Locally owned and operated in Harlingen, TX ·  our crews, our fiber, our NOC
Home / DDoS Protection
DDoS protection, operator-built

Attacks hit our edge.
Your network stays clean.

Always-on DDoS detection and scrubbing. An on-prem appliance filters at your site, and larger floods divert across our Texas backbone. Attack traffic is dropped before it eats your bandwidth.

Detection in seconds Line-rate XDP scrubbing No IP or DNS changes Works with any upstream
How it works

Detect. Divert. Scrub. Return.

FastNetMon sensors detect the attack at line rate. BGP announcements divert it. XDP filters scrub it. Only clean traffic comes back to you.

1. Attack Launches

A volumetric flood targets your prefixes from botnets or reflection attacks.

2. Divert & Scrub

Traffic diverts to our scrubbing centers, where XDP line-rate filters drop attack flows in microseconds.

3. Clean Traffic Returns

Only legitimate traffic is sent back to your network. Your users keep working.

Anomaly-based detection SYN proxy at the scrubbing edge BGP diversion with hold-down Only clean traffic returned
Service tiers

Pick Your Level of Armor.

Detection-Only

A FastNetMon sensor at your edge with 24/7 alerting to your team. See attacks as they start and respond on your terms. The first step toward full protection.

Entry tier

Always-On Scrubbing

An on-prem appliance filters your traffic at line rate, all the time. Attacks bigger than your circuit divert upstream. Your firewall never sees the flood.

Most chosen

Network / ISP Grade

Scrubbing as a service for ISPs and multi-site enterprises. Protect your own customers on our infrastructure, with white-label reporting.

Wholesale
Coverage

What We Stop, and How.

Attack vectorStoppedHow
UDP floods & amplification (DNS, NTP, memcached)YesUpstream diversion + line-rate filtering
SYN floods & TCP state exhaustionYesXDP SYN proxy at the scrubbing edge
Botnet HTTP/HTTPS floods (L7)YesAnomaly thresholds + per-source limits
Reflection attacks (SSDP, CLDAP, CharGEN)YesUpstream blackholing of spoofed sources
Slow-loris & application exhaustionYesOn-prem appliance deep inspection

Detection is anomaly-based, not signature-based, so it catches novel and zero-day volumetric attacks without reconfiguration.

Why TX Fiber

Operator-Built. Battle-Tested.

We run it ourselves

It's the same stack that protects TX Fiber's own carrier network and customers, continuously tuned against real attacks.

Texas-local scrubbing

Scrubbing capacity in our San Antonio edge PoP and across our Texas backbone. Clean traffic doesn't cross the country and back.

Works with your setup

On-prem protection needs no DNS changes and no BGP prep. Keep your IP space, firewall, and upstreams. We add protection around them.

FAQ

Straight Answers on DDoS.

How fast does protection kick in?
Detection typically fires within seconds of an anomaly. On-prem filtering is instant, with no diversion window, for any attack the appliance can absorb locally. Larger volumetric attacks trigger BGP diversion automatically, with hold-down timers to prevent route flapping.
Do I need to change my IP addresses?
No. DDoS protection works with your existing IP space. On-prem mode filters inline. Upstream diversion mode announces your prefixes from our scrubbing centers during an attack.
We're an ISP. Can we protect our own customers?
Yes. The Network / ISP Grade tier gives you scrubbing as a service with white-label reporting for your customers. Regional networks already lean on our infrastructure.
What happens to legitimate traffic during an attack?
Scrubbers filter on behavior, not blanket rate limits: per-flow anomaly scoring, a SYN proxy for legitimate handshakes, and allowlist propagation. Clean traffic passes. Attack flows die at the edge.

Find Out What You're Up Against.

Get a no-cost NetFlow assessment of your traffic baseline. Then decide how much armor you need.