Always-on or on-demand scrubbing with BGP trigger & RTBH. Optional Flowspec for granular filtering. Dual-stack IPv4/IPv6. 24/7 NOC and clear runbooks.
Schematic — simplified.
Mitigation focuses on L3/L4 and selected L7-adjacent patterns while preserving low latency for legitimate traffic.
Traffic continuously passes through scrubbing. Best for high-risk or mission-critical workloads.
Activate during an event via BGP trigger or support request. Cost-effective for periodic risk.
Selected prefixes always-on; others on-demand with RTBH & Flowspec options.
Advertise tagged routes to signal diversion; clean traffic returns with minimal added latency.
Emergency sink for attack targets to protect upstream capacity; prefix/host scope.
Fine-grained network-layer filters (ports, protocols, rates) for targeted mitigation.
Telemetry & baselines detect anomalies. Alerts trigger automation or operator action.
BGP trigger routes traffic to edge scrubbers. Filters drop malicious packets; rate limits smooth bursts.
Clean traffic returns via stable paths. Continuous monitoring verifies service health.
Capability | Included | Optional |
---|---|---|
IPv4 / IPv6 protection | ✔ | — |
BGP trigger & diversion | ✔ | — |
RTBH communities | ✔ | — |
BGP Flowspec rules | — | ✔ |
Live mitigation logs | — | ✔ |
Custom runbooks & tests | — | ✔ |
47263:100 Prefer (High LocalPref)
47263:200 De-prefer (Low LocalPref)
47263:666 RTBH IPv4 (blackhole)
47263:667 RTBH IPv6 (blackhole)
# Full sheet provided with contract.
# Illustrative example only (final rules per incident)
# match tcp dst-port 80 then rate-limit 10000 packets-per-second
# match udp dst-port 27015 then drop
# We define exact rules with you during onboarding.
Choose a posture that fits your risk and budget. Final quotes depend on capacity, prefixes, and SLA.
Traffic is continuously scrubbed. Ideal for gaming, fintech, and 24/7 services.
Activate via BGP trigger or ticket during an incident. Monthly retainer + usage.
Always-on for critical prefixes; on-demand for others. Can be delivered via GRE tunnel for remote sites.
Protect match servers and voice gateways; avoid false positives with tuned rules.
Scrub volumetric noise without breaking customer traffic patterns.
Keep checkout responsive during events with pre-staged mitigation.
We engineer for minimal added RTT; exact figures depend on your path and mode (always-on vs on-demand diversion).
Yes — dual-stack by default. We provide both IPv4 and IPv6 RTBH communities.
On request. We can expose summaries or streams suitable for your SIEM.
We mitigate what’s addressable at network level. For deep L7 (HTTP/HTTPS bots), we can integrate with partner L7 providers.
Tell us about your prefixes, normal traffic profile, and risk posture. We’ll propose a plan with SLAs & pricing.
Or email us at sales@as47263.net