How mitigation works
Templass is a scrubbing service with a Layer 3 and Layer 4 focus. Attack traffic is handled in Frankfurt before it reaches your GRE tunnel or Equinix FR5 cross-connect.
Placement
Templass sits between the internet and your origin:
- Packets destined to your protected address arrive at Templass (AS208743, Equinix FR5).
- Mitigation decides drop, limit, or forward.
- Forwarded packets travel to you as clean traffic.
Your origin sees a much smaller mix than the full attack firehose.
Layer 3
Layer 3 covers IP-level abuse: floods that waste bandwidth or routing state without a useful transport payload. Typical examples are large UDP or IP floods and amplification that shows up as raw volume.
Those packets are handled on the Templass side. Platform capacity for that work is about 1 Tbps. Your plan still limits the clean traffic you may pull. See Frankfurt DDoS scrubbing and Plans and bandwidth.
Layer 4
Layer 4 covers TCP and UDP behavior: SYN floods, ACK floods, UDP application floods, and other transport abuse aimed at sockets you run.
Default mitigation is always on for a provisioned service. You add intent with:
- Firewall rules
- Rate limiting
- Port requests for the listeners you need
Ask for the ports you serve rather than leaving unused listeners open.
Clean traffic still has a budget
Mitigation drops junk. Legitimate traffic still consumes the Mbps on your plan. 95th percentile billing and overage are under Plans and bandwidth.
Keep DNS and routing on the protected path so traffic actually hits Templass. See Routing. Origin TLS and application auth stay your responsibility.
Seeing it work
Open Attacks during an event. Empty Attacks with a down origin usually means a routing leak, a wrong prefix, or a service that is not on Templass yet. See Under attack.