Protected IP Transit built for exposed, performance-sensitive networks
Deploy resilient Anti-DDoS transit via cross-connect, GRE, IPIP, VXLAN or router VM, with BGP included and delivery tailored to your architecture.
Why operators choose Peeryx
Transit first
A clear focus on protected transit for infrastructure, hosting and public-facing services.
Flexible delivery
Cross-connect, GRE, IPIP, VXLAN and router VM delivery models let you fit Peeryx into your existing network design.
Policy control
Five included post-filter firewall rules let you ratelimit, accept or drop traffic after mitigation.
Built for serious traffic
Protection spans L3, L4, L5 and L7, including DDoS targeting all L3/L4 protocols.
Delivery methods
Cross-connect
Protected transit delivered directly in datacenter for low-latency, high-trust interconnection.
GRE tunnel
Fast deployment model for secure protected transit over established GRE encapsulation.
IPIP tunnel
Simple routed delivery option when IPIP better matches your infrastructure constraints.
VXLAN tunnel
Flexible protected delivery for environments built around overlay network designs.
Router VM
Prefer to keep tunnel control on your side? Peeryx can provide a router VM for iBGP or eBGP return paths.
How the service works
1. Delivery design
Choose cross-connect, tunnels or router VM based on your existing topology and operational preferences.
2. Protected ingress
Traffic enters the Peeryx mitigation fabric where volumetric and protocol attacks are filtered in real time.
3. Post-filter policy
Firewall rules and behavioral analysis refine the accepted traffic profile after core mitigation.
4. Clean handoff
Filtered traffic is handed back to your infrastructure through the chosen delivery method, with BGP included.
Protected transit pricing
Commit-based pricing keeps the offer transparent while scaling efficiently for larger networks.
Commit pricing
Commit pricing
Commit pricing
Commit pricing
Everything included in the default offer
- BGP announcement included
- No prefix announcement limit
- Under-ASN support included
- AS-SET parameter supported
- Anti-DDoS firewall included
- Behavioral AI-based mitigation included
- 5 included firewall rules
- Additional rules available at low extra cost
Router VM delivery option
If you prefer to control the tunneling layer yourself, Peeryx can provide a router VM so you can establish tunnels on your side and route traffic back using iBGP or eBGP according to your design.
Optional Game Anti-DDoS filtering
Add specialized gaming traffic filtering for €190/month when you need deeper rules tailored to game protocols and session patterns.
Activation windows
Tunnel delivery
Up to 24 hours
Cross-connect delivery
Up to 72 hours
Urgent activation
Under 2 hours with €250 setup
Typical use cases
Hosting providers
Protect public-facing customer workloads without sacrificing delivery flexibility.
Infrastructure operators
Add premium Anti-DDoS protected transit to exposed backbone segments and edge services.
Enterprise services
Secure business-critical applications, APIs and platforms against disruptive traffic spikes.
Gaming-related networks
Protect game-adjacent infrastructure while keeping the transit product as the operational core.
Protected transit FAQ
What is the minimum commit?
The minimum commit is 100 Mbps, billed on a 95th percentile basis.
Can Peeryx deliver through a router VM?
Yes. Router VM delivery is available when clients want to manage the tunneling layer and return traffic through iBGP or eBGP.
Is Game filtering mandatory?
No. It is an optional €190/month add-on for customers who need more specialized gaming rules.
What happens outside the commit?
Excess traffic outside the commit is billed at €1.50/month per exceeded Mbps.
Need a technical transit design review?
Share your architecture with us and we’ll recommend the right protected delivery model.