Skip to content

A network
that belongs to us

Our own fibre between the locations, our own AS number — the identifier of our network in internet routing — and our own routers. No reselling of third-party capacity; troubleshooting therefore does not end at a provider boundary.

Prices net plus 19% VAT. locations: 5.

Network metrics
Backbone capacity
18.4 Tbit/s
Peering points
94
DDoS filter capacity
1.2 Tbit/s
CDN locations
42 PoPs
Autonomous system
AS204812
IPv6
/48 per account, at no extra charge
All values refer to the status of the current expansion stage, measured at the border routers.
Backbone
18.4 Tbit/s
counter-rotating ring, 2 × separate routes
Peering points
94
IX and private interconnects
DDoS filter
1.2 Tbit/s
included in every plan
CDN-PoPs
42
one address for all

Eleven building blocks, one network

The following sections go through each service individually. This table tells you in advance what each is intended for and where you stand — including the one service we do not yet offer.

Network building blocks with purpose, status and entry size
Building blockWhat forStatusEntry
Uplink and backboneGuaranteed connection of every system to our own fibre optic network.available1 Gbit/s included
ConnectDedicated port between your data centre and our network edge.availablefrom 10 Gbit/s
Private network (vRack)Layer 2 segment across location boundaries, without routing through the internet.available1 Gbit/s included
VPCRouted, multi-tenant network with custom subnets, routing tables and rule sets.in preparationnot yet available
GatewayOutbound address translation for systems without their own public address.availablethree size classes
Load BalancerDistribution of incoming connections on Layer 4 and Layer 7.availableper instance and month
DDoS protectionVolumetric filtering at the network edge, permanently active.availableBasic protection included
CDNDelivery via 42 locations at the network edge, all under one address.availableby volume
IPv4 and IPv6Additional subnets, IPv6 at no extra charge, self-service reverse DNS.available1 × IPv4 included
Floating IPPublic address that moves between systems without touching DNS.availablebound without charge
Own address block (BYOIP)Announcement of your own prefix via our AS number.availablewithout charge

The entry column states the smallest expansion stage, not the final price of a configuration. The amounts are listed in the respective section, net plus 19% VAT.

A ring, not a single route

The locations are connected to a counter-rotating fibre optic ring. If one section fails, the opposite direction takes over — switching takes milliseconds, not a maintenance window.

A fibre distribution frame close up from the front: two cable bundles run from the left and right over their own guide rings to their own coupling blocks, without touching.

Two ways out of the network

Peering means two networks connect directly and hand over their traffic to each other, without a third party in between. Transit means a third-party provider accepts the traffic for a fee and carries it further, on routes they choose.

Direct interconnection is the shorter route and the one we can measure ourselves. However, it requires both sides to be at the same node and willing. Transit, on the other hand, reaches every network — even those nobody peers with.

Therefore both, and neither of the two routes alone.

Ring topology

Every location is connected via two physically separate routes that feed in on different sides of the building. The routes are documented on maps and checked for route overlap with every expansion.

Segment routing works in the ring with pre-calculated backup paths; the switching time is under 50 ms.

FRA1 – FRA2 – MUC1 – BER1 – HEL1 – FRA1

Peering

Around 72 percent of traffic leaves the network via direct peering, the rest via four independent transit providers. No provider may carry more than 40 percent of the transit volume.

Private interconnects are available from 10 Gbit/s, requests go through the peering contact in the PeeringDB entry.

94 interconnections · DE-CIX Frankfurt, DE-CIX Munich, BCIX Berlin, FICIX Helsinki

Uplink per system

Every connection is guaranteed, not overbooked. From 10 Gbit/s, the connection is a dual-port with LACP — two ports bundled into one connection — on two separate switches, so a switch restart does not cause an interruption.

