Anti-DDoS protection · always on

20 Tbps Anti-DDoS
on every plan

Mitigation sits in front of our datacenter in São Paulo: traffic passes through cloud protection and the A10 Thunder appliance, and whatever is left is filtered in the kernel with XDP and eBPF.

Como funciona

The path your protected traffic takes

Every request goes through four layers of defence before reaching your server.

01
Cloud protection

Rocket Network

All traffic first enters through Rocket Network, our main cloud protection, which absorbs most volumetric attacks before they reach our edge.

02
Our own appliance · up to 500 Gbps

Advanced A10 Networks appliance

Traffic then passes through our own mitigation appliance, an A10 Networks Thunder 14045 TPS rated up to 500 Gbps, which runs advanced filtering focused on SYN flood attacks.

03
XDP · DPDK · eBPF

XDP filtering in the kernel

Next, our own appliances apply complementary rules using XDP, DPDK and eBPF, discarding malicious packets in the kernel itself, with practically zero latency.

04
Clean traffic

Customer server

Only after going through all these layers is legitimate traffic delivered to the customer server, with attack traffic already discarded in the previous layers.

Security

20 Tbps Anti-DDoS, always on

Inline protection across the whole network, at no extra cost and with nothing to configure. While you play or work, we block the attacks.

Inline mitigationMalicious traffic filtered before it reaches the server.
20 TbpsVolumetric absorption capacity at the network edge.
Always on24/7 protection, with nothing to switch on or configure.
Real-time alertsOur team watches and acts on every attack attempt.
SYN flood ✕UDP flood ✕DNS amplif. ✕Layer 7 ✕
Network infrastructure

Built to run under pressure

NE8000 edge router, switches with ports up to 100 GbE and three separate transit networks.

NE8000 edge router

High-capacity edge routing, sized to sustain large volumes of traffic without degradation.

Arista and Huawei switches

Enterprise switching with Arista and Huawei switches, running ports of up to 100 GbE.

Redundant transit and backup

Connectivity with Durand, Embnex and Ascenty as transit and backup networks, keeping a route available at all times.

Transit and backup networks
DurandEmbnexAscentyPorts up to 100 GbE
Before you buy

Frequently asked questions

Didn't find what you need? Message us on WhatsApp.

No. Anti-DDoS protection is inline and already active on every plan, at no extra cost and with nothing to configure.

The impact is minimal. Filtering happens at the edge and in the kernel, through XDP, discarding malicious traffic before it reaches your server.

We handle volumetric attacks such as UDP floods and amplification, protocol attacks such as SYN floods, and application layer attacks.

We keep connectivity with several providers, among them Durand, Embnex and Ascenty. If one link fails, traffic is rerouted through the others.

Easier over a chat

Message us on WhatsApp and we help you pick the right plan for your project. Quick answers from real people.