SMARTNET / AS203446
SmartMitigate

DDoS protection for real production traffic.

Inline network and transport-layer mitigation for hosting, game, voice and infrastructure services, operated directly on the SMARTNET network.

Approach

Mitigation based on traffic behaviour, not broad blocking.

SmartMitigate is SMARTNET's own DDoS mitigation platform and works alongside the existing vendor-based mitigation cluster.

Traffic is inspected continuously. Countermeasures include SYN validation, TCP and UDP authentication, protocol-aware filtering and attack signatures that identify harmful traffic without treating ordinary geography or customer traffic as the attack.

InspectionInline traffic processing for IPv4 and IPv6.
VisibilityAttack records, packet samples, portal access and REST API.
FilteringTCP, UDP, ICMP, GRE and application-specific profiles.
DeliveryBGP, GRE, cross-connect or direct SMARTNET network access.
OperationsCustom mitigation profiles and direct engineering support.
<10 secondsTypical time to mitigate detected attacks.
1 Tbps / 1 GppsGuaranteed mitigation baseline per customer.
IPv4 + IPv6Network and transport-layer mitigation for dual-stack services.
24/7 inlineContinuous inspection rather than emergency-only diversion.
Features

Built for sustained, high-rate attack traffic.

SmartMitigate is designed around real operating requirements: long attacks, latency-sensitive applications, packet inspection and customer-specific filtering.

Inline processing

Traffic is inspected continuously without waiting for manual diversion.

Attack visibility

Review attack history, packet samples and filter actions through the portal or API.

Packet samples

Inspect captured traffic independently when deeper analysis is required.

Multiple protocols

Coverage for TCP, UDP, ICMP, GRE and IPv6 traffic.

Game and voice

Profiles for TeamSpeak, FiveM, Minecraft, Source-engine traffic and other services.

Custom mitigation

Policies can be adapted to unusual or high-risk workloads.

Coverage

What the platform mitigates.

SMARTNET focuses on network-layer and transport-layer attacks. Application-layer abuse that looks like legitimate user behaviour requires controls inside the application.

Supported attack types

  • IPv4 and IPv6 floods
  • UDP floods
  • TCP floods
  • ICMP floods
  • Other protocol floods
  • Resource exhaustion attacks
  • Amplification floods
  • PCAP replay attacks
  • New attack patterns where standard countermeasures are insufficient

Not fully covered

  • Layer 7 HTTP and HTTPS floods
  • Real application bot traffic such as Minecraft bots
  • Application logic abuse that resembles legitimate users

These attacks must be handled at the application or reverse-proxy layer rather than by the network mitigators.

SmartMitigate

Application-specific filtering for high-risk services.

SmartMitigate applies strict TCP and UDP authentication for game, voice and other public-facing services.

For TCP applications, permanent protection is recommended. Activating a different traffic path only after an attack begins can interrupt existing sessions.

Permanent protection

UDP traffic and selected TCP ranges can remain on SmartMitigate continuously, avoiding a mid-attack path change.

Custom mitigation profiles

Profiles can be developed for specific applications. Broadly useful filters may be added without charge; complex one-off logic may require paid development.

Source whitelisting

LPM-based source whitelisting is supported. Whitelisted traffic can still be constrained if the source becomes part of an attack.

SmartRules

Customers can control mitigation behaviour for specific destination IPs and services through the DELTA interface.

Protected applications

Supported game, voice and VPN ranges.

Applications should use the assigned ranges. Mixing unrelated traffic into application-specific ranges reduces the accuracy of protocol-aware mitigation.

UDP ranges

FiveM: 30000–32000Factorio: 34100–34200TeamSpeak 3: 9000–9999Valve Source: 27000–28000Minecraft Bedrock: 19100–19200Palworld: 8200–8300SCP SL: 7100–7200Rust: 28015–28100BeamMP: 40140Hytale / QUIC: 5520–5620OpenVPN: 1194–1294WireGuard: 51820–51920

TCP ranges

FiveM: 30000–32000Minecraft Java: 25565–26000SSH: 22HTTP: 80HTTPS: 443

Permanent SmartMitigate ranges

UDP traffic and FiveM TCP traffic on ports 30000–32000 are currently routed through SmartMitigate permanently.

Traffic policy

Rate limits and default protocol handling.

Some traffic classes are constrained during attacks to protect the affected service and the wider network.