1 Gbit/s included, up to 25 Gbit/s available

Uplink options and their monthly surcharges
OptionSurcharge / month
1 Gbit/s guaranteedStandardUnmetered within the included traffic.included
2 Gbit/s guaranteedDoubled uplink capacity, identical fair use policy.€100.83$116.96
3 Gbit/s guaranteedBasic connection of the FORGE series, included in the plan.€150.41$174.48
4 Gbit/s guaranteedFor delivering large files from a single location.€200.83$232.96
5 Gbit/s guaranteedIntermediate level for streaming and mirror servers.€250.41$290.48
10 Gbit/s guaranteedFor storage replication and media delivery.€500.83$580.96
25 Gbit/s guaranteedDual-port connection with LACP to redundant switches.€1,250.41$1,450.48

Locations in the backbone

Latency — the time a packet takes for the round trip — is the median of a week, measured from DE-CIX Frankfurt against a reference host at the respective location. The capacity specification describes the occupancy of the installed floor space, not the network load. The price factor applies to the net base price of each product, before term discount and VAT apply.

All locations with name, latency, occupancy, price factor and PUE
CityDescriptionLatencyOccupancyPrice factorPUE
Frankfurt am Mainfra1Location Rhein-Main I3 ms71%1.00 ×1.14
Frankfurt am Mainfra2Location Rhein-Main II3 ms44%1.00 ×1.09
Berlinber1Location Spree6 ms58%1.00 ×1.16
Munichmuc1Location Isar5 ms82%1.00 ×1.11
Helsinkihel1Location Uusimaa21 ms36%0.94 ×1.08

PUE — the ratio of the total power consumption of a data centre to that of its IT systems — is the annual average of the respective location. The price factor 1.00 designates the reference location Frankfurt am Main; all list prices apply there, net plus 19% VAT.

A line instead of a tunnel

Connect attaches your data centre as a dedicated port to our network edge. The traffic then sees two networks — yours and ours — and not the twelve in between over which a tunnel runs through the open internet.

Bandwidth classes

The port price corresponds to the surcharge for a guaranteed connection of the same speed; a dual-homed handover occupies the edge capacity twice and costs twice as much accordingly. Not included is the cross-connect in the meet-me room — the handover room of the data centre where network operators interconnect their lines. This is billed by the building operator, not us.

Connect bandwidth classes with optics, configuration and port price
ClassOpticsConfigurationPort / month
10 Gbit/s10GBASE-LR, single-mode LC, 1310 nmSingle port. Maintenance on the edge router interrupts the link.€500.83$580.96
2 × 10 Gbit/s2 × 10GBASE-LR, LACPTwo edge routers in separate fire zones, active/active.€1,001.66$1,161.93
25 Gbit/s25GBASE-LR, single-mode LC, 1310 nmSingle port. For replication links with maintenance window.€1,250.41$1,450.48
2 × 25 Gbit/s2 × 25GBASE-LR, LACPHighest expansion stage, 50 Gbit/s total capacity.€2,500.82$2,900.95

All amounts net, plus 19% VAT. minimum term 12 months, then cancel monthly. We do not offer Connect below 10 Gbit/s — there, an IPsec tunnel carries the same load at a fraction of the cost.

Fibre optic patch panel: densely bundled fibres in neat arcs, amber light at the LC couplers.
From the meet-me room, two separate routes run to two edge routers — whether the failure of a router affects your link, however, is determined by the number of ports: a single port is connected to exactly one.

Handover points

The cross-connect ends in the meet-me room of the respective location. From there, the link runs via two separate routes to two edge routers in different fire zones.

Frankfurt am Main — location Rhine-Main I
3 ms
Frankfurt am Main — location Rhine-Main II
3 ms
Helsinki — location Uusimaa
21 ms

You reach all other locations via the same port: from the handover point, the traffic continues in our own backbone, not via transit.

3 locations with carrier-neutral meet-me room

Connect or VPN

Connect and IPsec over the open internet in comparison
PropertyConnectIPsec over the internet
RouteDedicated port on the edge routerAcross any number of third-party networks
Packet latencyGuaranteed and measuredDependent on the route of the day
JitterUnder 0.2 msSingle milliseconds to seconds
ThroughputPort speed, guaranteedRemainder of the internet connection
EncryptionOptional, MACsec on the linkMandatory, IPsec in the tunnel
Setup10 to 20 working daysSame day
Makes sense from10 Gbit/s continuous loadAny load below that

A VPN is not a worse version of Connect, but the right answer to a different question. A dedicated port only pays off when latency and throughput must be contractually guaranteed.

