← Back to Blog

Remote DDoS Protection over a GRE Tunnel from Amsterdam: Your Prefixes on GSL, Live in Hours

Published · by RS Computers

DDoS protection IP transit BGP

Remote DDoS protection over a GRE tunnel lets you keep your servers and routers where they are and still have your IP prefixes filtered by a large protected network. You build a tunnel from your router to our edge at Qupra Datacenter in Amsterdam, we run a BGP session through it, and your prefixes are announced on Global Secure Layer (GSL, AS137409). Attack traffic is filtered on GSL's network before it ever reaches your link, and clean traffic arrives through the tunnel. We deliver it from 500 Mbit/s up to 10 Gbit/s of clean traffic, and a tunnel is usually live within 2 to 4 hours of receiving your details.

In short:

How remote DDoS protection over a tunnel works

A volumetric attack wins by filling the pipe in front of your server. Filtering on your own router does not help once your uplink is already full. Remote protection moves the fight upstream, onto a network with far more capacity than any single site:

  1. You build a GRE tunnel from your router (or a Linux server running BIRD or FRR) to our edge router at Qupra Datacenter in Amsterdam.
  2. We bring up a BGP session inside the tunnel, and your prefixes are announced to the internet on GSL's network.
  3. Traffic to your addresses now enters GSL first, at the exchange or carrier nearest to the sender, and passes through GSL's filtering.
  4. The clean part travels to Amsterdam and down the tunnel to you. Attack traffic is dropped long before it gets near your link.

Your outbound traffic can leave through the tunnel too, so replies keep the same protected path, or through your local uplink if you prefer. Because the tunnel runs over your existing internet connection, it works from any data centre, office or country, without new hardware or cabling.

What you get

ItemRemote DDoS protection over GRE
Where it landsOur PoP at Qupra Datacenter, Amsterdam
Clean capacityFrom 500 Mbit/s up to 10 Gbit/s
UpstreamGlobal Secure Layer (AS137409), with inline DDoS filtering
RoutingBGP over the tunnel, IPv4 and IPv6, your own ASN and prefixes
Your ASN under GSLAvailable: we add your ASN directly in GSL's portal
Time to go liveUsually 2 to 4 hours after we have your ASN, prefixes and tunnel endpoint
PriceQuoted per network on Telegram or by email, with flexible terms

The network behind it: GSL in numbers

Protection is only as strong as the network that absorbs the attack. Global Secure Layer is a Brisbane-based transit provider built around its own inline mitigation system, which it calls Goliath. Its own pages state that it can mitigate an attack in under one second and that it peers with more than 3,500 networks.

Public routing data shows the scale. According to bgp.tools, GSL is connected to 82 internet exchanges with roughly 9.9 Tbit/s of exchange ports between them, buys transit from carriers including Cogent, Lumen, GTT, Zayo and NTT, and serves around 250 networks directly. In Amsterdam alone it has 100 Gbit/s ports at AMS-IX, NL-ix, LSIX and Frys-IX, and in Frankfurt a 400 Gbit/s port at DE-CIX. Attack traffic is spread across all of that before it can reach your tunnel.

GSL's filtering works in two stages, described in its Creatia documentation. Level 1 handles volumetric floods and amplification with heuristics and a SYN proxy for TCP. Level 2 is a per-prefix firewall of custom rules that can accept, drop or rate-limit traffic. Prefixes carried over a GRE tunnel are always filtered inline, so there is no detection delay before scrubbing begins.

Your ASN directly under GSL

Most protected-tunnel services announce your prefixes behind the reseller's own network, so the provider's ASN sits between you and the protected upstream. We can do it differently: your ASN can be added directly under GSL in GSL's Creatia portal, so your prefixes are announced straight to GSL (AS137409) and the path does not go through ours.

That keeps your routing clean. Looking glasses and route collectors show GSL as your upstream, filtering applies to your prefixes exactly as registered, and your announcements follow your own route objects and RPKI records. You still deal with us for setup, changes and support, so you get a person on Telegram instead of a ticket queue.

Why take it from a direct transit provider

RS Computers connects to GSL directly in Amsterdam. Buying protection from a direct customer rather than a reseller of a reseller has practical advantages:

What you need

Plan for the tunnel overhead. On a normal 1500 byte path, GRE over IPv4 adds 24 bytes, a 20 byte outer IPv4 header plus the 4 byte GRE header defined in RFC 2784, which leaves an MTU of 1476 inside the tunnel. Clamp TCP MSS to match, 1436 for IPv4, and we check both ends with you when the session comes up. Your own uplink to Amsterdam also sets the ceiling for clean traffic, so a 10 Gbit/s service needs a site with at least that much bandwidth.

How to order

  1. Message us on Telegram or email info@rscomputers-ks.com with your ASN, the prefixes to protect, the clean capacity you need and the public IP of your tunnel endpoint.
  2. We check your route objects and ROAs and send a quote.
  3. Once you confirm, we send the tunnel and BGP details and add your ASN under GSL.
  4. You bring up the tunnel and session at your end. Most setups are live within 2 to 4 hours.

Frequently asked questions

What is remote DDoS protection over a GRE tunnel?

It is a service where your IP prefixes are announced from a protected network instead of your own, and clean traffic is delivered to you through a GRE tunnel. Attacks are absorbed and filtered upstream, on a network much larger than your own link, so your servers stay reachable without moving them.

Do I need my own ASN?

Yes, or IP space you are authorised to announce with matching route objects and RPKI records. Your ASN can then be added directly under GSL, so your prefixes are announced straight to GSL. If you are not sure your setup qualifies, message us and we will check it.

How quickly can the tunnel be live?

Usually within 2 to 4 hours after we have your ASN, prefixes and tunnel endpoint, and once your route objects and ROAs check out.

How much capacity can I get?

From 500 Mbit/s up to 10 Gbit/s of clean traffic over the tunnel. Your own uplink to Amsterdam has to carry it, so plan the site bandwidth accordingly.

How much does it cost?

Prices depend on the clean capacity and the number of prefixes, so we quote each network individually. Send your details on Telegram or to info@rscomputers-ks.com.

Start with a message

If your network is being hit, or you simply want a protected upstream before it happens, send us your ASN, prefixes and the capacity you need. We will tell you what fits, quote it, and in most cases have your tunnel and BGP session up the same day. For flat-rate transit without protection, see IP transit in Amsterdam.

← All articles

Chat on Telegram