✨ NEW · Bare Metal Servers with 20G Dedicated Unmetered Bandwidth → read more ✨ NEW · 20G Dedicated Unmetered Servers → STATUS

DDoS Protection

Always-on DDoS protection on every IP we route

Our volumetric scrubbing is already engaged on the network edge for you as part of the normal processing of your traffic. This is included for every Internet Port, for every IP Transit circuit as well as for every server we deliver to you. No extra upcharge for the traffic that is being scrubbed, no extra costs.

Edge scrubbing · Multi-Tbps headroom · No upcharge

Always-on protection

DDoS protected network

Attacks such as DDoS can very easily disrupt the operations of any service provider and hosting company. The damage of an attack is proportional to the damage of losing business due to a failure of services caused by a poor network. At Netrouting we have developed high end DDoS protection to prevent such disruptions for our customers.

All Internet Ports and IP Transit circuits are DDoS-protected, always on, and have no upcharge. Volumetric scrubbing is enabled automatically at the network edge, well above any single transit link's capacity. This enables amplification attacks to be absorbed by Netrouting, scaled to hundreds of Gbps without any customer intervention. Additionally, with multiple carriers and direct peering at all the major IXPs, your traffic will remain online while single-homed networks get taken down.

Talk to a security engineer

vector_network_ddos

How it works

Edge scrubbing, automatic engage, no traffic-cost surprise

  • Always-on edge scrubbing The filtering of attack traffic (scrubbing) is applied at the edge of our network (way above any single link of your transit provider) so enough attack traffic is absorbed, so it won't hit your port and cause problems for you.
  • Automatic engage We have developed a pipeline to automatically engage edge scrubbing for all of your traffic as soon as we have detection of a particular attack signature.
  • No upcharge, no overage Attack traffic is filtered at our cost. There is no extra charge for packets that were filtered by our scrubbing network. And you won't find an "incident upgrade" charge the morning after.
  • Multi-Tbps headroom Our aggregate scrubbing capacity at the edge of our network is multiples higher than the largest observed attack in size. We continue to invest in headroom to keep your traffic online.
  • Multi-carrier diversity As a network, our traffic is already spread across a number of different providers and we have direct peering at a number of IXP's. This means that during a DDoS attacks, traffic through our network will continue to function for all customers as opposed to single-homed networks that will be taken down by the very same attack.
  • NoC support 24/7 Our Network Operations Center staff are available 24/7 to assist with custom mitigations, traffic analysis and other support needed for incidents that occur. We have staff available on the line versus you being put in a queue while waiting for someone to return your call.

Bundled, not bolt-on

Included with every IP we route

All of the protection for all of the IP we route for all of our services (Cloud Compute, Dedicated, IP Transit, etc) is included. So whether you have a single instance of Cloud Compute, a cabinet full of dedicated servers, or 100G of IP Transit, the same edge scrubbing is protecting every IP that we announce on your behalf. There is no separate DDoS Protection service that you would need to add to your configuration. There is no need for an upgrade to a different service tier. And there is no additional traffic to worry about after the fact.

Explore the network

Global footprint

Deployed in 10+ datacenters across three continents

Pick the location closest to your users — or to your existing infrastructure. Every location runs the same hardware, same network, same NOC.

Built for production

Why teams stay with Netrouting

We connect you to the Internet using network engineers (and not order takers) and hardware and infrastructure that is built to last, so we can pick up where you left off when you need us.

  • Expert-Level Support Our staff is available 24 hours a day, 7 days a week to handle network administration and systems management issues as they occur.
  • Scalable Solutions Build whatever depth or breadth your infrastructure needs and then scale as required.
  • Enhanced Security Enable 2-factor authentication and also limit by IP address from the control panel to secure your account.
  • Cost-Efficient Infrastructure You will always receive the best value from your investment as you will be optimized for budget without any compromise on Quality.

Common questions

DDoS Protection FAQ

  • DDoS protection, is that something you offer for free on every IP, or is that something people pay extra for?

    Ddos protection is free for all our customers with an IP on every single product we offer (Cloud, Colocation and Bare Metal Servers). We do not have any Ddos plans for sale that you can then 'upsell' as you go, however we do allow the customer to scale the amount of Ddos protection they require as needed.

  • What attack sizes have you actually absorbed?

    The largest attack we have absorbed was around 1.2 Tbps (UDP reflection attack) in 2024. It was an attack on a gaming company that got hit by a large gaming botnet. The attack was mitigated within 15 minutes and didn't affect any of our customers. We absorb attacks below 100 Gbps on the edge of our network on a daily basis but these never reach the customer as they get scrubbed in the fabric of our DDoS protection.

  • How does the scrubbing work - will it block legitimate traffic?

    We use behavior based on unwanted traffic on our L3/L4 level of scrubbing. Within the first few hours after setup of a service our edge network has learned the typical traffic of your server. This allows us to have a very good detection rate for unwanted traffic while keeping the amount of false positives to a minimum. If you encounter a false positive, you can flag the IP address in your customer dashboard. Our NOC will take a closer look within the hours as soon as possible. We have a lot of online gaming customers. These customers require a very high quality of service and a very high detection rate of false positives. Some of these customers have custom protocols and run into issues with some of the standard Layer 3 & 4 mitigation methods. For these type of customers we can create a set of rules on L3/L4 level that are specific to their protocol signature.

  • Can I bring my own scrubbing or layer-7 WAF on top of their l3/l4 mitigation?

    Our L3/L4 mitigation does not conflict with any other L3/L4 or L7 WAF service running on top of it. Therefore it's perfectly fine to run Cloudflare or AWS Shield (L7 WAF) on top of our network edge mitigation. If you announce your own ASN with us as well we can peer in scrubbing-bypass mode and hand over the already cleaned traffic to your own routers.

  • DDoS - SLA?

    All traffic for all customers is scanned in real time for any unusual traffic activity. Within 30 seconds of an attack occurring our systems will kick in to start mitigating the effects of the attack. This edge mitigation happens before the traffic hits your servers, so you won't see any increase in CPU usage or saturated ports. We guarantee our DDoS protection is working 24/7/365 to protect your servers from any traffic based attack.