Latency guarantee

Guaranteed are 2 ms packet latency on a monthly average to the edge router of the handover location and a packet loss of under 0.01 percent. For other locations, the backbone latency listed in the location table also applies.

The measurement runs every second against a reference point behind the port. The values are available in the customer account and are the same ones that result in a service credit under the Service Level Agreement.

Measured between handover port and edge router of the target region

Order process

After ordering, we will provide you with the port ID and the contact in the meet-me room. You order the cross-connect from the facility operator, we activate the port and test the link together with you for optical levels, MTU and LACP status before production traffic runs over it.

10 to 20 working days until the light signal

A Layer 2 network across location boundaries

Servers, cloud instances and managed databases end up in the same broadcast segment — even if they are located in Frankfurt am Main, Berlin and Helsinki. The traffic never leaves the ENTRONYX CLOUD network.

vRack options and their monthly prices
OptionPrice / month
No private networkincluded
vRack 1 Gbit/sStandardIsolated Layer 2 network across all locations.included
vRack 10 Gbit/sFor storage replication and database clusters.€39.00$45.24
vRack 25 Gbit/sDedicated fabric for HPC and hypervisor clusters.€119.00$138.04
vRack 50 Gbit/sFor distributed storage pools whose write path runs over the private network.€219.83$255.00
vRack 100 Gbit/sHighest expansion stage for clusters with synchronous replication between fire zones.€421.49$488.93

All amounts net, plus 19% VAT.

Segment limits

Standard MTU
1500 bytes
Jumbo frames
up to 9000 bytes
VLAN IDs
1 to 4000, freely selectable
VLANs per account
64
Systems per vRack
5,000
Traffic in vRack
without charge
Addressing
custom, RFC-1918 or public
Encryption
MACsec on the location links

Why Layer 2 and not Layer 3

Cluster software often expects a shared segment: Keepalived with VRRP, Proxmox-Corosync, database failover with a floating virtual IP. On a routed network, this only works with workarounds.

Technically, the vRack runs as a VXLAN overlay with EVPN: VXLAN encapsulates your Layer 2 frames into packets that travel through our routed network; EVPN distributes which address is at which location. What you see is a second network adapter in the system, unconfigured and without DHCP.

VXLAN with EVPN control plane

Using jumbo frames correctly

For storage replication and backups, the larger MTU — the maximum packet length a segment carries — brings measurable throughput because there are fewer packets and therefore fewer interrupts. Prerequisite: every system in the segment must have the same MTU.

A single host with 1500 bytes otherwise causes fragmentation and consequently hard-to-find timeouts. The MTU is therefore set per VLAN, not per system.

9000 byte MTU reduces overhead by about 4 percent

An exit for systems without a public address

Instances in a private segment need to be able to fetch packages, renew certificates and send telemetry — without being accessible from the internet themselves. That is exactly what the gateway does: it translates outgoing connections to a shared public address and lets nothing in from the outside.

Size classes

The class determines throughput and the number of concurrent translations. One translation corresponds to one connection: a build server pulling packages holds a few dozen, a crawler with a thousand targets holds correspondingly more. Switching between classes is seamless, as the state is transferred to the new pair.

Gateway size classes with throughput, capacity and monthly price
ClassThroughputConcurrent translationsNew per secondPrice / month
Gateway S1 Gbit/s500,00040,000€12.00$13.92
Gateway M2 Gbit/s1,000,00080,000€112.83$130.88
Gateway L10 Gbit/s2,000,000200,000€512.83$594.88

All amounts net, plus 19% VAT. The amount consists of the base fee for a managed network instance and the surcharge for the respective throughput class — the same as an uplink of the same speed costs. Outbound traffic via the gateway is not charged separately.

