Joy Services
All systems operational Sign in
JoyProductsDDoS Protection
Network

Always-on scrubbing. On every port. At no extra cost.BETA

Every packet entering the Joy network is analysed in real time. When an attack starts, the affected addresses are diverted to the scrubbing centre automatically, attack traffic is dropped and legitimate traffic is delivered, with no ticket, no phone call and no traffic cap. It is included on every cloud server, dedicated server and colocation port; for prefixes hosted elsewhere, Virtual Connect brings them under the same protection.

Included on every portNo traffic capAutomatic diversionVirtual Connect for prefixes elsewhere
01 How it works
Detect, divert, scrub, deliver

What happens during an attack.

  • 01

    Every flow is scored

    Joy's traffic analysis watches source, destination, ports and volume on every border router in real time and scores anomalies as they appear.

  • 02

    Diversion without a human

    When a score crosses the threshold, the affected prefix is diverted to the scrubbing centre in Mumbai automatically, in seconds.

  • 03

    Attack traffic is dropped

    Volumetric floods, amplification (DNS, NTP, SSDP, memcached), SYN/ACK storms and L7 request floods are filtered. Custom rules for game and other protocols are added by ticket.

  • 04

    Legitimate traffic is delivered

    Real users reach your server as before, on the same address. Nothing changes on your side.

  • 05

    Elsewhere too

    With Virtual Connect you announce your prefixes to AS152565 over BGP inside a GRE tunnel; attacks are scrubbed at our edge and clean traffic is delivered to your router anywhere.

02 Offers
Included or bought

Free where you are. Bought where you are not.

OfferPriceFor whom
On-network protectionincludedEvery cloud server, dedicated server and colocation port on AS152565
DDoS-protected transit$700 / Gbps / moTransit customers announcing their own prefixes
Virtual Connect (GRE)from $200 / moPrefixes hosted at another provider: announce to AS152565 over BGP inside GRE, clean traffic delivered to your router
BlackholeincludedTransit customers: community 152565:666 on a /32 or /128. Cloud-server customers: Urgent ticket, applied within minutes
Custom protocol rulesby ticketGaming and other custom protocols
03 Who it protects
GAMING

Game servers

Attacks against game ports are the most common we see; rules for popular protocols exist and new ones are added by ticket.

BUSINESS

Sites and APIs

L7 request floods are filtered before they reach your web server; the CDN in front adds a second layer.

NETWORKS

Your own prefixes

DDoS-protected transit for operators; blackhole a single address anywhere with one community.

ELSEWHERE

Servers at another provider

Virtual Connect protects prefixes you host anywhere, delivered clean over GRE.

04 Guarantees and limits
Coverage
every port on AS152565
Traffic cap
none
Diversion
automatic seconds
Layers
L3 – L7
Blackhole
152565:666 or Urgent ticket
Custom rules
by ticket
Flow records
30 days
Elsewhere
Virtual Connect from $200
05 Questions
Is DDoS protection included with my server?

Yes: always-on volumetric and L3–L7 filtering on every cloud server, dedicated server and colocation port on AS152565, at no extra cost and with no traffic cap.

Can I protect servers that are not at Joy?

Yes, with Virtual Connect: you announce your prefixes to AS152565 over BGP inside a GRE tunnel, attacks are scrubbed at our edge and clean traffic is delivered to your router anywhere. Pricing starts at $200.

How long are flow records kept?

Thirty days, for attack detection and traffic engineering. See the Privacy Policy.

Next step

Protection is a property of the network, not a product you forgot to buy.