-
Products
- Compute
- Network
- Platform
- Add-ons
-
Solutions
- By Industry
- By Use Case
- Featured
-
Developers
- Documentation
- Tools
- Resources
- Pricing
- Login
DDoS Protection
Our volumetric scrubbing is already engaged on the network edge for you as part of the normal processing of your traffic. This is included for every Internet Port, for every IP Transit circuit as well as for every server we deliver to you. No extra upcharge for the traffic that is being scrubbed, no extra costs.
Edge scrubbing · Multi-Tbps headroom · No upcharge
$ netr ddos status PROFILE edge-scrub TRIGGER auto (volumetric, protocol) HEADROOM multi-Tbps INCLUDED every IP, every port
Always-on protection
Attacks such as DDoS can very easily disrupt the operations of any service provider and hosting company. The damage of an attack is proportional to the damage of losing business due to a failure of services caused by a poor network. At Netrouting we have developed high end DDoS protection to prevent such disruptions for our customers.
All Internet Ports and IP Transit circuits are DDoS-protected, always on, and have no upcharge. Volumetric scrubbing is enabled automatically at the network edge, well above any single transit link's capacity. This enables amplification attacks to be absorbed by Netrouting, scaled to hundreds of Gbps without any customer intervention. Additionally, with multiple carriers and direct peering at all the major IXPs, your traffic will remain online while single-homed networks get taken down.
How it works
Bundled, not bolt-on
All of the protection for all of the IP we route for all of our services (Cloud Compute, Dedicated, IP Transit, etc) is included. So whether you have a single instance of Cloud Compute, a cabinet full of dedicated servers, or 100G of IP Transit, the same edge scrubbing is protecting every IP that we announce on your behalf. There is no separate DDoS Protection service that you would need to add to your configuration. There is no need for an upgrade to a different service tier. And there is no additional traffic to worry about after the fact.
Global footprint
Pick the location closest to your users — or to your existing infrastructure. Every location runs the same hardware, same network, same NOC.
Built for production
We connect you to the Internet using network engineers (and not order takers) and hardware and infrastructure that is built to last, so we can pick up where you left off when you need us.
Common questions
Ddos protection is free for all our customers with an IP on every single product we offer (Cloud, Colocation and Bare Metal Servers). We do not have any Ddos plans for sale that you can then 'upsell' as you go, however we do allow the customer to scale the amount of Ddos protection they require as needed.
The largest attack we have absorbed was around 1.2 Tbps (UDP reflection attack) in 2024. It was an attack on a gaming company that got hit by a large gaming botnet. The attack was mitigated within 15 minutes and didn't affect any of our customers. We absorb attacks below 100 Gbps on the edge of our network on a daily basis but these never reach the customer as they get scrubbed in the fabric of our DDoS protection.
We use behavior based on unwanted traffic on our L3/L4 level of scrubbing. Within the first few hours after setup of a service our edge network has learned the typical traffic of your server. This allows us to have a very good detection rate for unwanted traffic while keeping the amount of false positives to a minimum. If you encounter a false positive, you can flag the IP address in your customer dashboard. Our NOC will take a closer look within the hours as soon as possible. We have a lot of online gaming customers. These customers require a very high quality of service and a very high detection rate of false positives. Some of these customers have custom protocols and run into issues with some of the standard Layer 3 & 4 mitigation methods. For these type of customers we can create a set of rules on L3/L4 level that are specific to their protocol signature.
Our L3/L4 mitigation does not conflict with any other L3/L4 or L7 WAF service running on top of it. Therefore it's perfectly fine to run Cloudflare or AWS Shield (L7 WAF) on top of our network edge mitigation. If you announce your own ASN with us as well we can peer in scrubbing-bypass mode and hand over the already cleaned traffic to your own routers.
All traffic for all customers is scanned in real time for any unusual traffic activity. Within 30 seconds of an attack occurring our systems will kick in to start mitigating the effects of the attack. This edge mitigation happens before the traffic hits your servers, so you won't see any increase in CPU usage or saturated ports. We guarantee our DDoS protection is working 24/7/365 to protect your servers from any traffic based attack.
$ netr deploy --ready
200+ teams rely on Netrouting for bare metal, cloud, GPU servers and colocation. Easy to order servers within minutes. We also love to design custom servers for you and your business, with our experienced engineers.