Always-on scrubbing. On every port. At no extra cost.BETA
Every packet entering the Joy network is analysed in real time. When an attack starts, the affected addresses are diverted to the scrubbing centre automatically, attack traffic is dropped and legitimate traffic is delivered, with no ticket, no phone call and no traffic cap. It is included on every cloud server, dedicated server and colocation port; for prefixes hosted elsewhere, Virtual Connect brings them under the same protection.
What happens during an attack.
- 01
Every flow is scored
Joy's traffic analysis watches source, destination, ports and volume on every border router in real time and scores anomalies as they appear.
- 02
Diversion without a human
When a score crosses the threshold, the affected prefix is diverted to the scrubbing centre in Mumbai automatically, in seconds.
- 03
Attack traffic is dropped
Volumetric floods, amplification (DNS, NTP, SSDP, memcached), SYN/ACK storms and L7 request floods are filtered. Custom rules for game and other protocols are added by ticket.
- 04
Legitimate traffic is delivered
Real users reach your server as before, on the same address. Nothing changes on your side.
- 05
Elsewhere too
With Virtual Connect you announce your prefixes to AS152565 over BGP inside a GRE tunnel; attacks are scrubbed at our edge and clean traffic is delivered to your router anywhere.
Free where you are. Bought where you are not.
| Offer | Price | For whom |
|---|---|---|
| On-network protection | included | Every cloud server, dedicated server and colocation port on AS152565 |
| DDoS-protected transit | $700 / Gbps / mo | Transit customers announcing their own prefixes |
| Virtual Connect (GRE) | from $200 / mo | Prefixes hosted at another provider: announce to AS152565 over BGP inside GRE, clean traffic delivered to your router |
| Blackhole | included | Transit customers: community 152565:666 on a /32 or /128. Cloud-server customers: Urgent ticket, applied within minutes |
| Custom protocol rules | by ticket | Gaming and other custom protocols |
Game servers
Attacks against game ports are the most common we see; rules for popular protocols exist and new ones are added by ticket.
Sites and APIs
L7 request floods are filtered before they reach your web server; the CDN in front adds a second layer.
Your own prefixes
DDoS-protected transit for operators; blackhole a single address anywhere with one community.
Servers at another provider
Virtual Connect protects prefixes you host anywhere, delivered clean over GRE.
Is DDoS protection included with my server?
Yes: always-on volumetric and L3–L7 filtering on every cloud server, dedicated server and colocation port on AS152565, at no extra cost and with no traffic cap.
Can I protect servers that are not at Joy?
Yes, with Virtual Connect: you announce your prefixes to AS152565 over BGP inside a GRE tunnel, attacks are scrubbed at our edge and clean traffic is delivered to your router anywhere. Pricing starts at $200.
How long are flow records kept?
Thirty days, for attack detection and traffic engineering. See the Privacy Policy.
Protection is a property of the network, not a product you forgot to buy.