GRE tunnel
- BGP or static routing
- IPv4 and IPv6
- Redundant setup
- /30 IPv4 and /128 IPv6
- 1 Gbps 95/5 clean traffic included
- 24/7 support
Inline network and transport-layer mitigation for hosting, game, voice and infrastructure services, operated directly on the SMARTNET network.
SmartMitigate is SMARTNET's own DDoS mitigation platform and works alongside the existing vendor-based mitigation cluster.
Traffic is inspected continuously. Countermeasures include SYN validation, TCP and UDP authentication, protocol-aware filtering and attack signatures that identify harmful traffic without treating ordinary geography or customer traffic as the attack.
SmartMitigate is designed around real operating requirements: long attacks, latency-sensitive applications, packet inspection and customer-specific filtering.
Traffic is inspected continuously without waiting for manual diversion.
Review attack history, packet samples and filter actions through the portal or API.
Inspect captured traffic independently when deeper analysis is required.
Coverage for TCP, UDP, ICMP, GRE and IPv6 traffic.
Profiles for TeamSpeak, FiveM, Minecraft, Source-engine traffic and other services.
Policies can be adapted to unusual or high-risk workloads.
SMARTNET focuses on network-layer and transport-layer attacks. Application-layer abuse that looks like legitimate user behaviour requires controls inside the application.
These attacks must be handled at the application or reverse-proxy layer rather than by the network mitigators.
SmartMitigate applies strict TCP and UDP authentication for game, voice and other public-facing services.
For TCP applications, permanent protection is recommended. Activating a different traffic path only after an attack begins can interrupt existing sessions.
UDP traffic and selected TCP ranges can remain on SmartMitigate continuously, avoiding a mid-attack path change.
Profiles can be developed for specific applications. Broadly useful filters may be added without charge; complex one-off logic may require paid development.
LPM-based source whitelisting is supported. Whitelisted traffic can still be constrained if the source becomes part of an attack.
Customers can control mitigation behaviour for specific destination IPs and services through the DELTA interface.
Applications should use the assigned ranges. Mixing unrelated traffic into application-specific ranges reduces the accuracy of protocol-aware mitigation.
UDP traffic and FiveM TCP traffic on ports 30000–32000 are currently routed through SmartMitigate permanently.
Some traffic classes are constrained during attacks to protect the affected service and the wider network.
Public resolvers such as 1.1.1.1, 8.8.8.8 and 9.9.9.9 receive higher priority during DNS-related attacks.
GRE and uncommon protocols require known source and destination pairs. GRE tunnels can be whitelisted through SmartRules.
Each customer receives a defined guaranteed baseline. Larger attacks are still mitigated where the network can absorb them safely.
Up to 1 Tbps and 1 Gpps of mitigation capacity is included regardless of the monthly recurring charge.
Larger attacks are not automatically blackholed. SMARTNET may request more information or propose a higher-capacity service design.
Mitigation above the guaranteed baseline is best effort. Traffic may be discarded when an event materially threatens network stability.
GRE is a straightforward way to receive protected traffic from SMARTNET. For highly latency-sensitive services, a physical interconnect is normally the better design.
Many MikroTik platforms cannot process high-rate GRE traffic reliably. SMARTNET does not provide support for MikroTik-based GRE endpoints.
Endpoints outside Europe introduce additional latency, congestion domains and troubleshooting complexity.
Game, voice and other latency-sensitive platforms should use a direct handoff where possible.
Mitigation can be delivered through GRE, a direct cross-connect or a custom integrated network design.
Customers can review attacks, packet samples and filtering activity through the DELTA customer portal.

Packet captures and traffic analysis support the development of filters against replay attacks and new attack patterns.

Protection is integrated with the same network, portal and engineering team used for connectivity services.
Details about pricing, SmartRules, supported traffic and mitigation behaviour.
Tell us the service, traffic profile, delivery model and expected attack characteristics.