Remote DDoS protection over a GRE tunnel lets you keep your servers and routers where they are and still have your IP prefixes filtered by a large protected network. You build a tunnel from your router to our edge at Qupra Datacenter in Amsterdam, we run a BGP session through it, and your prefixes are announced on Global Secure Layer (GSL, AS137409). Attack traffic is filtered on GSL's network before it ever reaches your link, and clean traffic arrives through the tunnel. We deliver it from 500 Mbit/s up to 10 Gbit/s of clean traffic, and a tunnel is usually live within 2 to 4 hours of receiving your details.
In short:
- Your prefixes stay yours: your own ASN and IP space, including leased IPv4 with matching route objects.
- Your traffic is filtered inline by GSL, which says its protection starts mitigating an attack in under one second.
- Clean capacity from 500 Mbit/s to 10 Gbit/s, delivered over GRE from our Amsterdam PoP at Qupra.
- Your ASN can be added directly under GSL, so your routes are announced straight to GSL rather than behind our network.
- Pricing is quoted per network: message us on Telegram or by email, and we keep terms flexible.
How remote DDoS protection over a tunnel works
A volumetric attack wins by filling the pipe in front of your server. Filtering on your own router does not help once your uplink is already full. Remote protection moves the fight upstream, onto a network with far more capacity than any single site:
- You build a GRE tunnel from your router (or a Linux server running BIRD or FRR) to our edge router at Qupra Datacenter in Amsterdam.
- We bring up a BGP session inside the tunnel, and your prefixes are announced to the internet on GSL's network.
- Traffic to your addresses now enters GSL first, at the exchange or carrier nearest to the sender, and passes through GSL's filtering.
- The clean part travels to Amsterdam and down the tunnel to you. Attack traffic is dropped long before it gets near your link.
Your outbound traffic can leave through the tunnel too, so replies keep the same protected path, or through your local uplink if you prefer. Because the tunnel runs over your existing internet connection, it works from any data centre, office or country, without new hardware or cabling.
What you get
| Item | Remote DDoS protection over GRE |
|---|---|
| Where it lands | Our PoP at Qupra Datacenter, Amsterdam |
| Clean capacity | From 500 Mbit/s up to 10 Gbit/s |
| Upstream | Global Secure Layer (AS137409), with inline DDoS filtering |
| Routing | BGP over the tunnel, IPv4 and IPv6, your own ASN and prefixes |
| Your ASN under GSL | Available: we add your ASN directly in GSL's portal |
| Time to go live | Usually 2 to 4 hours after we have your ASN, prefixes and tunnel endpoint |
| Price | Quoted per network on Telegram or by email, with flexible terms |
The network behind it: GSL in numbers
Protection is only as strong as the network that absorbs the attack. Global Secure Layer is a Brisbane-based transit provider built around its own inline mitigation system, which it calls Goliath. Its own pages state that it can mitigate an attack in under one second and that it peers with more than 3,500 networks.
Public routing data shows the scale. According to bgp.tools, GSL is connected to 82 internet exchanges with roughly 9.9 Tbit/s of exchange ports between them, buys transit from carriers including Cogent, Lumen, GTT, Zayo and NTT, and serves around 250 networks directly. In Amsterdam alone it has 100 Gbit/s ports at AMS-IX, NL-ix, LSIX and Frys-IX, and in Frankfurt a 400 Gbit/s port at DE-CIX. Attack traffic is spread across all of that before it can reach your tunnel.
GSL's filtering works in two stages, described in its Creatia documentation. Level 1 handles volumetric floods and amplification with heuristics and a SYN proxy for TCP. Level 2 is a per-prefix firewall of custom rules that can accept, drop or rate-limit traffic. Prefixes carried over a GRE tunnel are always filtered inline, so there is no detection delay before scrubbing begins.
