DDoS protection services

Protection for websites, servers and networks

NetIO delivers DDoS protection as a service: traffic is filtered on our infrastructure before it reaches yours. Three connection models cover a single website, an individual server, or an entire network — all running on mitigation software we develop ourselves.

Website protection

Layer 7 · reverse proxy · HTTP / HTTPS · WAF

Your site is published through NetIO's filtering layer. You point your domain at a protected IP address we assign to you; we terminate the connection, inspect every request, and forward only legitimate traffic to your origin server — which stays hidden behind us.

How it works

  1. We assign a protected IP address from NetIO address space and provision your domains in the control panel.
  2. You repoint DNS — an A/AAAA record, or a CNAME, to the address we gave you. Nothing changes on your server.
  3. Every request is inspected at the application layer: HTTP floods, slow-rate attacks, scrapers, credential stuffing and OWASP-class exploits are blocked or challenged.
  4. Clean requests reach your origin over the connection we keep open to it. Your origin address is never exposed to the public Internet.

What is included

  • Protected IPv4 and IPv6 addresses assigned to your account from NetIO address space
  • HTTP and HTTPS flood mitigation, including slow-rate and low-and-slow attacks
  • Web application firewall covering OWASP-class threats — injection, XSS, path traversal, file inclusion
  • Bot mitigation — challenge-response, JavaScript validation, TLS and HTTP fingerprinting
  • Managed TLS certificates, or bring your own
  • Origin cloaking, access rules, rate limits, geo and ASN filtering
  • Traffic and attack analytics in the control panel, plus a documented REST API
  • Multiple origins with health checks and failover
Built for Online media E-commerce SaaS platforms Corporate websites Public-sector portals Web agencies

Server and dedicated IP protection

Layers 3–4 · protected IP address · GRE / IP-in-IP tunnel

For everything that is not a website — game servers, VPN endpoints, mail, VoIP, APIs, databases and custom TCP or UDP services. We assign you a protected IP address, filter all traffic destined for it at packet level, and deliver clean traffic to your server over a tunnel or a direct link.

How it works

  1. We assign protected IP addresses from NetIO address space — one or more per server — and agree the ports and protocols to forward.
  2. A tunnel is established between our filtering node and your server using GRE or IP-in-IP; if you are in the same facility, clean traffic is delivered over a direct link instead.
  3. All traffic is filtered at layers 3–4: volumetric floods, malformed and fragmented packets, amplification and state-exhaustion attacks are dropped at the edge.
  4. Clean traffic arrives at your server through the tunnel, source addresses intact. Your real server address stays private.

What is included

  • Protected IPv4 and IPv6 addresses assigned to each of your servers
  • Any TCP or UDP service — you are not limited to HTTP
  • Volumetric mitigation: SYN, UDP and ICMP floods, DNS, NTP, SSDP and Memcached amplification, IP fragmentation
  • Protocol and state-exhaustion defence for firewalls, load balancers and connection tables
  • Per-port and per-protocol policies, whitelists, blacklists and rate limits
  • Delivery over GRE, IP-in-IP or a direct cross-connect
  • Works with any operating system and any hosting provider — no software to install on your server
  • Per-address traffic statistics and attack reports
Built for Game hosting VPN & VoIP operators Mail servers API backends Streaming & media delivery Financial platforms

Network protection

BGP announcement · your own prefixes · always-on or on-demand

For operators that hold their own address space. Your prefix is announced through NetIO, inbound traffic is drawn to our filtering nodes, and clean traffic is returned to your network over tunnels or a direct interconnect. You keep your addressing, and your customers keep their IP addresses.

How it works

  1. We establish a BGP session and agree the prefixes to protect — a /24 or larger for IPv4, a /48 or larger for IPv6 — with route origin authorization in place.
  2. Your prefix is announced from NetIO's network: permanently for always-on protection, or only during an attack for on-demand diversion.
  3. Inbound traffic is scrubbed at our filtering nodes across layers 3 to 7, with per-prefix and per-host policies applied.
  4. Clean traffic is returned to your network over GRE tunnels or a dedicated interconnect, with your original addressing preserved end to end.

What is included

  • BGP session with NetIO — your prefixes remain registered to you
  • Always-on protection, or on-demand diversion triggered automatically by detection
  • Return path over GRE, IP-in-IP or a direct cross-connect
  • Per-prefix and per-host policies, so you can tune protection for individual customers of your own
  • NetFlow and sFlow based detection, thresholds and alerting
  • White-label option — resell protection to your own customers under your own brand
  • Protected IPv4 and IPv6 addresses from NetIO address space where you need additional capacity
  • On-premises alternative: license the software and run filtering inside your own network
Built for Internet service providers Hosting & cloud providers Data-centre operators Telecommunications operators Enterprises with their own AS
Choosing a service

Which model fits you

The filtering engine is the same in all three. What differs is how traffic reaches us, and what you need to change on your side.

  Website protection Server & IP protection Network protection
Protects Websites and web applications Individual servers and services Entire networks and address blocks
You change DNS record Tunnel on the server BGP announcement
Traffic HTTP and HTTPS Any TCP or UDP All IP traffic to the prefix
Filtering layers L3–L7, including WAF and bot mitigation L3–L4, with optional L7 for web ports L3–L7 across the whole prefix
Addressing Protected IP assigned by NetIO Protected IP assigned by NetIO Your own address space, announced via NetIO
Prerequisites Control of your domain's DNS Ability to configure a tunnel interface Your own AS number and prefixes
Typical customer Business, media, e-commerce, SaaS Hosting customer, game or VPN operator ISP, hosting provider, data centre
Getting started

How to connect

Onboarding is handled by engineers who will actually be looking after your traffic — not by a ticket queue.

1

Tell us what you protect

Websites, servers or a network — plus your traffic profile, protocols and where your infrastructure sits.

2

Technical scoping

We agree the connection model, the addresses or prefixes involved, filtering policy and escalation contacts.

3

Provisioning and test

Addresses are assigned, tunnels or BGP sessions are established, and the configuration is validated before you switch.

4

Go live

You cut traffic over. Policy is tuned against real patterns, and support stays reachable around the clock.

IPv4 and IPv6Dual-stack across every service
24/7 supportEngineers, not scripts
REST APIAutomation and SIEM integration
Transparent pricingQuoted up front, no per-attack fees

Tell us what you need to keep online

Send us your traffic profile and we will come back with a connection plan and pricing — usually within one business day.