Limits and behaviour

Direction
outbound only
Addresses per gateway
1 to 8, from a pool
Port range per instance
1,024 ports, expandable
TCP timeout
300 s, adjustable 60 to 1,800 s
UDP timeout
60 s
Connected segments
up to 16 VLANs per gateway
Logging
Connection log, 7 days in account
Traffic via the gateway
no separate charge

What the gateway does not do

There is no port forwarding and no inbound rule. A connection from the outside finds no way back, because there is no entry for it in the translation table. If you need to be reachable inbound, use a Load Balancer or a public address on the system.

This makes the direction a property of the design and not a rule that someone accidentally reverses.

No forwarding from outside to inside

High availability

Each gateway runs as a pair. The translation table is continuously synchronised, so that existing connections survive a failover — they hang briefly instead of dropping. The public address does not migrate, it resides on the pair.

Maintenance work runs via the same failover: first the passive system, then the swap, then the second. A maintenance window is not required for this.

Active/passive across two fire zones · failover under 3 s

External visibility

Because all systems behind the same gateway show the same source address, this single address can be provided to partners and added to access lists. The address is permanently assigned and does not change during a failover or when changing the size class.

A source address for allowlists

Layer 4 and Layer 7 on the same instance

A load balancer can simultaneously pass through TCP ports and distribute HTTP requests by path. Both run on redundant hardware in at least two fire compartments.

Layer 4 — transport

Distributes TCP and UDP connections without looking into the content. The connection remains end-to-end encrypted, the load balancer only sees addresses and ports.

Protocols
TCP, UDP, TLS-Passthrough
Concurrent connections
4,000,000
New connections per second
480,000
Throughput per instance
25 Gbit/s
Client IP forwarding
PROXY protocol v1 and v2
Session affinity
Source IP, consistent hashing

Layer 7 — application

Terminates TLS, reads host and path and distributes accordingly. Headers can be set, removed and rewritten; redirects and rate limiting are part of the rule.

Protocols
HTTP/1.1, HTTP/2, HTTP/3 (QUIC)
Requests per second
250,000
Routing
Host, path, header, cookie, method
Rules per instance
200
Rate limit
per rule, per source IP or header
Session affinity
Cookie, optionally signed

Distribution methods

Round Robin
In turn, equally weighted. Useful for equally sized backends and short requests.
Weighted Round Robin
Each backend receives a weight from 1 to 256. For mixed instance sizes and phased rollouts.
Least Connections
To the backend with the fewest open connections. Standard for long-lived connections like WebSockets.
Least Response Time
Moving average of the response time over 30 seconds. Automatically balances unequal backend load.
Source IP hash
Consistent hashing across the source address. When adding a backend, only a fraction of the mappings is redistributed.

Health checks

Checks are performed via TCP connection establishment or via HTTP request against a freely selectable path with an expected status range and its own host header. A backend is considered healthy after two successful checks and failed after three failed ones.

When removed, existing connections drain — 30 seconds by default, adjustable up to one hour. The backend no longer receives new requests from the first failed check.

Interval 2 to 60 s · standard 5 s

TLS termination

Certificates can be uploaded or automatically obtained and renewed via ACME — the protocol used by Let's Encrypt to issue certificates, for example. RSA-2048 and ECDSA P-256 are delivered in parallel per hostname, the client makes the selection via the cipher suite.

OCSP stapling is active — the server delivers the proof of validity of its certificate right away —, session tickets are rotated every six hours. On Layer 7, checking client certificates (mTLS) against a custom CA is also possible.

TLS 1.2 and 1.3 · up to 100 certificates per instance

Pricing model

A load balancer instance costs €12.00$13.92 per month. This includes the first forwarding rule, unlimited traffic and TLS termination. Each additional rule is billed by the hour at €0.0060$0.0070 per hour — this corresponds to €4.38$5.08 in an average month with 730 hours. Rules that you create during the day and remove again in the evening only cost the actual hours.

