.
LETO
Off-path GRE protection

Protect your origin with the DDoS Clean Zone

Attack traffic is scrubbed in the LETO Clean Zone, and only clean traffic is delivered to your origin over a GRE tunnel — no server migration or IP change required.

Tbps

Tbps-scale absorption

GRE

Off-path GRE

24/7

24/7 detection & mitigation

Absorb the attack, keep the service running

The DDoS Clean Zone is off-path protection that filters malicious traffic in front of your network. It absorbs large attacks without changing your origin, and forwards legitimate traffic with no added latency in normal times.

No origin change

Just connect a GRE tunnel — no server migration or IP change needed.

Large-scale absorption

Tbps-scale scrubbing capacity withstands massive attacks.

Always-on mitigation

24/7 detection and mitigation blocks attacks automatically.

How it works

Attack traffic is scrubbed in the Clean Zone, and only clean traffic reaches your origin.

01

Attack traffic arrives

All inbound traffic is routed into the LETO Clean Zone.

02

Clean Zone scrubbing

L3/4 and L7 analysis identifies and blocks attack traffic.

03

Clean traffic delivered

Only scrubbed, legitimate traffic is delivered to your origin via the GRE tunnel.

Protecting services like these

Game servers

Keep game services — frequent DDoS targets — running without interruption.

Finance & public sector

Ensure continuity for finance and public services where availability is critical.

Media & commerce

Keep high-traffic media and e-commerce stable even under attack.

Hosting & IDC

Protect hosting and IDC infrastructure that serves many customers.

From monitoring to response, protected 24/7

A dedicated operations team monitors attacks around the clock and takes responsibility for shielding your origin and minimizing impact on legitimate traffic.

The security operations team continuously watches for attack signals and responds immediately.

Hide your origin IP and deliver only scrubbed, legitimate traffic through the GRE tunnel.

Only attack traffic is selectively blocked, minimizing impact on legitimate users.

Reports on attack type, scale, and response support post-incident analysis.

Key features

Off-path

Leave your origin infrastructure untouched — only the traffic path goes through the Clean Zone.

L3/4 & L7 protection

Covers everything from volumetric to application-layer attacks.

Always-on or on-demand

Choose always-on protection or automatic failover on attack detection.

Origin IP masking

Your origin server IP is never exposed to attackers.

Real-time dashboard

Monitor attacks and mitigation activity in real time.

24/7 response

Our security operations team handles large attacks year-round.

Be ready before the attack

Tell us the service and bandwidth to protect, and we'll propose an optimal defense setup.