Your ASN directly under GSL
Most protected-tunnel services announce your prefixes behind the reseller's own network, so the provider's ASN sits between you and the protected upstream. We can do it differently: your ASN can be added directly under GSL in GSL's Creatia portal, so your prefixes are announced straight to GSL (AS137409) and the path does not go through ours.
That keeps your routing clean. Looking glasses and route collectors show GSL as your upstream, filtering applies to your prefixes exactly as registered, and your announcements follow your own route objects and RPKI records. You still deal with us for setup, changes and support, so you get a person on Telegram instead of a ticket queue.
Why take it from a direct transit provider
RS Computers connects to GSL directly in Amsterdam. Buying protection from a direct customer rather than a reseller of a reseller has practical advantages:
- Shorter path. Your tunnel lands on our router at Qupra, which reaches GSL over our own network, with no other providers in between.
- Faster changes. New prefixes, filter adjustments and capacity upgrades go straight to the people running the edge.
- Flexible capacity. Start at 500 Mbit/s and move up to 10 Gbit/s as your traffic grows, without changing the setup.
- More than protection. The same team sells flat-rate IP transit in Amsterdam and Skopje, so protected and unprotected routes can come from one provider.
What you need
- Your own ASN, or IP space you are authorised to announce. Leased IPv4 is fine when the route objects and RPKI ROAs match the ASN that will announce it.
- At least a /24 of IPv4 or a /48 of IPv6, the smallest prefixes most networks accept in the global routing table.
- IRR route objects (and ideally an AS-SET) and valid ROAs for the prefixes you want protected.
- A router that can run GRE and BGP: MikroTik, Juniper, Cisco, VyOS, or Linux with BIRD or FRR.
- A public IP address on your side for the tunnel endpoint.
Plan for the tunnel overhead. On a normal 1500 byte path, GRE over IPv4 adds 24 bytes, a 20 byte outer IPv4 header plus the 4 byte GRE header defined in RFC 2784, which leaves an MTU of 1476 inside the tunnel. Clamp TCP MSS to match, 1436 for IPv4, and we check both ends with you when the session comes up. Your own uplink to Amsterdam also sets the ceiling for clean traffic, so a 10 Gbit/s service needs a site with at least that much bandwidth.
How to order
- Message us on Telegram or email info@rscomputers-ks.com with your ASN, the prefixes to protect, the clean capacity you need and the public IP of your tunnel endpoint.
- We check your route objects and ROAs and send a quote.
- Once you confirm, we send the tunnel and BGP details and add your ASN under GSL.
- You bring up the tunnel and session at your end. Most setups are live within 2 to 4 hours.
Frequently asked questions
What is remote DDoS protection over a GRE tunnel?
It is a service where your IP prefixes are announced from a protected network instead of your own, and clean traffic is delivered to you through a GRE tunnel. Attacks are absorbed and filtered upstream, on a network much larger than your own link, so your servers stay reachable without moving them.
Do I need my own ASN?
Yes, or IP space you are authorised to announce with matching route objects and RPKI records. Your ASN can then be added directly under GSL, so your prefixes are announced straight to GSL. If you are not sure your setup qualifies, message us and we will check it.
How quickly can the tunnel be live?
Usually within 2 to 4 hours after we have your ASN, prefixes and tunnel endpoint, and once your route objects and ROAs check out.
How much capacity can I get?
From 500 Mbit/s up to 10 Gbit/s of clean traffic over the tunnel. Your own uplink to Amsterdam has to carry it, so plan the site bandwidth accordingly.
How much does it cost?
Prices depend on the clean capacity and the number of prefixes, so we quote each network individually. Send your details on Telegram or to info@rscomputers-ks.com.
Start with a message
If your network is being hit, or you simply want a protected upstream before it happens, send us your ASN, prefixes and the capacity you need. We will tell you what fits, quote it, and in most cases have your tunnel and BGP session up the same day. For flat-rate transit without protection, see IP transit in Amsterdam.