DDoS Protection & Mitigation
Always-on and on-demand DDoS mitigation with 5 Tbps+ scrubbing capacity, BGP diversion or DNS-based protection, layer 3 to layer 7 coverage and a contractual time-to-mitigate under 60 seconds.

5 Tbps+
Global scrubbing capacity
< 60 s
Time-to-mitigate SLA
L3–L7
Attack coverage
What is DDoS Protection & Mitigation?
Dollu DDoS Protection & Mitigation absorbs volumetric, protocol and application-layer attacks before they reach your network, your applications or your voice and messaging infrastructure. Scrubbing centres at our London, Frankfurt, Amsterdam, Ashburn, Mumbai and Singapore PoPs - backed by partner capacity in further regions - provide more than 5 Tbps of aggregate mitigation, and because they sit on the Dollu backbone, clean traffic is returned to Dollu connectivity customers over the same private paths they already use. Attacks are stopped upstream, not at your firewall.
Two delivery models cover every kind of asset. Network protection uses BGP: in always-on mode your prefixes are announced through Dollu scrubbing permanently and every packet is inspected; in on-demand mode traffic flows normally and is diverted to scrubbing within seconds of detection, with clean traffic returned over GRE tunnels, a private cross-connect or directly onto your Dollu circuit. Web and API protection uses DNS: you point records at Dollu anycast proxies, which terminate TLS, absorb floods, apply web application firewall rules and forward legitimate requests to your origin.
Detection combines flow telemetry from the Dollu core, inline packet analysis at the scrubbing edge and application-layer behavioural baselines. Mitigation is automatic and layered: upstream ACLs and flowspec drop the obvious, stateful scrubbing handles SYN, UDP, DNS and NTP amplification, and application-layer engines separate real users from HTTP floods, slow-loris, API abuse and bot traffic. For carrier and voice customers we add SIP-aware profiles that recognise INVITE and REGISTER floods and protect SBCs and softswitches without dropping legitimate call setup.
Every event is documented. The portal shows attacks in real time - vectors, peak bits and packets per second, sources, mitigation actions and residual traffic - and generates a post-attack report suitable for management, insurers and regulators. Contractual time-to-mitigate is under 60 seconds for always-on and under five minutes for on-demand diversion, and our 24×7 security operations team is on the phone with you throughout a sustained attack.
Why choose Dollu for ddos protection.
The advantages of buying from a carrier that owns its network, interconnects and operations - rather than a reseller.
Mitigation measured in seconds
Always-on customers are protected continuously; on-demand customers see diversion and cleaning begin within seconds of detection, with a contractual time-to-mitigate rather than a best effort.
Capacity to absorb terabit attacks
5 Tbps+ of distributed scrubbing means multi-hundred-gigabit floods are absorbed without saturating your circuits or ours, and without collateral blocking of clean traffic.
Built for carriers and voice
Profiles tuned for SIP signalling, RTP media, SMPP and carrier interconnects, so an attack on your SBC or SMS gateway is stopped without dropping legitimate calls or messages.
Visibility during and after the event
Real-time dashboards, alerts and detailed post-attack reports show what happened, what was blocked and what got through, for engineering, management and compliance.
Same provider as your circuits
For Dollu DIA, MPLS and cloud customers, mitigation is upstream on the same backbone with clean return already in place - no tunnels to build, no third-party escalation.
Capabilities in detail.
Everything included with DDoS Protection & Mitigation - the platform features, options and controls you get from day one.
- 01
Always-on network protection
Your prefixes are announced via Dollu scrubbing at all times; every packet passes inline inspection with no diversion delay. Recommended for voice cores, payment systems and public-facing carrier infrastructure.
- 02
On-demand BGP diversion
Traffic flows normally until flow-based detection triggers diversion of the affected /24 or larger prefix; clean traffic returns via GRE, private cross-connect or directly onto your Dollu circuit. Customer-triggered diversion is also available.
- 03
DNS-based web and API protection
Anycast reverse proxies terminate TLS, absorb HTTP floods, enforce rate limits and WAF rules, challenge suspicious clients and forward clean requests to your origin, whose IP stays hidden.
- 04
Multi-layer mitigation engine
Flowspec and upstream ACLs, SYN and UDP flood defence, reflection and amplification filtering for DNS, NTP, SSDP, CLDAP and memcached, fragment handling, and application-layer behavioural analysis.