Monthly costs of a load balancer instance by number of additional rules
ConfigurationBase feeAdditional rulesTotal / month
One rule (included)€12.00$13.92none€12.00$13.92
6 rules€12.00$13.92€21.90$25.40€33.90$39.32
11 rules€12.00$13.92€43.80$50.81€55.80$64.73
26 rules€12.00$13.92€109.50$127.02€121.50$140.94
51 rules€12.00$13.92€219.00$254.04€231.00$267.96

All amounts net, plus 19% VAT. The “Additional rules” column extrapolates the hourly rate to a full average month; billing is by the hour.

Frontal shot of an exposed concrete bulkhead with a bolted steel frame; three cable penetrations are flush-sealed and ground smooth.

Filter capacity 1.2 Tbit/s — as much traffic as 48 systems with the largest bookable connection (25 Gbit/s) could generate together. At ENTRONYX CLOUD, the filtering runs permanently; it is not switched on.

Filter capacity 1.2 Tbit/s

1.2 Tbit/s filtering capacity, always active

Basic protection is included in every product and does not need to be switched on. It runs permanently, not just after a call to support.

Mitigation process — defending against an attack

  1. t + 0 sDetection via samplingEvery border router exports sFlow — a sample of the traffic — at a ratio of 1:2048, i.e. every 2,048th packet. The evaluation runs every second against baselines per prefix, which are formed from the last 14 days.
  2. t + 3 sSignature matchingIf the threshold is exceeded, the traffic pattern is checked against over 400 known attack signatures — from UDP amplification and SYN floods to HTTP request floods.
  3. t + 9 sRedirection to the scrubbing centresThe affected target address is announced via BGP as a /32, i.e. individually, to the scrubbing centres — the filtering centres in Frankfurt am Main, Berlin and Helsinki. From here, all traffic for this address passes through the filters.
  4. t + 18 sFilters activeFiltering is stateful: rate limiting per source, checking the TCP handshake, dropping packets with implausible combinations. Legitimate traffic flows back to the location via a GRE tunnel.
  5. t + 3 minFine-tuningIf advanced protection is booked, Layer 7 rules also apply: behavioural analysis per session, JavaScript checking and individual rules that you have stored in advance.
  6. End + 15 minDeactivation and reportIf the traffic falls below the threshold for 15 minutes, the redirection is reversed. A report with the timeline, peak values, vectors and the top source networks is then available in the customer account.

What basic protection covers

Amplification attacks via DNS, NTP, memcached and SSDP, SYN and ACK floods, fragmented packets, attacks with spoofed source addresses. This class accounts for the vast majority of incidents.

Volumetric, Layer 3 and 4

What advanced protection is needed for

Request floods against expensive endpoints, Slowloris — attacks that intentionally keep connections open —, distributed login attempts and attacks that behave like real users. These patterns cannot be cleanly separated volumetrically.

Layer 7 · from €49.00$56.84 per month, net

Levels of DDoS protection
OptionPrice / month
Basic DDoS protectionStandardVolumetric filtering up to 1.2 Tbit/s. Included in every plan.included
DDoS protection advancedLayer 7 analysis, behaviour patterns and individual mitigation rules.€49.00$56.84
DDoS protection gamingProtocol-specific filters for UDP game protocols with under 1 ms additional latency.€89.00$103.24

All amounts net, plus 19% VAT.

Filter capacity
1.2 Tbit/s
across three scrubbing centres
Detection time
3 s
Median over the last 12 months
Additional latency
under 1 ms
measured in the gaming profile
Attacks in 2025
18,412
automatically mitigated, without a ticket

42 PoPs on one Anycast address

A PoP is a delivery location at the network edge; Anycast means that all are accessible under the same IP address and every device ends up at the nearest one. One origin, one address, the same everywhere — routing is handled by the network and not a DNS trick waiting for expiring caches.

Cache rules

Rules apply to path patterns, file extensions, request methods, headers and query parameters. For each rule, you can define cache duration, handling of query strings, Vary headers and cookie forwarding.

Without a rule, the origin's Cache-Control applies. If this is also missing, nothing is cached — the CDN does not invent a shelf life.

