All systems operational

Pay with Bitcoin, Monero, USDT & 11 more · email-only sign-up

Network & DDoS protection

Traffic you don’t count. Attacks you don’t see.

Every server gets an unmetered port, a routed IPv6 block and always-on DDoS filtering at the network edge — in 10 carrier-neutral locations on three continents.

  • 1–10 Gbpsunmetered ports
  • L3/L4always-on filtering
  • 99.9%network SLA
  • /64IPv6 per server

Attack filteredMitigated

Target
203.0.113.10
Vector
UDP amplificationNTP reflection, source port 123
Started
14:02 UTCLasted 14 minutes
Action
Dropped at the edgeLegitimate traffic kept flowing
Your part
Nothing — this email is for your records

Example of the email you receive for a significant attack. Address from a documentation range.

Footprint

10 locations, one network

Each location is multi-homed with several transit carriers and connected to its metro’s main internet exchange where available, so traffic takes short, direct paths.

Amsterdam, Netherlands (AMS)AmsterdamFrankfurt, Germany (FRA)FrankfurtHelsinki, Finland (HEL)HelsinkiBucharest, Romania (BUH)BucharestStockholm, Sweden (STO)StockholmLondon, United Kingdom (LON)LondonNew York, United States (NYC)New YorkMiami, United States (MIA)MiamiLos Angeles, United States (LAX)Los AngelesSingapore, Singapore (SIN)Singapore
Ports & bandwidth

Unmetered means unmetered

No traffic counter, no ratio, no fair-use clause, in either direction. What you can push is limited by the port — nothing else.

  • 1 Gbps on every server — up to about 324 TB a month at line rate.
  • 10 Gbps on the 10G model or as an option in Amsterdam, Frankfurt, New York — about 3.2 PB a month.
  • 25 Gbps as a custom build in the same cities.

What a full port moves in 30 days

1 Gbps324 TB
10 Gbps3.24 PB

For comparison, hyperscale clouds typically bill outbound traffic at $0.05–0.09 per GB: 324 TB would cost tens of thousands of dollars. Here it is part of the monthly price.

DDoS protection

Filtered at the edge, before it reaches you

Always on, for every IP address, at no extra cost. Nothing to enable, no “under attack” mode to trigger.

  1. Detect

    Traffic to every address is analysed continuously at our network edge; attack signatures and volume anomalies are recognised in seconds.

  2. Filter

    Attack packets are dropped at the edge while legitimate traffic keeps flowing to your port — your server never sees the flood.

  3. Tell you

    For significant attacks you get an email with the target address, the attack type and its duration.

Attack types and how they are handled
Attack typeHandled by our filtering
UDP floodsYes
SYN, ACK and RST floodsYes
Amplification (DNS, NTP, memcached, CLDAP, SSDP)Yes
IP fragmentation attacksYes
ICMP floodsYes
HTTP floods and other L7 attacksUse a reverse proxy or WAF
Addressing

IP addresses and private networking

  • IPv4 + IPv6 included1 dedicated IPv4 and a routed /64 IPv6 block per server. A /56 is free on request.

  • Extra IPv4 addressesUp to 16 per server at $3 a month each, routed to your machine.

  • Reverse DNSSet PTR records for every IPv4 and IPv6 address from the client area.

  • Private VLANConnect your servers in the same location over a private network, free, on request.

  • Clean address spaceSource-address validation (BCP 38) at the edge and a 30-day quarantine before an address is reassigned.

  • Traffic graphsPer-server bandwidth graphs in the client area — informational only, since nothing is billed on traffic.

Between locations

Round-trip time between our sites

Figures in bold are medians of real measurements (WonderNetwork, September 2026). The others are estimated from distance — fibre at about two-thirds of the speed of light, 1.25 × the straight-line route, plus 5 ms for equipment and local routing — and real routes may be faster or slower.

Round-trip time in milliseconds between each pair of locations: measured where available, otherwise estimated from distance
FromAMSFRAHELBUHSTOLONNYCMIALAXSIN
Amsterdam — 11 38 25 21 8 80 100 115 135
Frankfurt 11 — 24 30 20 16 85 100 120 135
Helsinki 38 24 — 25 8 30 90 110 120 120
Bucharest 25 30 25 — 25 30 100 120 135 115
Stockholm 21 20 8 25 — 25 85 105 115 125
London 8 16 30 30 25 — 70 95 115 140
New York 80 85 90 100 85 70 — 25 55 195
Miami 100 100 110 120 105 95 25 — 50 215
Los Angeles 115 120 120 135 115 115 55 50 — 180
Singapore 135 135 120 115 125 140 195 215 180 —

Estimate latency from your users’ cities

FAQ

Network questions

Still have a question?

Ask the engineers who run the servers — median first reply under 15 minutes, 24/7.

Contact us
Will you null-route my IP during an attack?

Only as a last resort, when an attack is large enough to endanger the network for other customers. We filter first, tell you immediately if we ever have to drop traffic to an address, and lift it as soon as the attack subsides.

Does filtering cover application-layer (L7) attacks?

No. Our filtering handles network and transport-layer attacks (L3/L4). HTTP floods and other application-level attacks look like normal requests to a network filter: stop them with a reverse proxy, rate limiting or a WAF in front of your application.

Is there a traffic ratio or fair-use limit?

No. Unmetered means we do not count your traffic in either direction and do not apply a ratio or a fair-use cap. You can run the port at line rate all month.

Can I bring my own IP addresses?

Not as a standard product today. If you hold your own IP space and need a BGP session, ask sales: we evaluate it case by case for larger deployments.

How do you stop spoofed traffic leaving your network?

Our network applies source-address validation (BCP 38): packets with a source address that does not belong to your server are dropped at the edge. It is one of the reasons our IP ranges keep a clean reputation.