Traffic that may be rate limited

  • TCP traffic
  • UDP traffic
  • DNS traffic per destination IP

Public resolvers such as 1.1.1.1, 8.8.8.8 and 9.9.9.9 receive higher priority during DNS-related attacks.

Blocked by default

  • IPv4 GRE traffic unless explicitly whitelisted
  • Non-IP protocol traffic except protocols 1, 4, 6 and 17

GRE and uncommon protocols require known source and destination pairs. GRE tunnels can be whitelisted through SmartRules.

Capacity

Mitigation capacity and operating limits.

Each customer receives a defined guaranteed baseline. Larger attacks are still mitigated where the network can absorb them safely.

Included baseline

Up to 1 Tbps and 1 Gpps of mitigation capacity is included regardless of the monthly recurring charge.

Above the baseline

Larger attacks are not automatically blackholed. SMARTNET may request more information or propose a higher-capacity service design.

Best-effort operation

Mitigation above the guaranteed baseline is best effort. Traffic may be discarded when an event materially threatens network stability.

GRE delivery

Useful for remote protection, but not ideal for every service.

GRE is a straightforward way to receive protected traffic from SMARTNET. For highly latency-sensitive services, a physical interconnect is normally the better design.

MikroTik GRE is not recommended

Many MikroTik platforms cannot process high-rate GRE traffic reliably. SMARTNET does not provide support for MikroTik-based GRE endpoints.

Cross-continent GRE is not recommended

Endpoints outside Europe introduce additional latency, congestion domains and troubleshooting complexity.

Physical interconnect for critical services

Game, voice and other latency-sensitive platforms should use a direct handoff where possible.

Offers

DDoS protection delivery options.

Mitigation can be delivered through GRE, a direct cross-connect or a custom integrated network design.

GRE tunnel

Remote protected delivery
  • BGP or static routing
  • IPv4 and IPv6
  • Redundant setup
  • /30 IPv4 and /128 IPv6
  • 1 Gbps 95/5 clean traffic included
  • 24/7 support
260 € / month

Cross-connect

Direct physical delivery
  • BGP or static routing
  • IPv4 and IPv6
  • Jumbo-frame ready
  • Redundant setup
  • 1, 10, 25 or 40G ports
  • Starting from 1 Gbps 95/5
  • 24/7 support
170 € / month

Custom solution

Integrated deployment
  • Fully managed design
  • Custom routing and filtering policy
  • Multiple locations or delivery models
  • For larger or unusual workloads
  • Direct engineering engagement
Custom pricing
Visibility

Traffic insight during and outside attacks.

Customers can review attacks, packet samples and filtering activity through the DELTA customer portal.

SMARTNET DDoS dashboard overview

Assisted filter development

Packet captures and traffic analysis support the development of filters against replay attacks and new attack patterns.

Filter analysis
Benefits

Operational benefits.

Protection is integrated with the same network, portal and engineering team used for connectivity services.

  • Time to mitigate under 10 seconds
  • Optimised for latency-critical applications below 0.2 ms
  • Pay for clean traffic only
  • Portal and REST API attack reporting
  • BGP, GRE, Layer 1 and Layer 2 delivery
  • Custom zones per IP
  • Game protection for Minecraft, FiveM and Source-engine services
  • Voice protection for TeamSpeak and Mumble
  • UDP, TCP, GRE and ICMP coverage
  • Amplification pre-filters
  • New attack-pattern detection
  • Flexible custom BPF rules
FAQ

DDoS protection questions.

Details about pricing, SmartRules, supported traffic and mitigation behaviour.

No. The mitigation infrastructure is expensive to operate, and the minimum price allows SMARTNET to provide a meaningful capacity baseline and direct support without overselling the platform.
Yes. SmartRules in the DELTA customer interface can control mitigation behaviour for specific destination IPs and services.
Permanent SmartMitigate, rate-limit mode and UDP ephemeral-port filtering are currently supported.
It should be enabled for critical TCP services and high-risk target IPs. UDP traffic is already diverted through SmartMitigate by default.
No. Layer 7 HTTP and HTTPS attacks must be handled at the application, reverse-proxy or CDN layer.
GRE can be whitelisted and protected, but a physical interconnect is preferred for latency-critical services.
Excessive or continuous attack testing against rented address space is not permitted. Testing must be coordinated with SMARTNET in advance.
Urgent requests should be opened through DELTA and should include the affected service, start time and MTR or WinMTR data where relevant.

Discuss a protection deployment.

Tell us the service, traffic profile, delivery model and expected attack characteristics.