What it is
A scrubbing center is filtering infrastructure placed between incoming traffic and the target. It separates attack traffic from legitimate traffic under load.
That means it needs enough bandwidth, packet processing capacity and filtering logic to absorb the attack while still forwarding valid traffic.
How traffic gets there
Traffic is usually redirected to the scrubbing center either inline or through a tunnel such as GRE. Once traffic arrives, the filtering path decides which packets should be dropped, rate-limited or forwarded.
The destination server or customer edge then receives only the traffic that survived the filtering process.
What a scrubbing center needs
- Sufficient bandwidth to absorb incoming attack traffic
- High packet processing capacity under small-packet floods
- Fast filtering logic for early decisions
- A forwarding path for legitimate traffic after filtering
Capacity and routing constraints
The filtering path must preserve legitimate traffic while processing the attack load.
State growth, lookup complexity, packet rate and forwarding overhead can become limiting factors even when sufficient link bandwidth is available.
Inline vs tunnel-based setup
Inline filtering keeps traffic on the mitigation path continuously. A tunnel-based setup allows the customer infrastructure to remain at its existing location.
Tunnel-based paths add encapsulation overhead and require correct MTU and routing configuration.
Purpose of a scrubbing center
A scrubbing center filters large packet floods upstream of the customer edge, reducing load on the target infrastructure.
Upstream placement provides additional bandwidth and packet-processing capacity before traffic reaches the customer network.
DDoS protection from SMARTNET
Connection options, filtering capabilities and service limits.
View DDoS protection