Under attack?
4 Tbps of XDP filtering. You keep the ASN. GRE, IPIP or WireGuard if you are not in the rack.
Someone is trying to knock you offline. Cute.
Distributed floods work by sending you a very large, very rude postcard from every botnet on the planet. Blocking a country does not help. Asking the attacker to stop also does not help.
To businesses, that is lost sales. To game servers, that is how the other team won without touching a keyboard. To your upstream, that is a ticket you did not want and a nullroute you definitely did not order.
We filter at the PoP. Detection in under a second. No extra lag for players who just wanted to mine a tree in peace.
What we actually stop
Volumetric
- UDP, ICMP, SYN and ACK floods
- Fragmentation and spoofed SYN
- Amplification and reflection
Reflective
- DNS and NTP amplification
- SSDP, SNMP and Chargen
- Smurf and Ping of Death
Exhaustion
- Slowloris and slow HTTP
- Invalid ports and private-IP junk
- Game-shaped garbage at the edge
Who knew a UDP flood could ruin a weekend.
Operators who run game servers tend to find out first. The ones on our DDoS Protection tend to stay up. No nullroute. Players keep their ping. The botnet gets a timeout.
Can your DDoS Protection save you from this?
DDoS Protection vs the usual options
What to expect when the internet decides you are interesting.
| Solution | What you get | Cost |
|---|---|---|
| Akronic DDoS Protection | Always-on XDP, anycast, GRE/IPIP/WireGuard. You keep the ASN. Filtering at the PoP, not after a DNS change. | Included on dedicated. Available as a service. Uptime even during attacks. |
| No protection | Nullroute, downtime, angry Discord, a very quiet shop. | US$ 0/mo until it is not. |
| Third-party scrub | DNS changes, extra latency, a setup that takes days. | US$ 1,000+/mo. A car payment. |
| Dedicated hardware | Staff, licenses, and a rack that exists only to say no. | US$ 10,000+/mo. A very nice vacation. Every month. |
How you connect
Questions operators actually ask
On-demand: traffic stays clean until detection, usually in under 1 second. When an attack is seen, every PoP filters as close to the source as possible. Game-shaped garbage included. No extra lag. No nullroute hobby.
Included on dedicated servers. Available as a service on IP transit and as remote DDoS Protection over GRE, IPIP or WireGuard.
XDP filtering at the PoP is meant to stay out of the way. The flood dies at the edge. The session keeps its ping.
Connect with us, connect with the World
Tell us where the prefixes live. We bring the filter.