DDoS Protection for IDCs and Cloud Providers
Protect your customers — and your reputation.
The unique dilemma for IDCs and clouds
For IDCs and cloud providers, DDoS is not merely a technical issue — it is a business model issue:
- One tenant attacked, the whole facility suffers — when the upstream link saturates, your other customers go offline too, directly hurting renewals.
- Upstream blackhole policy you cannot control — your transit provider may null-route an entire IP block during a large attack, with no chance for you to explain.
- Customers expect protection — "do you have DDoS protection?" is now a standard pre-signing question.
- Building your own scrubbing is expensive — appliances, bandwidth reserves, and specialist staff are not economical for most IDCs.
What AwayDDoS offers IDCs and cloud providers
1. Whole-subnet tunnel protection
Using GRE / BGP tunnels, your facility's entire IP block is steered into our scrubbing centers — covering all ports and protocols at once with no per-customer configuration. Attacks are washed away before reaching your facility, so your upstream link is never saturated.
2. Per-tenant attack isolation
When one tenant becomes a target, scrubbing policies apply only to that tenant's IPs; all other tenants' traffic is completely unaffected. This solves the IDC's most painful problem: one bad actor ruining it for everyone.
3. Elastic wholesale scrubbing capacity
You do not need to build your own scrubbing infrastructure. Use AwayDDoS capacity on a wholesale basis and scale on demand — converting fixed costs into variable costs. Capacity is the combined power of our global nodes with no hard cap.
4. White-label protection services
Sell protection as your own product — we provide the backend capability while you own the customer relationship. This is a new revenue line that directly lifts ARPU.
Why IDCs partner with us
- No blackholing — we will not null-route your entire IP block to protect other customers. Understand the risk of blackholing
- Fixed pricing — predictable costs that make it easy to price your own product.
- 7×24 expert operations — a dedicated counterpart during attacks, so you are not facing it alone.
- Non-HTTP business supported — gaming, mail, and custom protocols covered as well.
- Flexible engagement — from one-off emergency steering to long-term wholesale partnerships.
A typical partnership architecture
The most common model: the IDC uses BGP announcements to steer its IP block into AwayDDoS scrubbing centers, and clean traffic is tunneled back into the facility. Your network topology and customer configurations remain completely unchanged, yet protection is live.
For a full comparison of tunnel mode against other onboarding methods, see the deployment comparison. To explore white-label and wholesale options, contact us.