Skip to content
A Akamai Security Reference

Product deep dive

Prolexic

Network-layer DDoS defence for everything that is not HTTP: entire IP subnets, DNS infrastructure, VPN concentrators, mail, gaming and voice traffic, routed through globally distributed scrubbing centres.

Why a separate product from the web edge

The Akamai edge platform inherently absorbs attacks against HTTP/HTTPS properties it proxies. But an enterprise also runs services the CDN does not front: SIP trunks, IPsec/SSL VPN concentrators, SMTP, authoritative DNS on your own IPs, game servers, SFTP and legacy TCP applications. Prolexic protects those by routing entire network prefixes through scrubbing centres, at layers 3 and 4, independent of protocol.

How traffic gets to a scrubbing centre

BGP route advertisement

You advertise your prefix (typically a /24 or larger for IPv4) from Prolexic's scrubbing centres instead of, or in addition to, your own transit. Internet traffic destined for that prefix is drawn into the nearest scrubbing centre by anycast, filtered, and only clean traffic is delivered onward to your datacentre.

Internet  --->  Anycast scrubbing centres (multi-Tbps, globally distributed)
                    |  filters: ACLs, flowspec, signatures, behavioural
                    |  drops: spoofed, malformed, amplified, out-of-state
                    v
                Clean traffic returned over GRE tunnels
                    or a dedicated interconnect
                    v
                Customer datacentre / origin

Return path options

Always-on versus on-demand

Always-onOn-demand
RoutingTraffic permanently flows through scrubbingRoutes are advertised only when an attack is declared
Time to mitigateImmediate — controls are already appliedMinutes: detection, decision, BGP convergence
LatencySmall, constant additionNone in peacetime
Best forBusiness-critical, frequently targeted, or compliance-driven servicesCost-sensitive or latency-critical services with rare exposure

Always-on is strongly preferred for anything whose outage has a revenue or safety cost. The failure mode of on-demand is human: someone must notice, decide and trigger, at 3 a.m., correctly.

What the scrubbing centre actually does

  1. Coarse filtering — drop protocols and ports you never use, invalid source addresses (bogons, RFC1918), and malformed packets. The single highest-value control most customers under-use: a tight proactive ACL that permits only the protocols your services genuinely serve.
  2. Flowspec-style rules — rapid, granular drop/rate-limit rules matched on 5-tuple, packet length, TCP flags and fragmentation state.
  3. Signature and heuristic matching — known amplification signatures (DNS ANY, NTP monlist, memcached, CLDAP, SSDP), reflection sources, booter fingerprints.
  4. Stateful TCP validation — SYN cookies and out-of-state ACK/RST dropping so spoofed L4 floods never touch your firewalls.
  5. Behavioural anomaly detection — deviation from learned per-prefix, per-protocol baselines.
  6. SOC involvement — Akamai's SOCC applies and tunes countermeasures during an event under an agreed runbook.

Proactive mitigation controls

Rules pre-agreed and pre-loaded so that mitigation is applied the moment attack traffic appears, rather than after analysis. This is what makes a zero-second mitigation SLA meaningful: the controls are already in the data path. Building them requires you to document, honestly, which protocols and ports each protected prefix must serve — an exercise that itself usually finds exposed services nobody remembered.

Runbook design

A Prolexic deployment is only as good as its runbook. It should record, per protected prefix:

Test the routing, not just the plan. Schedule live GRE/BGP failover drills. The most common real-world failure is not the scrubbing — it is an MTU mismatch, a stale ACL on your own border router, or an expired contact.

Pairing Prolexic with the rest of the stack

Reference documentation compiled from Akamai TechDocs, Akamai blog/newsroom material and Cloudflare Learning Center fundamentals. Product behaviour and limits change — validate against current vendor documentation before production use.