
Protect your origin with the DDoS Clean Zone
Attack traffic is scrubbed in the LETO Clean Zone, and only clean traffic is delivered to your origin over a GRE tunnel — no server migration or IP change required.
Tbps
Tbps-scale absorption
GRE
Off-path GRE
24/7
24/7 detection & mitigation
Absorb the attack, keep the service running
The DDoS Clean Zone is off-path protection that filters malicious traffic in front of your network. It absorbs large attacks without changing your origin, and forwards legitimate traffic with no added latency in normal times.
No origin change
Just connect a GRE tunnel — no server migration or IP change needed.
Large-scale absorption
Tbps-scale scrubbing capacity withstands massive attacks.
Always-on mitigation
24/7 detection and mitigation blocks attacks automatically.
How it works
Attack traffic is scrubbed in the Clean Zone, and only clean traffic reaches your origin.
Attack traffic arrives
All inbound traffic is routed into the LETO Clean Zone.
Clean Zone scrubbing
L3/4 and L7 analysis identifies and blocks attack traffic.
Clean traffic delivered
Only scrubbed, legitimate traffic is delivered to your origin via the GRE tunnel.
Protecting services like these
Game servers
Keep game services — frequent DDoS targets — running without interruption.
Finance & public sector
Ensure continuity for finance and public services where availability is critical.
Media & commerce
Keep high-traffic media and e-commerce stable even under attack.
Hosting & IDC
Protect hosting and IDC infrastructure that serves many customers.
From monitoring to response, protected 24/7
A dedicated operations team monitors attacks around the clock and takes responsibility for shielding your origin and minimizing impact on legitimate traffic.
The security operations team continuously watches for attack signals and responds immediately.
Hide your origin IP and deliver only scrubbed, legitimate traffic through the GRE tunnel.
Only attack traffic is selectively blocked, minimizing impact on legitimate users.
Reports on attack type, scale, and response support post-incident analysis.
Key features
Off-path
Leave your origin infrastructure untouched — only the traffic path goes through the Clean Zone.
L3/4 & L7 protection
Covers everything from volumetric to application-layer attacks.
Always-on or on-demand
Choose always-on protection or automatic failover on attack detection.
Origin IP masking
Your origin server IP is never exposed to attackers.
Real-time dashboard
Monitor attacks and mitigation activity in real time.
24/7 response
Our security operations team handles large attacks year-round.
Be ready before the attack
Tell us the service and bandwidth to protect, and we'll propose an optimal defense setup.