Home/Technical

AS35200 network reference.

Mitigation modes and peering addresses for the TransitX network.

01 / Mitigation modes

On-demand vs always-on

Two types of DDoS mitigation implementation. Both use the Corero SmartWall ONE platform deployed on-net; the difference is whether traffic passes through the filtering appliance at all times or only during an event.

A

On-demand

Detect & divert
Filtering Appliance activates on detection Internet Attack Traffic Edge router mirrored 1:5000 Customer peacetime · direct redirect scrubbed peacetime attack traffic scrubbed
  • DetectionMirrored packet sampling at the edge (1:5000) identifies anomalies and triggers a redirect.
  • RedirectOnly traffic to the targeted prefix is steered through the filtering appliance.
  • Peacetime pathTraffic goes direct to customer — never touches the filtering appliance until an attack is detected.
Trade-off

In rare cases, very small attacks or very widespread carpet-bomb attacks may slip under detection thresholds before redirection kicks in.

B

Always-on

Inline · 1:1
Internet Attack Traffic Edge router inbound traffic Filtering Appliance 1:1 inspection inline · always-on Customer clean traffic attack traffic scrubbed
  • Inspection1:1 sampling - every packet is inspected by the appliance.
  • MitigationInstantaneous. No detection-to-redirect window.
  • Smallest catchNo threshold to slip under - even small or carpet-bomb attacks are inspected and dropped.
Trade-off

Inbound traffic routed through mitigation appliances at the edge of our network - may add an extra hop or two with hairpinned traffic flow. Latency increase negligible.

On-demand
Always-on
Sampling
Mirrored packets · 1:5000
1:1 packet inspection
Path in peacetime
Direct - bypasses filtering appliance
Always through filtering appliance
Time to mitigate
Seconds (detect & redirect)
Instantaneous
Detection sensitivity
Limited by detection threshold
No threshold - every packet inspected
Shared-fate risk
Low
Although extremely rare, appliance saturation possible

Always-on mitigation is available for up to 20 prefixes at no charge; additional prefixes are subject to surcharge. Customers with an average of more than 10 Gbps of inbound clean traffic using always-on may be subject to an additional surcharge.

02 / Peering

Where to find us

TransitX is present at the major UK exchanges and offers private peering at multiple carrier-neutral facilities.

LINX LON1
London Internet Exchange
Public
Port 1
v4195.66.225.162
v62001:7f8:4::a74f:1
Port 2
v4195.66.228.97
v62001:7f8:4::a74f:2
LONAP
London Access Point
Public
Port 1
v45.57.81.166
v62001:7f8:17::a74f:1
Port 2
v45.57.81.167/22
v62001:7f8:17::a74f:2/64
Private peering
Available across multiple facilities
PNI
UKServers Coventry
Telehouse North 2
Telehouse West
Telehouse East
Equinix Manchester MA1