X4B Announces 100G Anycast based protection

Posted On // Leave a Comment

Hi all,


Sorry this is a bit late. I have been waiting for response to a PM to the moderation staff for 3 weeks now without response. I dont see anything in the rules prohibiting industry announcements for non-VPS services but I know the staff can dislike this content. After 3 weeks of waiting, I will just post it and wait and see.


We at X4B are pleased to announce the public availability of Anycast based remote protection services with a 100 Gbps/140 Mpps protection limit. It took us a bit longer than expected, but its finally ready for public consumption. No pricing details for LET peeps since we arent a VPS / Dedicated server provider. So purely technical talk :)


Available with backend delivery in Chicago, Denver and L.A locations with these three networks forming the current Anycast PoPs and distributed filtering locations.


100Gbps should be available for all attacks given the capacity available on individual links (reasonable assurity). As this is a multi-homed network it is possible for very large attacks to saturate individual peers links (Zayo, Cogent, Comcast, Tinet) which are less than 100Gbps each. Don't worry though it is particularly rare and an extremely difficult (not to mention expensive) attack vector to produce and sustain (single network attack, not possible via amplification).


We have successfully tested with the assistance of our upstream network some really jaw dropping attacks, some artificial ones as large as 50Gbps and one for a customer on the network hit 90Gbps :)



Type: TCP Invalid Packet (bad hdr length 0 - too short, < 20)
L.A - [Sun Nov 23 22:27:06 PST 2014] Network usage: 3097 Kpps, 47686 Mbps
Chicago - [Sun Nov 23 22:27:10 PST 2014] Network usage: 3818 Kpps, 26346 Mbps
Denver - [Sun Nov 23 22:27:03 PST 2014] Network usage: 2165 Kpps, 19464 Mbps


There is still much more planned for the future, including:




  • Optional delivery to your own servers based on the Anycast PoP doing the filtering. As opposed to our network backhauling to a single location.




  • Automated Partial Null-routes: Currently null-routes affect all routes to an IP across all PoPs, we hope to automate partial nullrouting to help you stay mostly online with attacks with a sum greater than 100Gbps.




  • More filtering Points of Presence are planned. But sssh, more at a later date :P




http://ift.tt/1dvHQ0Z

0 comments:

Post a Comment