Integration methods
DDoS Protection integrates in three ways. Choose based on network structure and owned assets.
1. Direct Protection
A protection service provided based on Public IP managed by PacketStream.
DDoS Protection is applied immediately by integrating with PacketStream products without separate configuration.
Features
- Uses PacketStream-managed IP
- Basic L3/L4 Protection automatically applied
- L7 Protection selectable based on application characteristics
Compatible Products
- PacketStream Virtual Server (Cloud VM)
- PacketStream Baremetal Server
- PacketStream CDN Service
Usage Flow
- Service application → Protection applied when creating servers/resources
- No separate routing configuration required
- Basic DDoS filtering activated
- L7 defense settings can be added when needed
2. BYOIP / BYOAS Protection (Bring Your Own IP / AS)
A method where customers integrate their own IP Prefix or ASN with PacketStream for protection.
Mainly suitable for customers operating their own IP resources.
Features
- Uses customer-owned IP Prefix or ASN
- Prefix Advertisement through BGP sessions
- Supports Prefix Filtering and Community-based Blackhole
Compatible Products
- PacketStream Transit Service
- PacketStream DIA (Dedicated Internet Access)
Usage Flow
- Submit Prefix and ASN information
- Set up BGP session with PacketStream
- Normal traffic routing and protection applied when DDoS occurs
- Manual response possible through Blackhole Community when needed
Note Prefix requires RPKI and ROA registration.
3. Remote Protection
PacketStream DDoS Protection can be used even in external data centers or customer on-premises environments.
Traffic is processed through PacketStream network using GRE tunnels, etc.
Features
- Supports GRE, IP-in-IP tunneling
- Access to PacketStream protection network through tunnels
- Compatible with managed IP, BYOIP, and BYOAS
Usage Flow
- Set up GRE tunnel with PacketStream
- Configure Tunnel Endpoint IP router
- Static IP Route or BGP Advertisement (for BYOAS)
- Only clean traffic with mitigated attack traffic delivered to customer network
Requirements and Recommended Settings
- Tunnel Type: GRE or IP-in-IP (WireGuard supported)
- Tunnel Endpoints: Public IP required on both sides
- MTU: 1400 bytes or less recommended when using GRE
- BGP: BGP session can be configured on the GRE tunnel (optional)
- Failover: Dual GRE tunnel recommended (Primary/Backup)
Warning GRE tunnels add packet overhead (24 bytes) by default. Tunnel interface and server MTU should be adjusted to 1400 bytes to prevent fragmentation issues.