP multihop, BFD available for sub-second failure detection.
Prefix filtering
Filters generated from IRR data, refreshed automatically. RPKI origin validation applied to every session - invalids are dropped, not de-preferenced, with no opt-in and no extra charge.
Communities
Documented large communities for prepending, regional and per-exchange restriction, and per-upstream control. The full list is published rather than sent on request.
Blackholing
Customer-triggered RTBH, and FlowSpec rules where the upstream path supports them. Blackholing is available to you; it is never our own mitigation step.
Maximum prefixes
Agreed per session, with a warning threshold well below the limit so a leak is a page rather than a session reset.
Capacity and performance
Committed rate
Flexible CDR from 1 Gbps to 400 Gbps, with burst above it.
Oversubscription
None. Committed capacity is reserved end to end on every segment it traverses. No contention ratio, on any port, at any hour.
Backbone
Juniper throughout, fully redundant MPLS mesh over our own DWDM. Nx100G between sites, 50 Tbps of core capacity.
Jumbo frames
Up to 9000 bytes MTU, available on request and confirmed end to end before turn-up.
Latency and jitter
Engineered for low latency with minimal jitter and no packet loss on committed traffic. Per-route figures quoted from measurement, not from a map.
Resilience
Diverse paths in every metro. A failed link or line card is a re-convergence, not an outage.
Delivery
Handoff
Physical port at any of our sites, cross connect arranged by us, or a redundant GRE / IPIP / VXLAN tunnel where you stay at your current facility.
Optics
10GBASE-LR, 25G LR, 100GBASE-LR4, 400G LR4 and ZR, subject to the path.
Redundancy
Dual ports at one site or diverse ports across two, carried over EVPN-MPLS with no single point of failure in our path.
Billing
95th percentile with a committed rate and burst, or flat-rate on a fixed port.
Turn-up
Typically a few working days once the cross connect is in place; a tunnel handoff can be same-day.

Building and managing your network

A transit port assumes there is a network on your side of it. When there is not yet - or when it is one engineer wearing four hats - that side is work we also do.

Design

Architected against your traffic

Border and edge design from the people who run one: upstream mix, routing policy, redundancy that survives the failure it was drawn for. Measurements first, opinions second. How an engagement runs →

Equipment

Rent the routers with the port

The same Juniper platforms we operate ourselves - specified, configured and kept current by us, on rental rather than capital. For a network taking its first 100G port, the difference between a project and a purchase order.

Operation

Run by us, or handed over

We can operate the edge we built, monitor it from the same NOC that watches our own, or hand it over documented and tested with your team trained on it. The engagement ends when your people can change it without us.

What customers use it for

Frequently asked

Is DDoS protection really included?

Included and always on, from the day the session comes up. No activation, no per-incident invoice, no surge pricing - attack traffic is never billed, because charging you for being attacked would make us a beneficiary of the attack.

Full table, partial or default - can I change later?

All three live on the same port, and changing between them is a request, not a new order or a new circuit.

What does "no oversubscription" actually mean here?

Your committed rate is reserved on every segment it crosses - a 1:1 contention ratio, verifiable by measuring on the busiest evening of the year. Congestion elsewhere is usually a provider's contention ratio arriving on schedule; ours cannot, because it does not exist.

Do you support IPv6?

Dual stack on the same BGP session, by default, at no surcharge. RPKI origin validation runs on every session - invalids are dropped, not de-preferenced.

How is it billed?

95th percentile with a committed rate and burst above it, or flat-rate on a fixed port - whichever fits how your traffic behaves.

Can you deliver where you have no site?

Yes - over a redundant GRE, IPIP or VXLAN tunnel to wherever you are, or via a Layer 2 circuit from a partner facility into our nearest point of presence.