sales@as203446.net

SmartMitigate

DDoS Protection via GRE

Keep your servers with their current provider and use SMARTNET to filter incoming attacks. We deliver the filtered traffic to your router over a GRE tunnel.

Network and data centre infrastructure

How the tunnel works

Route your protected prefixes through SMARTNET so incoming traffic reaches our filters first. We discard the packets identified as attacks and send the accepted traffic to your router inside the GRE tunnel.

Traffic enters SMARTNET

Protected prefixes are routed to SMARTNET by BGP or static routing before mitigation.

Attacks are filtered

Network-layer and transport-layer attacks are filtered before traffic is forwarded to the customer network.

Traffic is returned through the GRE tunnel

Accepted packets are encapsulated and sent to the configured GRE endpoint.

Keep your existing hosting provider

GRE is an option when your equipment is at another provider and you cannot take a direct cross-connect to SMARTNET.

Your equipment stays at its existing location; there is no need to install a router in one of our racks.

You will need your own ASN and routable prefixes for the protected network.

Incoming traffic for the protected IPv4 prefixes is routed through SMARTNET before it reaches your site.

Review attacks in DELTA and contact us by ticket when you need help with the service.

Router and tunnel configuration

Check that your router can forward the expected amount of GRE traffic. The extra tunnel headers also need to be allowed for in your MTU and TCP MSS settings.

Routing

  • BGP or static routing
  • Customer-owned or routed IP space
  • IRR route objects and RPKI ROAs recommended
  • Protected prefixes

Tunnel endpoint

  • Stable endpoint connectivity
  • Sufficient CPU for GRE encapsulation
  • Correct MTU / MSS handling
  • Router capable of expected throughput

Traffic profile

  • Expected clean traffic commit
  • Main protocols and ports
  • Game / voice / VPN workload details
  • Known attack history if available

Support

  • DELTA customer portal
  • Ticket contact for routing changes
  • MTR / WinMTR for troubleshooting
  • Affected service and destination

Technical limits of GRE

The tunnel uses the IP path between your router and ours. Its performance depends on that path and on the forwarding capacity of your GRE endpoint.

Latency-sensitive services

For latency-sensitive services, a direct cross-connect is normally preferable. GRE adds encapsulation and depends on the IP path between both endpoints.

MikroTik GRE is not recommended

Many MikroTik routers are not able to handle GRE traffic above 1 Gbps reliably. We do not provide support for performance issues caused by MikroTik-based GRE endpoints.

Endpoint location

SMARTNET does not recommend GRE endpoints outside Europe because the longer path adds latency and another failure domain.

Traffic covered by GRE protection

The mitigation scope is unchanged when GRE is used. Protection covers network and transport layers, not Layer 7 application traffic.

GRE tunnel pricing

The monthly price below covers the GRE service and the listed clean-traffic allowance. Contact us if you need a larger commitment or more tunnels.

Protected GRE tunnel

260 €/ month
Clean traffic
1 Gbps included, billed at the 95th percentile
Routing
BGP or static routing · IPv4 and IPv6
Tunnel addresses
/30 IPv4 and /128 IPv6
DDoS filtering
SmartMitigate; filtered traffic delivered over GRE
Attack reports
DELTA customer portal
Enquire about a GRE tunnel

Additional GRE options

  • Higher clean-traffic commit
  • Multiple tunnels
  • Custom routing policy
  • Review of normal and attack traffic
Discuss your requirements

Direct cross-connect

A physical connection avoids the additional GRE path and is preferable for latency-sensitive game and voice services.

1G, 10G, 25G and 40G ports.

Cross-connect options

Contact

Contact sales