Skip to main content

Frankfurt DDoS scrubbing

Templass cleans inbound attack traffic in Frankfurt, inside Equinix FR5. Mitigation capacity is about 1 Tbps. Clean packets leave FR5 toward your origin on the path you ordered: GRE or a cross-connect.

What "scrubbing" means here

  1. Users and attackers send packets to your protected address on AS208743.
  2. That traffic arrives at Templass in FR5, not at your origin's public NIC.
  3. Volumetric and Layer 3 / Layer 4 abuse is dropped or limited on the Templass side.
  4. Remaining traffic is forwarded to you.

Your origin should not have to absorb the attack bandwidth. It still has to accept the clean rate you subscribed to. See Plans and bandwidth.

Capacity, honestly

~1 Tbps is the mitigation capacity of the scrubbing platform, not the bandwidth of your plan.

  • Essential, Standard, and Premium cap clean (or billed) throughput far below 1 Tbps.
  • A large attack can still be dropped in FR5 while your clean channel stays within plan.
  • Custom designs are scoped with sales if you need a different clean rate or handoff.

Capacity figures are platform-level. For day-to-day behavior, read How mitigation works.

Location consequences

  • Latency to users is the path to Frankfurt, then the path from Templass to your origin.
  • If your origin is far from FRA, GRE adds that extra stretch on every clean packet.
  • A cross-connect only removes the Templass-to-origin internet hop when you are also in FR5.

There is no second scrubbing site documented here. If you need another campus, ask [email protected] rather than assuming anycast or extra metros.

What you do in Panel

Watch Dashboard and Attacks, and change firewall or rate limits when you need policy on top of default mitigation.

People look for this page as Frankfurt DDoS scrubbing, Equinix FR5 DDoS, or Templass Frankfurt. Those all refer to the same FR5 platform described above.