Up to 100 rules per zone, evaluated from top to bottom

Invalidation

Invalidation can be done individually by URL, by prefix or via cache tags provided by the origin in the response header. A tag purge hits all objects with this tag, regardless of the path.

For deployments, the variant with tags is preferable: one call instead of a thousand URLs, and the counter stays low.

At all PoPs under 30 s · 5,000 requests per day

Origin protection

All PoPs fetch missing objects via an upstream intermediate layer. This typically reduces requests at the origin by 90 percent for a cold cache.

Stale-While-Revalidate — expired objects are delivered while the CDN renews them in the background — continues to deliver the last valid response for up to 24 hours in the event of an origin failure.

Origin Shield at a location of your choice

Prices per delivered terabyte

Billing is based on the volume that the PoPs deliver to end devices. Retrieval from the origin is included, as are TLS, HTTP/3 and invalidation. The scale is sliding: you pay the price of the respective tier reached for each terabyte.

CDN pricing tiers per delivered terabyte
Volume tierPrice per TBExample 50 TBNote
First 10 TB€9.90$11.48€495.00$574.20Entry tier, no minimum commitment
10 to 100 TB€7.40$8.58€370.00$429.20Automatically upon exceeding the first tier
100 to 500 TB€5.20$6.03€260.00$301.60Typical tier for media libraries
From 500 TB€3.90$4.52€195.00$226.20Above this on request with annual commitment

All amounts net, plus 19% VAT. The comparison column calculates all 50 TB at the respective tier price so that the tiers remain comparable. Actual billing is tiered: the first 10 TB at the first tier, the rest at the second.

Technical specifications

PoPs
42 delivery nodes at the network edge
Addressing
Anycast via IPv4 and IPv6
Protocols
HTTP/1.1, HTTP/2, HTTP/3
Compression
Brotli and gzip, generated at the PoP
Image conversion
AVIF and WebP based on Accept header
Object size in cache
up to 20 GB
Certificates
ACME, automatically renewed
Logs in the account
Raw data 30 days, aggregated 13 months
Availability in the vRack
usable as a private origin

IPv4 scarce, IPv6 in abundance

Every system comes with one IPv4 address and a /64 IPv6 prefix. Additional IPv4 subnets are possible, but are subject to the allocation rules of the RIPE NCC, the address registry for Europe. Below are the two special cases: the address that moves between systems, and the block that belongs to you.

IPv4 subnets and their monthly prices
OptionPrice / month
1 × IPv4 + /64 IPv6StandardStandard configuration, included in the price.included
/30 subnet (4 × IPv4)2 additional usable addresses.€6.00$6.96
/29 subnet (8 × IPv4)6 additional usable addresses.€14.00$16.24
/28 subnet (16 × IPv4)14 additional usable addresses.€27.00$31.32
/27 subnet (32 × IPv4)Proof of use required30 usable addresses. Justification required according to RIPE policy.€52.00$60.32

All amounts net, plus 19% VAT. · no setup fee

RIPE allocation policy

IPv4 addresses have been exhausted since 2019; the RIPE NCC only allocates from returned space. Therefore, we require evidence of use from a /27 — which services need which address and why a shared address is not sufficient.

The review usually takes one working day. Unused allocations are reclaimed after 60 days; this is not harassment, but a condition of our own allocation.

Evidence required from a /27

IPv6 and reverse DNS

A /64 is enough for one segment, a /48 for an entire network with 65,536 segments. Both cost nothing. You set reverse DNS records — the name an address returns in a reverse lookup — yourself in the customer account, for both IPv4 and IPv6.

We announce your own address ranges via our AS number — evidence, process and deadlines can be found below under own address block.

/64 included, /48 on request

Managed IPv4
412,672
from own allocations
RPKI-signed
100%
all prefixes with valid ROA
Locations live
5
with own address allocation
Reverse DNS
Self-service
Change active within 60 seconds

Floating IP — an address that moves

A Floating IP belongs to the account, not the system. It can be switched from one instance to another within a location — during failover, version upgrades or when a server is replaced. The detour via DNS is eliminated, and with it the waiting time that every cache between you and the caller extracts from a TTL — the validity period of a DNS record.

