Large-scale absorption
Tbps-scale scrubbing capacity withstands massive attacks.
Attack traffic is filtered out and only legitimate traffic reaches your servers. Inline always-on protection covers servers inside the LETO network, and Remote Protection covers servers elsewhere.
Overview
DDoS protection comes as two products. Inline always-on protection covers servers inside the LETO network, and Remote Protection covers servers in other data centers or clouds. Either way, abnormal traffic is filtered out and only legitimate traffic is passed on.
Tbps-scale scrubbing capacity withstands massive attacks.
Servers on the LETO network, such as instances and bare metal, come with basic protection. Inline always-on protection and Remote Protection are separate products you apply for.
Covers everything from volumetric to application-layer attacks.
24/7 detection and mitigation blocks attacks automatically.
Monitor attacks and mitigation activity in real time.
Products
Mitigation equipment sits in line in front of servers inside the LETO network. All traffic passes through it at all times before reaching the server.
Good for
Protects servers in other data centers or clouds without moving them. Traffic passes through the clean zone and then reaches the origin over a GRE tunnel.
Good for
Choose whether traffic always passes through the clean zone or only when an attack is detected.
All traffic passes through the clean zone at all times
Good forServices that are attacked often
The route changes only when an attack is detected
Good forWhen you want to keep the usual route in normal times
Either way, legitimate traffic passes without added delay.
How it works
Attack traffic is scrubbed in the Clean Zone, and only clean traffic reaches your origin.
All inbound traffic is routed into the LETO Clean Zone.
L3/4 and L7 analysis identifies and blocks attack traffic.
Only clean traffic is sent to the server. Remote Protection delivers it to the origin over a GRE tunnel.
Coverage
Attacks that saturate bandwidth and connections to block the path to the server.
Examples
Attacks that flood the application with requests that look legitimate until it is exhausted.
Examples
Features
01
Attacks are detected and mitigated automatically around the clock, and our security operations team takes over for large ones.
02
After an attack ends you get a report with its type, scale and the response taken.
03
Your origin server IP is never exposed to attackers.
04
Just connect a GRE tunnel. No server migration or IP change needed.
Use cases
Keep game services (frequent DDoS targets) running without interruption.
Ensure continuity for finance and public services where availability is critical.
Keep high-traffic media and e-commerce stable even under attack.
Protect hosting and IDC infrastructure that serves many customers.
FAQ
What people check most before putting the clean zone in front of a service.
If your servers are inside the LETO network, choose Inline always-on protection. If they are in another data center or cloud, choose Remote Protection.
No. Servers inside the LETO network are protected as they are with Inline always-on protection, and servers elsewhere only need a GRE tunnel with Remote Protection.
This is a choice within Remote Protection. Always-on keeps every packet going through the clean zone; on-demand switches the route only when an attack is detected. Either way, legitimate traffic passes without added latency. Choose always-on if attacks are frequent, on-demand if you prefer to keep your normal route day to day.
Yes. Coverage runs from volumetric L3/4 floods through to application-layer attacks.
Only attack traffic is filtered out, so the impact on real users stays minimal. You can watch the attack and the mitigation live on the dashboard, and you get a report of the type, scale and response afterwards.
This applies to Remote Protection. No. What is visible from outside is the clean zone address; traffic reaches the origin only through the GRE tunnel.
Basic protection is included. Inline always-on protection and Remote Protection are separate products, priced once we know the range you want protected and the scale of attack you expect.
Tell us the service and bandwidth to protect, and we'll propose an optimal defense setup.