DDoS protection
L3 and L4 filtering in the NIC driver at line rate, plus a separate Layer 7 WAF for what a packet filter cannot judge. Fifty-one vectors with their own counters and thresholds.
Our own DWDM lambdas between European points of presence, our own routers, switches and servers on top of them, and our own XDP/eBPF filter in the driver of every scrubbing node. One in-house team runs the whole of it, from the lambda to the packet - so there is no hand-off between the people who carry your traffic and the people who clean it.
| DNS amplification | 15 111 081 pps | drop |
| UDP flood | 48 159 634 pps | drop |
| Carpet bomb /24 | 1 117 215 pps | drop |
| SYN flood | 2 431 508 pps | drop |
| Customer traffic | 9 402 663 pps | pass |
Every layer below is ours to change. When a new attack vector appears we write the filter for it - we do not open a support case with an appliance vendor and wait for a firmware release.
Dedicated wavelengths between European sites.
One control plane for bridging and routing between PoPs.
Per-upstream marking, so a flood can be traced to the path it entered on.
Per-vector counters, per-destination budgets, signature latches - reloadable without dropping a packet.
A separate service, because a packet-level filter cannot judge a valid request.
Volumetric floods, amplification and reflection across every reflector class, carpet bombing spread over a whole prefix, TCP handshake abuse, protocol-specific game floods - and a separate Layer 7 engine for the attacks a packet filter cannot see.
Your traffic is never blackholed. We drop the attack, not the destination - a prefix under mitigation stays announced and stays reachable throughout.
The filter is the same for everyone. What changes is the thresholds, and we set them against your traffic rather than against an industry default.
Support is engineers on the network, around the clock - nothing automated answers before a human does, and the person who replies can change a rule while you are still typing. Why we run it this way →
Juniper at the edge, Dell clusters doing the filtering, our own DWDM lambdas between sites and EVPN-MPLS underneath the lot. Ten Tier 1 upstreams and twenty exchanges, with 100G and 400G handoff at every location.
The map and the ten locations → · The platform → · Upstreams & peering →
Every service below runs on the same network, with the same filter in front of it and the same engineers behind it. The detail lives on its own page rather than all of it here.
L3 and L4 filtering in the NIC driver at line rate, plus a separate Layer 7 WAF for what a packet filter cannot judge. Fifty-one vectors with their own counters and thresholds.
Dual stack, 1G to 400G, full or partial table, documented BGP communities - and no oversubscription on any port at any hour.
Dedicated 10G, 100G and 400G channels between European sites on our own line system, with latency quoted from the fibre rather than from a map.
Transparent Ethernet between sites - E-Line, E-LAN and E-Tree - with tags and MTU intact and sub-50 ms protection where the route is diverse.
Ten points of presence, the Juniper and Dell platform underneath them, ten Tier 1 upstreams and twenty exchanges.
Architecture, hardware selection and full border and edge builds - from people who have rebuilt their own data plane six times since 2009.
Six times we have designed a filtering data plane, chosen the hardware under it and rebuilt the border around it - on our own network, under real attack. DDoS architecture, router and switch selection, and full border and edge builds. What the engagements look like →
Each one was thrown away and rebuilt because the traffic outgrew it, not because a vendor released something. Every generation was ours to write, and the one running today can be replaced while packets are flowing.
5 Tbps of transit, 15 Tbps of peering and 50 Tbps of backbone between our points of presence.









































This site sets zero cookies - no analytics, no trackers, no profile of you. The only third-party requests are the fonts, served by Google Fonts, and the spam check on the contact form. Everything else stays between your browser and our network - the full privacy note.