ServicesConnectivity

DDoS protection you can follow.

An attack on your network is detected and filtered at our edge, before it fills your connection. In practice we often see mitigation take effect within seconds. And you do not have to take our word for it: per attack the dashboard shows what came in, what reached you and what we did.

Who it is for

DDoS protection fits if you:

  • Take IP transit from us, on its own or with your colocation
  • Run services that must stay reachable, such as hosting, gaming, VoIP or SaaS
  • Have your own /24 or more, where a carpet bomb hits your whole range
  • Want to see what happens during an attack, not hear afterwards that something happened
How it works

Detect, filter, show.

Baseline protection comes with every IP transit connection from us, including when you take it with your colocation. This is how it works:

Detection at our edge
We measure the traffic to your network all the time, not only during an attack. A sudden rise is assessed within seconds; signals that turn out not to be an attack are not shown to you.
Targeted mitigation
Targeted measures first, such as a rate limit on the attack traffic or an adjusted inbound route. Your own traffic keeps flowing.
Carpet bombing too
An attack spread across your whole /24, so that no single address looks suspicious, is recognised as one attack, with the number of addresses hit.
Notifications where your team is
A mail at the start and end to the owner and your NOC contacts. With the webhook add-on also in Slack, Discord or your own system, signed.
Two levels

Baseline included, extended on request.

Included
Baseline protection

With every IP transit connection from us, on its own or with your colocation: detection and automatic mitigation at our edge, the attack overview in the dashboard, notifications by mail and the blackhole routes below.

On request
Extended DDoS protection

Protection tailored to your services and your traffic, for those who need more than the baseline, for example with gaming, telephony or a platform that is often targeted. We agree the approach and the arrangements with you.

In the dashboard

Every attack, visible.

The examples below were made with demo data and show the Dutch interface; the dashboard is also available in English.

Attacks of the past 72 hours

On the dashboard home page: per attack the target, the peak, how much reached you and whether mitigation was applied.

How to follow an attack →

What came in and what we did

Timeline of offered and delivered traffic, the vectors, the origin per country and network, and every measure with the time it took effect.

A carpet bomb on a whole /24

Even an attack spread across hundreds of addresses and coming in waves appears as one attack in your overview, with the addresses hit.

Setting up notifications

When you are told and who gets the mail. With the webhook add-on you send the same notification to Slack, Discord or your own system.

Your emergency brake

Rather give up one address?

  1. A switch in the dashboard
    Turn a blackhole on and off per IPv4 address, with a confirmation first. Active within seconds.
  2. Through your BGP session
    Announce a /32 within your prefix list with 65535:666 or 211588:0:666. Withdrawing it lifts the blackhole.
  3. Automatically for subnet edges
    Declare your subnets, and during an attack we may filter their network, gateway and broadcast address for up to four hours.

A blackhole makes one address unreachable so the rest of your network stays reachable. It is an emergency brake, not a solution; usually it is not needed.

Why Xyphen IT

Our own network, our own mitigation.

  • Mitigation runs on our own network, AS211588, not at a reseller
  • Per attack you see what we did, instead of a monthly report
  • Engineers who do BGP, blackholing and scrubbing every day
  • Reachable during an attack, without a ticket queue

DDoS protection belongs in the network, not next to it.

FAQ

Frequently asked questions about DDoS protection

How quickly is an attack filtered?

In practice we often see mitigation become active within seconds, but that is not a guarantee: it depends on the shape and size of the attack. Per attack the dashboard shows when which measure took effect.

When is baseline protection included?

With every IP transit connection from us, including when you take it with your colocation. If you take colocation without internet access from us, your traffic does not run over our network and the protection is not included. Extended protection tailored to your services, and notifications through webhooks, are add-ons.

Do I get a notification for every traffic spike?

No. A spike is assessed first; only a confirmed attack appears in your overview and sends a notification, one at the start and one at the end.

Does a firewall not do the same?

Not against a volumetric attack: the connection in front of your firewall fills up before it can act. Such an attack has to be stopped in the network, before your connection, and that is where our mitigation sits.

What if my service is affected anyway?

Report it from the attack page in the dashboard; the attack ID goes along, so we look at the same attack straight away. As a last resort you can also blackhole an address yourself.

Want to know what an attack would look like for you?

We show you the dashboard and look at your services and your traffic with you.