Security & networking

DDoS Protection

Attack traffic is filtered out and only legitimate traffic reaches your servers. Inline always-on protection covers servers inside the LETO network, and Remote Protection covers servers elsewhere.

Overview

Absorb the attack, keep the service running

DDoS protection comes as two products. Inline always-on protection covers servers inside the LETO network, and Remote Protection covers servers in other data centers or clouds. Either way, abnormal traffic is filtered out and only legitimate traffic is passed on.

Large-scale absorption

Tbps-scale scrubbing capacity withstands massive attacks.

Basic protection is included

Servers on the LETO network, such as instances and bare metal, come with basic protection. Inline always-on protection and Remote Protection are separate products you apply for.

L3/4 & L7 protection

Covers everything from volumetric to application-layer attacks.

Always-on mitigation

24/7 detection and mitigation blocks attacks automatically.

Real-time dashboard

Monitor attacks and mitigation activity in real time.

Products

Choose by where your servers are

Inline always-on protection

Mitigation equipment sits in line in front of servers inside the LETO network. All traffic passes through it at all times before reaching the server.

Target
Instances, bare metal, colocation, IP Transit
Connection
Handled inside the LETO network, no tunnel
Protection mode
Always-on
Preparation
No server or IP changes

Good for

  • Services hosted with LETO
  • Services that are attacked often

Remote Protection

Protects servers in other data centers or clouds without moving them. Traffic passes through the clean zone and then reaches the origin over a GRE tunnel.

Target
Servers in other data centers or clouds
Connection
GRE tunnel
Protection mode
Always-on or on-demand
Preparation
No migration or IP changes

Good for

  • Services that are hard to move
  • When you want to keep the usual route in normal times

Always-on and on-demand in Remote Protection

Choose whether traffic always passes through the clean zone or only when an attack is detected.

Always-on

All traffic passes through the clean zone at all times

NormalInternetClean zoneOrigin
Under attackInternetClean zoneOrigin

Good forServices that are attacked often

On-demand

The route changes only when an attack is detected

NormalInternetOrigin
Under attackInternetClean zoneOrigin

Good forWhen you want to keep the usual route in normal times

Either way, legitimate traffic passes without added delay.

How it works

How it works

Attack traffic is scrubbed in the Clean Zone, and only clean traffic reaches your origin.

  1. 1Attack traffic arrives

    All inbound traffic is routed into the LETO Clean Zone.

  2. 2Clean Zone scrubbing

    L3/4 and L7 analysis identifies and blocks attack traffic.

  3. 3Clean traffic delivered

    Only clean traffic is sent to the server. Remote Protection delivers it to the origin over a GRE tunnel.

Coverage

From the network layer to the application layer

L3/4 volumetric attacks

Attacks that saturate bandwidth and connections to block the path to the server.

Examples

  • UDP flood
  • SYN flood
  • ICMP flood
  • DNS/NTP amplification

L7 application attacks

Attacks that flood the application with requests that look legitimate until it is exhausted.

Examples

  • HTTP flood
  • Slowloris

Features

From detection to report

  • 01

    Always-on response

    Attacks are detected and mitigated automatically around the clock, and our security operations team takes over for large ones.

  • 02

    Attack report

    After an attack ends you get a report with its type, scale and the response taken.

  • 03

    Origin IP masking

    Your origin server IP is never exposed to attackers.

  • 04

    No origin change

    Just connect a GRE tunnel. No server migration or IP change needed.

Use cases

Protecting services like these

  • Game servers

    Keep game services (frequent DDoS targets) running without interruption.

  • Finance & public sector

    Ensure continuity for finance and public services where availability is critical.

  • Media & commerce

    Keep high-traffic media and e-commerce stable even under attack.

  • Hosting & IDC

    Protect hosting and IDC infrastructure that serves many customers.

FAQ

Frequently asked questions

What people check most before putting the clean zone in front of a service.

  • If your servers are inside the LETO network, choose Inline always-on protection. If they are in another data center or cloud, choose Remote Protection.

  • No. Servers inside the LETO network are protected as they are with Inline always-on protection, and servers elsewhere only need a GRE tunnel with Remote Protection.

  • This is a choice within Remote Protection. Always-on keeps every packet going through the clean zone; on-demand switches the route only when an attack is detected. Either way, legitimate traffic passes without added latency. Choose always-on if attacks are frequent, on-demand if you prefer to keep your normal route day to day.

  • Yes. Coverage runs from volumetric L3/4 floods through to application-layer attacks.

  • Only attack traffic is filtered out, so the impact on real users stays minimal. You can watch the attack and the mitigation live on the dashboard, and you get a report of the type, scale and response afterwards.

  • This applies to Remote Protection. No. What is visible from outside is the clean zone address; traffic reaches the origin only through the GRE tunnel.

  • Basic protection is included. Inline always-on protection and Remote Protection are separate products, priced once we know the range you want protected and the scale of attack you expect.

Be ready before the attack

Tell us the service and bandwidth to protect, and we'll propose an optimal defense setup.