Traffic enters SMARTNET
Protected prefixes are routed to SMARTNET by BGP or static routing before mitigation.
SmartMitigate
Keep your servers with their current provider and use SMARTNET to filter incoming attacks. We deliver the filtered traffic to your router over a GRE tunnel.

Route your protected prefixes through SMARTNET so incoming traffic reaches our filters first. We discard the packets identified as attacks and send the accepted traffic to your router inside the GRE tunnel.
Protected prefixes are routed to SMARTNET by BGP or static routing before mitigation.
Network-layer and transport-layer attacks are filtered before traffic is forwarded to the customer network.
Accepted packets are encapsulated and sent to the configured GRE endpoint.
GRE is an option when your equipment is at another provider and you cannot take a direct cross-connect to SMARTNET.
Your equipment stays at its existing location; there is no need to install a router in one of our racks.
You will need your own ASN and routable prefixes for the protected network.
Incoming traffic for the protected IPv4 prefixes is routed through SMARTNET before it reaches your site.
Review attacks in DELTA and contact us by ticket when you need help with the service.
Check that your router can forward the expected amount of GRE traffic. The extra tunnel headers also need to be allowed for in your MTU and TCP MSS settings.
The tunnel uses the IP path between your router and ours. Its performance depends on that path and on the forwarding capacity of your GRE endpoint.
For latency-sensitive services, a direct cross-connect is normally preferable. GRE adds encapsulation and depends on the IP path between both endpoints.
Many MikroTik routers are not able to handle GRE traffic above 1 Gbps reliably. We do not provide support for performance issues caused by MikroTik-based GRE endpoints.
SMARTNET does not recommend GRE endpoints outside Europe because the longer path adds latency and another failure domain.
The mitigation scope is unchanged when GRE is used. Protection covers network and transport layers, not Layer 7 application traffic.
The monthly price below covers the GRE service and the listed clean-traffic allowance. Contact us if you need a larger commitment or more tunnels.