Overview
Your entire network can be routed via our global Threat Protection Centers (TPCs), which protect against Network DDoS attacks and known bad actors (IP Reputation). Bad actor’s Source IPs are added to our IP Reputation feed due to attacks they’ve previously attempted against any of our customers or because of recorded malicious hits in our Global Sensor Network.
Communication between your network and our Threat Protection Centers can take place over Generic Routing Encapsulation (GRE) or Private Network Interconnect (PNI). Traffic goes in via the Threat Protection Center for the network we protect, and a direct server response takes place on the return traffic using your transit link (ISP).
Benefits of Routed DSR
Protect your whole network (minimum /24 or /48 prefixes)
- Protection from DDoS attacks (Layer 3 & 4)
- Protection from known bad actors (IP Reputation)
- Always On Protection
Routed-To-Proxy
Optionally, you can also allocate IPs from your Routed DSR to be routed via an HTTP Proxy. This way, you can benefit from the broad network layer protection on your subnet while having Geo-fencing and Application layer protection for IPs used for HTTP/S services. This service is called Routed-to-Proxy.
If you require a Routed-To-Proxy service, please contact support@baffinbay.com or your Customer Success Advisor and specify the Customer Anycast IP from your subnet that should be allocated for creating the HTTP Proxy.
Please be aware that we pick up ALL traffic towards the selected IP, but only process traffic with the destination port(s) you have configured. The rest will be dropped. This can cause issues if there are multiple services running on the IP or if it’s used for outgoing connections. In that scenario, the return traffic will be dropped by us.
Benefits of Threat Protection Routed-To-Proxy (HTTP):
- All benefits of an HTTP Proxy
- Use your own IPs - No DNS changes are needed, therefore no downtime