Skip to main content

DDoS Mitigation Service

Cyberattacks such as DDoS (Distributed Denial of Service) can stop (digital) business operations in a very short time. A DDoS Mitigation solution helps protect systems, services, and networks from being overwhelmed by malicious traffic, providing significant business, security, and operational benefits by preventing service disruptions caused by malicious traffic.

The DDoS Mitigation Service increases the availability of the Equinix Internet Access (EIA) Service. To maintain the availability of EIA Service, protective measures are taken, depending on the assessed risks or the risk profiles. These protective measures can also be applied to business-critical applications accessed over the internet that must be optimally protected against cyberattacks.

Standard Service

In the onboarding process, the customer will provide their IP addresses and the e-mail address for the notification after which the service will be configured.

Incoming Internet traffic enters the Equinix network via Border Routers. Network sensors attached to these routers continuously scan incoming traffic to identify irregular patterns or sudden increases in volume as the result of DDoS attacks. Within seconds the network sensors detect an attack, traffic is automatically redirected from the affected IP address(es) to the DDoS Mitigation infrastructure.

The DDoS Mitigation infrastructure instantly filters out all abnormal traffic and forwards only clean traffic to the application origin. This redirection stops automatically once the DDoS attack ends. The customer will be notified after the identification of a DDoS attack on the customer’s infrastructure, with a report via e-mail, containing all details about the attack.

Unlike cloud-based anti-DDoS services, this service incurs no additional latency when you are not under attack and does not affect application performance. Traffic is redirected only during an attack (depending on the chosen service variant), so latency is unaffected during normal operation.

The DDoS mitigation infrastructure blocks illegal traffic from overloading customers' critical application servers while still allowing legitimate network traffic to and from end users.

ddos-mitigation-infrastructure

The customer can have the standard threshold values adjusted on request, and this can be specific to the relevant application. Equinix can advise the customer on this.

Service Options

ServicePort SpeedCountry
DDoS Mitigation – Standard1 GbpsUK, Spain, Ireland, Canada
DDoS Mitigation – Standard10 GbpsUK, Spain, Ireland, Canada
DDoS Mitigation – Premium10 GbpsNetherlands
DDoS Mitigation – Premium100 Gbps¹Netherlands
DDoS Mitigation – Additional IPsN/AUK, Spain, Ireland, Canada, Netherlands

¹ On special request only.

DDoS Mitigation – Standard

The Equinix Anti-DDoS service protects Equinix Internet Access with port speeds 1 Gbps and 10 Gbps. It can be used in combination with either the standard Equinix-owned (PA) or the user-owned provider-independent address space (PI).

The service operates the same for both PA and PI address space. Mitigation works by diverting the individual /32 address(es) under attack through our scrubbing device(s). There are no conditions on minimum subnet size or contiguous address space (beyond those already imposed by the EIA product).

DDoS Mitigation – Premium

The Equinix Anti-DDoS service protects Equinix Internet Access with port speeds 10 Gbps and 100 Gbps. It can be used in combination with either the standard Equinix-owned (PA) or the user-owned provider-independent address space (PI).

When using Equinix-owned IP addresses, Equinix protects all IP addresses up till /32 (IPv4) or /128 (IPv6). For existing Equinix Internet Access customers, this might require the use of a new IP subnet which does support Anti-DDoS.

When using your own PI space, you must have continuous IP address ranges of at least /23 (IPv4) or /47 (IPv6). Furthermore, Equinix must be the only provider for these ranges.

In case of a DDoS attack on one or more IP addresses in a subnet, rerouting takes place on that subnet to prevent adverse impact on other services.

Additional IP addresses

EMS operates under a fair use policy, which covers multiple small subnets, totaling up to a single /24, within the standard pricing. If protection is needed for more than a single /24, additional charges will apply.

Service Demarcation and Enabling Services

Equinix is solely responsible for the Standard Service and combination of Service Options as set out in the Order and subsequent Service Requests.

The DDoS Mitigation Service can only be ordered in combination with EIA (Equinix Internet Access) and as such acts as a security component in a solution.

This service is fully managed and has no self-service functionalities.

Equinix Managed Solution is not responsible for:

  • The EIA connection
  • User-owned provider-independent address space (PI)

For the DDoS Mitigation Service the following service boundaries apply:

  • Detection > volumetric based
  • Scrubbing > after detection & redirection in-depth scrubbing

Service Items

When ordering the DDoS Mitigation service, choose the variant that best suits the requirements. The DDoS Mitigation Service is charged based on Baseline values. Refer to the appropriate section for an explanation of each variant.

Charge Types

Baseline is the specific volume of Unit of Measure of the Service as defined in the Order.

Catalog of Billing Items

CategoryPurchase UnitUOMInstall FeeBilling MethodOverage
DDoS Mitigation - Standard1 GbpsEachYesBaselineNo
DDoS Mitigation - Standard10 GbpsEachYesBaselineNo
DDoS Mitigation - Standard100 Gbps¹EachYesBaselineNo
DDoS Mitigation - Premium10 GbpsEachYesBaselineNo
DDoS Mitigation - Premium100 Gbps¹EachYesBaselineNo
DDoS Mitigation - IPsAdditional IPsEachYesBaselineNo

¹ On special request only.

