DDoS Mitigation · Network-layer · BGP integrated

Stay online — even under attack

Always-on or on-demand scrubbing with BGP trigger & RTBH. Optional Flowspec for granular filtering. Dual-stack IPv4/IPv6. 24/7 NOC and clear runbooks.

AS47263 IPv4/IPv6 24/7 NOC
Edge / Scrubber
Mitigation
BGP Core
AS47263
Activation
BGP trigger / RTBH
Granularity
Flowspec (opt.)
Clean traffic
low added latency
IPv6 native
dual-stack
Telemetry
flows & alerts

Schematic — simplified.

Threat coverage

Mitigation focuses on L3/L4 and selected L7-adjacent patterns while preserving low latency for legitimate traffic.

Volumetric (L3/4)

  • UDP floods & reflection/amplification (e.g., NTP, CLDAP, Memcached)
  • ICMP/GRE floods
  • Fragmentation abuse

Protocol anomalies

  • SYN/ACK floods, TCP option abuse
  • Malformed/invalid headers
  • Rate & connection limits

Application-adjacent

  • HTTP/HTTPS floods (network-side measures)
  • L7 partner solutions available on request

Deployment modes & activation

Mode
Always-on

Traffic continuously passes through scrubbing. Best for high-risk or mission-critical workloads.

Mode
On-demand

Activate during an event via BGP trigger or support request. Cost-effective for periodic risk.

Mode
Hybrid

Selected prefixes always-on; others on-demand with RTBH & Flowspec options.

BGP trigger

Advertise tagged routes to signal diversion; clean traffic returns with minimal added latency.

RTBH (blackholing)

Emergency sink for attack targets to protect upstream capacity; prefix/host scope.

BGP Flowspec (optional)

Fine-grained network-layer filters (ports, protocols, rates) for targeted mitigation.

How mitigation works

Step 1
Detect

Telemetry & baselines detect anomalies. Alerts trigger automation or operator action.

Step 2
Divert & scrub

BGP trigger routes traffic to edge scrubbers. Filters drop malicious packets; rate limits smooth bursts.

Step 3
Return clean traffic

Clean traffic returns via stable paths. Continuous monitoring verifies service health.

Edge network Datacenter fiber Monitoring dashboards

Capabilities & options

Capability Included Optional
IPv4 / IPv6 protection
BGP trigger & diversion
RTBH communities
BGP Flowspec rules
Live mitigation logs
Custom runbooks & tests
BGP Communities (example)
47263:100   Prefer (High LocalPref)
47263:200   De-prefer (Low LocalPref)
47263:666   RTBH IPv4 (blackhole)
47263:667   RTBH IPv6 (blackhole)
# Full sheet provided with contract.
Flowspec (illustrative)
# Illustrative example only (final rules per incident)
# match tcp dst-port 80 then rate-limit 10000 packets-per-second
# match udp dst-port 27015 then drop
# We define exact rules with you during onboarding.

Pricing (indicative)

Choose a posture that fits your risk and budget. Final quotes depend on capacity, prefixes, and SLA.

Always-on

Lowest latency

Traffic is continuously scrubbed. Ideal for gaming, fintech, and 24/7 services.

€499/mo
  • Includes RTBH, BGP trigger
  • Optional Flowspec add-on
  • Live logs (add-on)
Select

On-demand

Budget friendly

Activate via BGP trigger or ticket during an incident. Monthly retainer + usage.

€149/mo
  • RTBH included
  • Usage-based scrubbing
  • Upgrade to hybrid anytime
Select

Hybrid / GRE

Fast turn-up

Always-on for critical prefixes; on-demand for others. Can be delivered via GRE tunnel for remote sites.

€299/mo
  • Dual-stack via v4/v6 GRE
  • MTU note: GRE overhead (~24 bytes)
  • Flowspec available
Select
Delivery: Direct BGP hand-off, private VLAN/NNI, or GRE tunnel.
Security: RPKI-ROV, IRR filters, max-prefix, staged policies.
Reports: incident summaries; live logs optional.

Use cases

Gaming
Tick-tight latency under load

Protect match servers and voice gateways; avoid false positives with tuned rules.

Hosting / SaaS
Stable APIs & control planes

Scrub volumetric noise without breaking customer traffic patterns.

E-commerce
No downtime days

Keep checkout responsive during events with pre-staged mitigation.

FAQ

What’s the added latency during mitigation? +

We engineer for minimal added RTT; exact figures depend on your path and mode (always-on vs on-demand diversion).

Do you support IPv6 and RTBH for v6? +

Yes — dual-stack by default. We provide both IPv4 and IPv6 RTBH communities.

Can you share live mitigation logs? +

On request. We can expose summaries or streams suitable for your SIEM.

Do you protect pure L7 attacks? +

We mitigate what’s addressable at network level. For deep L7 (HTTP/HTTPS bots), we can integrate with partner L7 providers.

Start a mitigation plan

Tell us about your prefixes, normal traffic profile, and risk posture. We’ll propose a plan with SLAs & pricing.

Your email client will open with a pre-filled message.

Or email us at sales@as47263.net

NOC & SLA

  • 24/7 monitoring & incident response
  • Defined response times (on request)
  • Change windows & maintenance notices

Quick facts

  • ASN: AS47263
  • Dual-stack IPv4/IPv6
  • RPKI-ROV & IRR filtering
  • BGP communities & Flowspec (opt.)