DDoS Protection

Our protection solutions

Depending on the data center we deploy different, site-specific DDoS solutions every product with its own IP address is protected automatically.

NTT FRA01
Frankfurt am Main · Root server (EPYC & Ryzen)

At the Frankfurt site we rely on in-house filtering directly in the data center. This means: in the event of an attack, traffic does not have to take an additional route via external filtering providers or third-party networks. This eliminates increased packet latency and rules out data protection concerns from third parties.

We use renowned filtering hardware that reliably blocks malicious traffic before it reaches your server, without affecting clean traffic.

Protected protocols
UDP Floods TCP Floods ICMP Floods GRE Floods Amplification IPv4 & IPv6
Netmountains VEL
Velbert · Xeon · Webspace · Dedicated

At the Velbert site SmartMitigate by AS203446 is used a purpose-built solution embedded natively in a cluster of hardware mitigators. Traffic is filtered directly within the network and forwarded cleanly to your server.

SmartMitigate detects attack patterns automatically and applies precise countermeasures such as SYN cookies, TCP and UDP authentication and protocol-specific filtering rules, including for zero-day attack patterns through adaptive filtering.

Protected protocols & services
UDP Floods TCP Floods ICMP Floods Amplification Zero-Day HTTP / HTTPS SSH IPv4 & IPv6
Databarn AMS
Amsterdam · Databarn · Xeon Platinum · Dedicated

At the Amsterdam site in the Databarn, a powerful always-on DDoS mitigation with over 7 Tbit/s total capacity protects you. Attacks are detected in real time and filtered at the network edge before they reach your server.

Continuous 24/7 monitoring, automatic traffic filtering and detailed attack analytics ensure that legitimate traffic passes through undisturbed, without any manual intervention.

Protected protocols
7+ Tbit/s UDP Floods TCP Floods ICMP Floods Amplification Always-on IPv4 & IPv6

How DDoS defense works

Malicious traffic is detected and filtered your server receives only clean connections.

Phase 1: Attack
Bot 1
Bot 2
Bot 3
Bot 4
Bot 5
+ many more
MALICIOUS TRAFFIC
DDoS filter
Detection & blocking of malicious packets
Blocked & dropped
Malicious traffic
Your server
Only clean traffic

Frequently asked questions

Do I have to activate the DDoS protection myself?

No. Protection is automatically active on all products with their own IP address you don't have to set up or manually switch on anything.

How does the protection respond to new attack methods?

Using automatically generated traffic samples during an attack, our experts can carry out a detailed analysis even after it ends. Based on these evaluations, new attack patterns are incorporated into the filtering systems almost daily so the protection continuously improves.

Does my connection suffer from the filtering?

Normally not. Because filtering takes place directly in the data center and no external detour via third-party networks is necessary, additional latency stays minimal. Clean traffic is passed through unthrottled.

Are application-specific services protected too?

Yes. The filtering systems support application-specific rules for common services such as web servers (HTTP/HTTPS) and other protocols. New applications can be integrated promptly based on traffic analysis.