Roles and Responsibilities

Onboarding

Installation

ActivitiesEquinixCustomer
Schedule / execute project kickoff meetingRACI
Schedule / execute customer onboardingRACI
Hardware and software DDoS Mitigation platformRACI

Configuration

ActivitiesEquinixCustomer
Configuring and setting of the DDoS Mitigation platform threshold valuesRACI

Acceptance Into Service

ActivitiesEquinixCustomer
Testing the configuration as part of operational managementRACI
Functional testingCIRA

Operational

ActivitiesEquinixCustomer
Technical management of the service (overall)RACI
Functional management of the customer configuration within the service (overall)IRAC
Service deskRACI
DDoS monitoring, detection, scrubbing and alertingRACI
Submitting Service Request via the PortalCIRA
Implementation of Changes in accordance with change process based on Service RequestsRACI
Interpretation of DDoS attacksRACI
note

RACI defines responsibility roles: Responsible, Accountable, Consulted, and Informed.

Incident Management

Incident management is included as part of service support. All incidents are handled according to priority. Priority is determined after the issue is reported and assessed by Equinix based on the information provided.

PriorityImpact/UrgencyDescription
P1 HighUnforeseen unavailability of a service or environment delivered and managed by Equinix in accordance with the service description due to a disruption. The user cannot fulfill obligations towards users and suffers direct demonstrable damage due to the unavailability of this functionality.The service must be restored immediately. The production environments are unavailable, with platform-wide disruptions.
P2 MediumThe service does not offer full functionality or has partial functionality or reduced performance, impacting users. The user suffers direct demonstrable damage due to unavailability of the functionality. The service may be impacted due to limited availability.The service must be repaired the same working day. The management environment is not available.
P3 LowThe service functions with limited availability for one or more users and a workaround is in place.The moment of repair is determined in consultation with the reporting person.
note

This classification does not apply to disruptions caused by user-specific applications, user actions, or dependencies on third parties. Incidents can be submitted in the Customer Portal under Managed Solutions. P1 incidents must be submitted by phone.

Service Requests

Customers can raise a Service Request for configuration changes that cannot be implemented through self-service in the Operational Console or when assistance is required for changes made in the Operational Console. Support is available 24x7x365 for the DDoS Mitigation Service.

There are two types of Service Requests:

  • Included - Service Requests within the scope of the service, with no additional charges.
  • Additional - Service Requests outside the scope of the service, with additional charges.
Type of ChangeIncluded / Additional
Change threshold valuesAdditional
Request additional reportsAdditional
Ask information about the productIncluded

Customers can select changes which are not listed in the table above by selecting “change” at the service request module in the Managed Solutions Portal. Equinix will perform an impact analysis to determine whether the change can be implemented, to determine associated costs and lead time.

Any charges related to Service Requests will be deducted from the Premier Support Plan, or in case of insufficient balance invoiced in arrears based on the prevailing rate.

Changes in the baseline capacity, amount ordered or any other change that will have an impact on the monthly service fee should be requested via the Sales team.

Reporting

Functional Reporting

The overviews of DDoS attacks can be reported according to the frequency or trigger agreed with the customer: weekly, monthly, after every DDoS attack or on customer request only. Additional reports are available upon request.

SLA Reporting

The customers may ask for SLA reporting via Service Request at any time without incurring additional charges.

Service Levels

The Service Level Agreement (SLA) defines the measurable performance levels associated with the DDoS Mitigation service and specifies the remedies available if these levels are not met. The service credits described are the sole and exclusive remedy for failure to meet the stated thresholds.

Support

The SLA for support applies to incident registration and resolution.

PriorityResponse time¹Resolution time²Execution of workSLA³
P1< 30 min< 4 hours24x795%
P2< 60 min< 24 hours24x795%
P3< 120 min< 5 days24x795%

¹ Response time is measured from the moment a trouble ticket is submitted until a formal response is sent by an Equinix Managed Solutions specialist. ² Resolution time is measured from case registration until the ticket is closed, cancelled in the ITSM tool, or handed over to IBX Support. ³ SLA applies to response time. Specific SLA terms are defined in the product policy.

Availability

The DDoS Mitigation Service is considered Unavailable when there is a DDoS attack and in the case of DDoS Mitigation Standard the scrubbing does not take place, or in the case of DDoS Mitigation Premium, rerouting of the subnet does not take place and/or scrubbing does not take place, for more than 5 minutes.

Availability Service LevelDescription
99.95%+This is met by achieving less than twenty-two (22) minutes of unavailability of the DDoS Mitigation Service over a calendar month period.

A Service credit regime on the availability SLA is described in the Product Policy, as well as how to calculate SLAs and what exclusions are applicable.

Cette page vous a-t-elle été utile ?