Network · IP connectivity

Protected IPs where your infrastructure already is

clean traffic

We assign IPs with up to 6 Tbps mitigation and deliver them over a tunnel to your server, with any provider. The attack stays on our network.

6 Tbps Mitigation
4 túneles GRE · WG · VXLAN · L2TP
MAD Cross-connect
How it works

Three steps. No infrastructure move.

You migrate nothing: your servers stay where they are while we put the IPs and mitigation in front of them.

Assignment

We assign protected IPs

A dedicated range for you behind our mitigation network. All traffic to those IPs passes through filtering first.

Tunnel

We bring up the tunnel

GRE, WireGuard, VXLAN, or L2TP to your machine, or a physical cross-connect in Madrid. No new hardware or migrations.

Production

Your traffic arrives clean

The attack is filtered at the anycast PoP nearest its source; only legitimate traffic, forwarded from Bilbao, reaches your tunnel.

Mitigation network

Real-time global traffic filtering.

Hasta 6 Tbps de mitigación sobre la red anycast de Global Secure Layer. Cada ataque se filtra en el PoP más cercano a su origen y el tráfico limpio se reenvía a Bilbao.

Clean traffic 142 Gbps
Filtered attack 260 Gbps
Status Network stable
  • Clean traffic
  • Attack
  • Mitigated
  • 27 PoPs anycast · Global Secure Layer
  • BIO Bilbao · clean-traffic destination

Illustrative visualization of the mitigation network.

Live Anti-DDoS

When the attack arrives, it is already filtered.

This is what a flood being mitigated in real time looks like: the spike arrives, Global Secure Layer filters it at the nearest PoP, and only clean traffic reaches your protected IP.

UDP flood

Mitigating attack live UTC+1
Delivery type

Four tunnels and fibre in Madrid.

Choose how to receive your protected IPs: an IP tunnel to any provider or a physical cross-connect at our Madrid facilities.

WireGuard

A modern encrypted tunnel and our recommendation: the path between your server and our network stays protected end to end.

GRE tunnel

The simplest option: an IP tunnel, no physical installation, with support on virtually any system or router.

VXLAN

Layer 2 over IP: extend your network to ours and assign protected IPs as though they were another segment of your infrastructure.

L2TP

Compatibility with classic equipment. If your router or firewall already speaks L2TP, you need change nothing.

Physical cross-connect

Direct fibre in our Madrid facilities: the latency and capacity of a physical port, with no tunnel overhead.

MAD

Tunnels reduce effective MTU; we help you adjust it during setup.

Billing

Two models. You choose.

Pay for the volume your IPs move or the bandwidth you actually use. You can change model as your traffic profile changes.

By volume

By TB transferred

Every plan includes a monthly allowance; you pay for the traffic you move, with no surprises at the end of the month.

  • Allowance included with every plan.
  • Predictable cost for regular traffic.
  • Switch to the p99 model when needed.
By bandwidth

Mbps at the 99th percentile

Your traffic is measured every five minutes and the top 1% of peaks is discarded: you pay for the rest.

  • One-off peaks do not inflate your bill.
  • Designed for high, sustained traffic.
  • The standard for operators.
Planes

IPs protegidas. Precio cerrado.

Cuatro planes con mitigación de hasta 6 Tbps incluida. Entrega por túnel a cualquier proveedor o cross-connect en Madrid.

Entry

START

Protect a server you already have with another provider.

from19 €/ month
Includes
  • IPs protegidas1
  • Tráfico5 TB
  • Anti-DDoS6 Tbps incluido
  • EntregaTúnel o MAD
1 servidorJuegoWeb
Pedir START por Discord
Scale

SCALE

For platforms with several services and dedicated IPs.

from129 €/ month
Includes
  • IPs protegidas8
  • Tráfico50 TB
  • Anti-DDoS6 Tbps incluido
  • EntregaTúnel o MAD
Multi-servidorStreaming
Pedir SCALE por Discord
Custom

Custom

Custom ranges to assign however you need.

Contact us
Includes
  • IPs protegidasA medida
  • TráficoA medida
  • Anti-DDoS6 Tbps incluido
  • EntregaTúnel o MAD
Rangos a medidaOperadores
Pedir Custom por Discord

¿Tráfico alto y sostenido? Modelo Mbps p99 desde 0,80 €/Mbps·mes: consúltanos.

Use cases

Where IP connectivity fits.

Services already running with another provider that need real protection without migrating anything.

Gaming

Game servers with another provider

Your Minecraft, FiveM, or Rust stays where it is: players connect through the protected IP and the attack never reaches your machine.

Web

Websites and APIs on third-party VPS

Publish your website or API behind a protected IP without changing VPS. The origin IP stays out of the attacker’s reach.

Voice

VoIP y TeamSpeak

Voice services are frequent attack targets. With a protected IP, calls and rooms remain online during the attack.

On-premise

On-premise infrastructure

Servers in your office or own datacenter: the tunnel carries protected IPs to your network without relying on the local operator.

Frequently asked questions

Before you order.

What we are asked most about IP connectivity.

Does it work with any provider?
Yes. Any VPS, dedicated server, or cloud that can establish tunnels works: we set up GRE, WireGuard, VXLAN, or L2TP to your machine and protected IPs arrive through it. No migration is necessary.
How much latency does it add?
The path between your server and our Madrid network, plus tunnel overhead. It depends on where your infrastructure is: the closer it is to Madrid, the lower the added latency.
Can I use my own IPs?
That is IP transit: you establish a BGP session with us and announce your prefixes with your own ASN. IP connectivity is for when you do not have your own range and we assign one to you.
How is a DDoS attack mitigated?
Filtering runs on the Global Secure Layer anycast network: the attack enters at the PoP nearest its source, is cleaned there, and only legitimate traffic is forwarded to Bilbao. Your tunnel and IPs do not change; you need do nothing.
Which tunnel should I choose?
We recommend WireGuard: encrypted, fast, and easy to configure on any modern Linux. If your equipment does not support it or you already use GRE, VXLAN, or L2TP, we use the best fit.
How is it billed?
By TB transferred (each plan includes a monthly allowance) or Mbps at the 99th percentile: measured every five minutes, the top 1% of peaks is discarded and you pay for the rest. You can change model as your traffic profile changes.

Do you have your own ASN and range?

IP transit gives you upstream with the same included up-to-6-Tbps mitigation and delivery in Bilbao and Madrid.

View IP transit

Tell us where your infrastructure is and we will set up the tunnel.

Discord or WhatsApp. No forms or waiting.