ESpanix Shield

DDoS protection built into the exchange

What is ESpanix Shield

ESpanix Shield is DDoS protection built into the exchange: we detect and block the attack inside the ESpanix network, before it reaches your port. No diversions, no added latency.

  • No added latency: legitimate traffic travels straight through. The path under attack is the same as the path in calm conditions: no GRE tunnels, no extra hops.
  • Certified sovereignty and security: mitigation happens inside the ESpanix network, certified to ISO/IEC 27001 and to the Spanish National Security Framework (ENS) at High category. Your traffic never leaves Spain.
  • Precision: granular filtering that separates attack sources from the real user arriving over the same network, without discarding whole prefixes.
  • Protection in both directions: we also identify attack traffic leaving your network, keeping your infrastructure out of global campaigns.
FeatureTraditional model (cloud scrubbing)ESpanix Shield (edge mitigation)
Traffic pathDivert → external centre → returnDirect, no diversions
Added latencyWhatever the trip to the scrubber costsNone
SovereigntyThird parties, possibly outside the EUESpanix network, in Spain
ComplexityPer-customer BGP/GRE configurationNo changes to your network
GranularityRisk of prefix-level discardGranular filtering
Traffic directionInbound onlyInbound, plus outbound detection

The new scenario: DDoS is infrastructure, not just application

For years, the predominant view was that DDoS attacks were sporadic peaks resolved with one-off measures. Current data proves otherwise. According to global reports from 2025/2026, we have entered the era of sustained cadence.

Attacks are no longer just massive volumetric floods lasting minutes. They are hybrid campaigns combining volume (terabits per second), state exhaustion (SYN floods, TLS handshake) and application layers (HTTP/S), executed at almost continuous frequency. For an IXP member, this means the connection port can be saturated by “garbage” that is legitimate in protocol but malicious in intent, consuming contracted bandwidth and degrading the latency of your real traffic.

The traditional "Divert to Scrubber" model no longer works in an IXP

The traditional solution consists of detecting the attack, diverting traffic to an external scrubbing centre via BGP/GRE and reinjecting it clean. In the context of an Internet Exchange Point (IXP), this model has three critical flaws:

  1. Tromboning and Latency: By diverting traffic, you introduce a round trip outside the optimal route. For low-latency services (online gaming, high-frequency trading, VoIP), this is unacceptable.
  2. Loss of Sovereignty: Your sensitive traffic travels through third-party infrastructures, often outside the EU, creating operational dependencies and regulatory compliance risks (GDPR, ENS) that corporate clients and public administrations cannot tolerate.
  3. Geographic Inefficiency: An attack launched from Spain, targeting Spain, must leave and re-enter via international links or backbone to be cleaned. It is a waste of network resources.

The ESpanix Shield solution: Edge Protection

ESpanix Shield changes the paradigm. We utilise Nokia Deepfield Defender, a platform that turns your border router (or ours, as the ingress point) into an active filter.

  • Intelligent Detection: We ingest IPFIX telemetry and correlate it with Secure Genome (an intelligence map of 5 billion IP addresses) to distinguish botnets from real traffic with surgical precision.
  • Local Action: Within seconds, we generate filtering rules (ACLs) that are installed directly onto the border router’s hardware.
  • Result: The attack is eliminated at the first hop. Legitimate traffic does not move from its path. There are no diversions, no GRE encapsulations, and no external cleaning centres.

Concrete benefits for your network

For Network Operators and ISPs (Access Networks)

Your access networks are the potential source of millions of compromised IoT devices. Failing to filter malicious traffic before it enters the IXP has two negative effects:

  1. Operational Cost: You spend outgoing bandwidth attacking others, paying for traffic that generates no revenue.
  2. Reputational and Technical Damage: If your network becomes a source of attacks saturating other members, you face complaints, disconnections, or peering restrictions. ESpanix Shield helps you stop the bleed before it pollutes the node.

For Enterprises and Service Providers (Traffic Consumers)

If you contract capacity at ESpanix to distribute content or services:

  • Real Availability: You avoid having low-volume but high-intensity attacks (L7 or SYN flood) take down your servers.
  • Quality of Experience (QoE): By not suffering the added latency of scrubbing, your end users maintain service fluidity even under attack.
  • Resilience: Protection scales with your contracted bandwidth. You do not need to buy “extra cleaning” if the attack exceeds your normal thresholds; filtering in silicon supports line rates.

The service

ElementScope
DetectionContinuous analysis of node traffic, 24×7, with no action required from you.
MitigationAutomatic filters on the ESpanix routers, with no diversion and no BGP changes.
CoverageThe prefixes you declare, over your peering port or your Internet access.
ComplianceInfrastructure certified to ISO/IEC 27001 and to the ENS, High category.
ControlPortal with status, events, mitigated traffic and per-prefix thresholds.
SupportESpanix NOC 24×7, with escalation to the Nokia response team.
AvailabilityAll ESpanix data centres, with no equipment on your premises.

Activation in three steps

  1. Prefix declaration. You tell us what to protect and we validate ownership against the routing registries.
  2. Profiling. We observe your traffic and tune the thresholds for each service with you.
  3. Activation. Mitigation switches to automatic: no tunnels, no new routes, no equipment.

Certified sovereignty and security

In today’s European regulatory environment, data residency matters as much as availability.

  • National jurisdiction. ESpanix Shield operates within the ESpanix network in Spain. Traffic does not leave the country to be processed or cleaned, and it does not pass through third-party platforms.
  • Certification. The infrastructure delivering the service is certified to ISO/IEC 27001 and complies with the Spanish National Security Framework (ENS) at High category. At ESpanix we certify the whole organisation, not a single service line.
  • Transparency. You can show your customers and your auditors that mitigation happens under national operational control, in line with CCN-CERT guidance and with the digital sovereignty requirements of public administrations.

Don't let your port be the weak link

Let’s talk about your traffic profile and which prefixes are worth protecting first. We can start with an observation phase over your current port, with no changes to your network.

Fill in the form:

Phone number, including the international dial code, so that we can contact you about your enquiry.
Email address to reply to your request.