Infrastructure DDOS Protection
With Generic Routing Encapsulation (GRE) tunneling and leveraging Border Gateway Protocol (BGP) routing, infrastructure protection is an on-demand security service that safeguards critical network infrastructure from volumetric and protocol-based DDOS attacks, such as UDP, SMTP or SYN Floods, executed directly or via DNS/NTP amplification. Infrastructure protection complements Incapsula’s other CDN-based services to provide web ops with a comprehensive solution that complete protection from all DDOS threats.
- Complete DDOS protection for all types of services (UDP/TCP, SMTP, FTP, SSH, VoIP, etc.)
- GRE tunneling for smooth on-demand onboarding
- DDOS protection for entire subnets or Individual IP addresses
- Complete protection against direct-to-IP DDOS attacks
- Enabled by Incapsula’s Behemoth scrubbing servers
Infrastructure Protection for Subnets
Infrastructure protection helps you protect all elements of your critical infrastructure (e.g., web, email, FTP) across entire subnet ranges.
In the event of an attack, traffic is rerouted through Incapsula’s scrubbing centers using BGP announcements. From that point on, Incapsula acts as the “ISP” and advertises all protected IP range announcements.
All incoming network traffic is inspected and filtered, and only legitimate traffic is securely forwarded to the enterprise network via GRE tunneling.