AKAMAI · SECURITY
Solution Overview · 2026-08-25

Prolexic: Comprehensive DDoS Protection

Platform overview, architecture, and dual region traffic flow
Customer
Prospective / Internal Review
Lead
Julian Diaz
Account
Enterprise Architecture
Status
Opportunity
Threat Landscape

DDoS attacks in 2026 are no longer just about size

Hyper-scale botnets such as Aisuru and Kimwolf now operate as residential proxies, blending attack traffic into legitimate user traffic. AI-driven reconnaissance and orchestration tools probe defenses in real time, identify the weakest surface, and launch multi-vector, multi-destination attacks. Stopping this class of attack requires automation paired with human intelligence and proven runbooks, not automation alone.

Why legacy defenses fall short
Sophisticated botnets hide in plain sight. Residential proxy traffic is difficult to distinguish from real users at the network edge.
Attacks are AI-orchestrated. Automated probing finds gaps in coverage across multi-cloud and on-prem environments faster than manual response can adapt.
DDoS is a smoke screen. Attacks are increasingly used alongside advanced persistent threats and multilayered, triple-extortion ransomware campaigns.
$1.7M
Avg. cost of a DDoS attack
93%
Of enterprises are multi-cloud
98%
Of attacks mitigated by automation
0s
Mitigation SLA, proactive controls
The Platform

Prolexic: comprehensive DDoS protection everywhere, every time

Prolexic stops DDoS attacks and other unwanted or malicious traffic before they reach applications, data centers, and internet-facing infrastructure, on any port and protocol. It is available on-premises, in the cloud, or as a hybrid combination of both, with a cloud-based network firewall providing an additional, centralized access control layer at the edge of the customer's network.

20+ Tbps
Dedicated defense capacity
32+
Global scrubbing center metros
225+
Frontline SOCC responders
100%
Platform availability SLA

Three pillars: platform, people, process

01
Platform
Automation-driven
20+ Tbps of dedicated defense capacity across globally distributed cloud scrubbing centers, with fully managed on-demand or always-on mitigation for hybrid environments.
02
People
24/7/365 SOCC
225+ frontline SOCC responders and threat researchers analyze and respond to complex attacks, backed by a proven mitigation record since 2003.
03
Process
Zero-second TTM
Proactive mitigation controls reduce time-to-mitigate to zero seconds. Service validation establishes a traffic baseline and a custom runbook per customer.
Deployment Options

Flexible on-ramp models for any origin

All Prolexic Routed services are carrier-agnostic and support customers with a routable IP space (IPv4 /24 and/or IPv6 /48). Customers without a routable block, or on cloud-hosting providers, use Prolexic IP Protect instead.

Service Model Notes
Prolexic Routed, GRE Cloud Primary DDoS mitigation service. Logical GRE tunnels return clean traffic asymmetrically to origin; live for 20+ years across enterprise deployments.
Prolexic Connect Cloud Direct VLAN connections to origin with asymmetric clean traffic return via Equinix Cloud Exchange, GTT, Megaport, or AT&T TAO.
Prolexic over Akamai Direct Connect Cloud Private interconnect supporting 10G and 100G ports, resilient multi-router metro deployments, and jumbo frame GRE tunnels.
Prolexic IP Protect Cloud Symmetric service activated via DNS redirection for customers with less than a routable IPv4 /24 and/or IPv6 /48, or fragmented IP space.
Prolexic Network Cloud Firewall Cloud First line of defense, sitting outside all other firewalls. Customer-managed ACLs and geographic/IP-based rules, integrated via native APIs.
Prolexic On-Prem, powered by Corero On-Prem Inline, sub-second automated mitigation at the customer edge without traffic backhaul. Suited to latency-sensitive real-time services.
Reference Architecture

Traffic flow across two regions

All traffic is announced to Prolexic via a single BGP route advertisement and passes through one Network Cloud Firewall layer, where ACLs and firewall rules block malicious traffic at the edge before it reaches scrubbing. From there, traffic is split across two regional Prolexic scrubbing centers, each returning clean traffic to its regional origin over a GRE tunnel. Cross-region connectivity gives each origin a redundant path if a regional scrubbing center or origin is degraded.

Reference Dual-region Prolexic traffic flow BGP routing · single firewall layer · dual-region scrub · clean return · cross-region failover
ATTACKERS / BOTNETS ATTACKERS / BOTNETS BGP Route Advertisement single announcement, all traffic Network Cloud Firewall single layer · ACLs · edge control REGION A · US-EAST REGION B · EU-WEST Prolexic Scrubbing Center Ashburn, VA Prolexic Scrubbing Center Frankfurt, DE clean traffic, GRE tunnel clean traffic, GRE tunnel Origin Data Center Region A applications and services Origin Data Center Region B applications and services cross-region redundant path (failover) LEGEND Inbound attack / suspect traffic BGP-routed traffic, pre-firewall Filtered traffic, split to regional scrub Clean traffic return (GRE tunnel) Cross-region failover path
One BGP announcement and one Network Cloud Firewall layer front both regions; scrubbing and clean-traffic return happen independently per region.