Scrub attack traffic, keep your service up
Filter volumetric and protocol-based DDoS attacks in an always-on scrubbing layer; only clean traffic reaches your infrastructure. Standard protection is free on all resources.
On quoteA quote for your needs
The exact price is set by your needs and scale. Get a quote or schedule a meeting with your account manager.
Multi-layer protection that kicks in the moment an attack starts
Traffic is under constant inspection; when an attack starts it is filtered without waiting for rerouting.
High-Gbps SYN floods and amplification attacks are absorbed at backbone capacity.
Rate limits and behavior-based rules for HTTP floods and slow attacks.
Abnormal traffic patterns are detected automatically; mitigation begins without waiting for human intervention.
Scrubbing removes only malicious traffic; real users have uninterrupted access.
For each incident the vector, duration and mitigation summary are reported in the panel.
Frequently asked questions about DDoS Protection
Yes. Always-on L3/L4 standard protection is on by default on all Tres resources and requires no extra charge. For higher capacity, L7 rules and a guaranteed SLA you move to a monthly tier.
Scrubbing aims to remove only attack traffic; real user requests keep getting through. When aggressive rules are needed they are tuned to minimize impact.
No. We do not bill attack traffic as if it were your legitimate usage; the monthly tier fee you pay covers the scrubbing capacity.
On the Enterprise tier we can route your own resources through our scrubbing layer via routing (BGP) or a proxy method; we clarify the scope in the quote.
Scrubbing is always on; because traffic is under constant inspection, when an attack starts mitigation is applied without waiting for rerouting. Rule activation time is measured in seconds.
Volumetric attacks are absorbed on our network with 3.2 Tbit/s of scrubbing capacity. The appropriate tier and guaranteed SLA are set with a quote based on your needs.
Scrubbing targets malicious traffic; rules are fine-tuned so as not to block legitimate users and are adapted with engineer support when needed.