Switchover process

  1. t + 0 sSwitchover requestedA call in the customer account or via the API specifies the target system. A confirmation, a maintenance window or a ticket are not required.
  2. t + 1 sRoute changed in the backboneThe address is rewritten as a /32, i.e. individually, to the edge router of the target system and withdrawn from the previous one. Both happen in the same transaction, so the address is never in two places at once.
  3. t + 4 sEffective in the networkMedian of switchovers over the last twelve months. Existing connections to the old system drop — the switchover does not replace connection synchronisation, it only moves the address.
  4. t + 10 sGuaranteed upper limitAt this point at the latest, the address is reachable on the new system. A DNS record is not touched in the process, so no one has to wait for a TTL to expire.

Billing by state

As long as the address is attached to a running system, it is its included IPv4 address and costs nothing extra. Only the reservation without usage is billed — the case where a scarce address is occupied without working.

Billing of a Floating IP by state
StatusWhat appliesBilling
Bound to a systemCounts as the included IPv4 address of this system.without charge
Reserved, not boundThe address remains allocated to you and is not available to anyone else.€0.0024$0.0028 / h€1.73$2.01 per month
60 days without bindingThe allocation is withdrawn after notification — the same rule as for unused subnets above.not applicable

All amounts net, plus 19% VAT. The hourly rate is derived from the IPv4 scale: €52.00$60.32 for a /27 with 30 usable addresses results in €1.73$2.01 per address and month, divided by 730 hours. Calculations are unrounded, rounding only occurs on output.

Limits

Address families
IPv4 and IPv6
Floating IPs per account
32, more on request
Switching scope
within a location
Switches per hour
60 per address
Reverse DNS
moves with the address
DDoS protection
applies to the address, not the system
Target systems
Cloud instance, VPS, dedicated server
Control
Customer account, API, Terraform provider

Your own address block — BYOIP

If you already hold your own address block, you can bring it with you. We announce it via AS204812; the addresses remain yours, the allocation remains with your registry. For access lists with partners, for reputation in email delivery and for every contract that contains an address, nothing changes when you move.

From proof to announcement

  1. Step 1Proof of controlAn LOA — Letter of Authorization — on the letterhead of the registered organisation, signed by an authorised signatory. It specifies the prefix, the period and us as the announcing network.
  2. Step 2ROA in the RPKIThe RPKI is the registry that states which network is allowed to announce a prefix. You deposit a ROA object there in the portal of your Regional Internet Registry, listing AS204812 as the permitted origin AS for the prefix. Without a valid ROA, large networks discard the announcement — the block is then announced, but not reachable.
  3. Step 3Route object in the registry databaseAdditionally, a route or route6 object in the RIPE database. Several large networks still build their prefix filters from this and not from the RPKI alone.
  4. Step 4Verification by usWe cross-check the LOA, ROA, route object and the registered organisation against each other. This usually takes two working days. If something does not match, we tell you what is missing — we do not announce anything we cannot prove.
  5. Step 5AnnouncementAfter approval, the prefix goes into announcement within one working day. It is usually globally visible after less than four hours; individual networks update their filters on a daily basis, so we expect up to 24 hours.

What we announce

IPv4, smallest block
/24 — smaller is filtered globally
IPv4, largest block
/16
IPv6, smallest block
/48
IPv6, largest block
/32
Origin
own allocation or transfer from an LIR (Local Internet Registry)
Announcing AS number
AS204812 or your own
Locations per prefix
one or more, also as Anycast
Setup and operations
without charge

Put together network options in the configurator

You put together uplink, vRack, gateway, Load Balancer, DDoS level and IPv4 subnet in the network configurator; the amounts there are the same as in the tables above. Connect and the announcement of your own address block do not go through the cart — both require a cross-connect or evidence and therefore a conversation.

Backbone
18.4 Tbit/s
Peering points
94
DDoS filter
1.2 Tbit/s
Load Balancer from
€12.00$13.92