- 05
SIP, RTP and SMPP profiles
Signalling-aware inspection that distinguishes INVITE, REGISTER and OPTIONS floods from legitimate call setup, rate-limits per source, protects RTP port ranges and preserves carrier interconnect traffic.
- 06
Automatic and manual controls
Detection thresholds and mitigation templates per prefix or application, one-click diversion from the portal, emergency hotline to the security operations centre and change control on protection policies.
- 07
Reporting and forensics
Live attack view with vectors, pps/bps, geographic and ASN sources; post-attack PDF and JSON reports; sampled packet captures on request; monthly summary reports.
- 08
Integration with Dollu security services
Events feed Dollu MDR and SOC for correlation, and protection policies coordinate with Dollu managed firewall and SASE so mitigation and access controls act as one system.
How it works.
From first conversation to live traffic - a tracked, engineer-led onboarding with a named owner at every step.
- Step 01
Onboard
We register your prefixes or domains, verify ownership, agree detection thresholds and mitigation templates, and configure GRE tunnels, cross-connects or origin settings.
- Step 02
Baseline
Flow telemetry and application traffic are profiled for two to four weeks to establish normal patterns per prefix, protocol and application, reducing false positives.
- Step 03
Test
A controlled diversion and clean-return test confirms routing, tunnel MTU and application behaviour under mitigation. Runbooks and escalation contacts are finalised.
- Step 04
Protect
Always-on customers are inline immediately; on-demand customers are monitored continuously with automatic or one-click diversion. Reports and alerts flow to your team and, optionally, your SIEM.
Who uses this and why.
Typical deployments across carriers, enterprises, platforms and contact centres.
Carriers and voice providers
Protect SBCs, softswitches, SMS gateways and interconnect edges from signalling floods and volumetric attacks that would otherwise take down call and message delivery.
Banks and payment platforms
Always-on protection for internet banking, UPI and payment gateway endpoints where a minute of unavailability has regulatory and reputational consequences.
Gaming and streaming
Absorb attacks aimed at game servers, matchmaking and streaming origins that peak during events, with low-latency clean return so players are not affected.
E-commerce and SaaS
DNS-based protection with WAF and bot management for storefronts and APIs, keeping origins hidden and available through sales peaks and extortion campaigns.
Enterprises and public sector
Protect DIA and MPLS internet breakouts, VPN concentrators and public services with upstream mitigation on the same Dollu backbone that carries the traffic.
Technical & commercial specifications.
Key parameters at a glance. Ask us for the full service description and SLA document.
| Scrubbing capacity | 5 Tbps+ aggregate; six Dollu PoPs plus partner centres |
|---|---|
| Delivery | Always-on BGP, on-demand BGP diversion, DNS anycast proxy |
| Clean return | GRE, private cross-connect, direct on Dollu DIA/MPLS |
| Coverage | L3/L4 volumetric and protocol; L7 HTTP/S, DNS, SIP, SMPP |
| Time-to-mitigate | < 60 s always-on; < 5 min on-demand diversion (SLA) |
| Minimum prefix | /24 IPv4, /48 IPv6 for BGP; any hostname for DNS proxy |
| WAF | OWASP rules, custom rules, rate limiting, bot challenge |
| Reporting | Real-time portal, post-attack reports, SIEM/syslog export |
| Pricing | Flat monthly per prefix or domain; no per-attack or overage charges |
| Support | 24×7 security operations; P1 response ≤ 15 min; hotline during attacks |
How Security is priced.
Security services are priced per protected site or circuit, per user or per endpoint - and MDR by endpoint count or log volume. Assessments and penetration tests are fixed-scope projects.
We publish the model, not a public rate card - actual rates depend on destination, route class, volume and regulatory cost. See how every Dollu service is priced.
- DDoS and managed firewall per protected site or circuit
- SASE and zero trust per user
- MDR per endpoint or by log volume
- Assessments and penetration tests as fixed-scope projects
- 12–36 month terms on managed services
- Billing
- Monthly recurring in advance; projects invoiced on milestones
- Commitment
- 12–36 months for managed services; none for assessments
DDoS Protection - your questions answered.
The questions customers and carriers ask us most often before they interconnect. If yours is not here, our team answers within one business day.
Still have a question?
Ask our solutions teamRelated services.
Services customers commonly combine with DDoS Protection & Mitigation.
Get protected before the next attack.
Send us your prefixes or domains for a proposal within one business day; if you are under attack now, call the 24×7 NOC or email [email protected] and an engineer will begin emergency onboarding immediately.
