A Better Route: How StormWall Became Part of the Network

The foundation of any connectivity provider’s business is continuous network availability and resilience. This is the level of service customers expect every day. However, in fast-growing, high-value connectivity markets, providing this level of DDoS protection in-house can be difficult and costly. A practical approach is to bring in a specialized partner that can handle large-scale traffic scrubbing.

A global connectivity service provider was expanding its network across the Middle East and began facing regular DDoS attacks. The company started looking for a DDoS protection partner. StormWall’s solution not only fit seamlessly into its architecture but also became part of the provider’s network as a transit node at the routing level.

How StormWall became part of a connectivity provider’s network, strengthened DDoS protection, and supported its expansion across the Middle East.

At a Glance

Customer / IndustryGlobal connectivity service provider and ISP aggregator headquartered in the Netherlands
Our servicesStormWall for Networks — BGP-based DDoS protection, On-Demand 
Protected resourcesNetwork connectivity: global internet services and private solutions for corporate clients 

Customer: a Global Connectivity Service Provider

Our customer is a global connectivity service provider and ISP aggregator headquartered in the Netherlands. The client preferred to remain anonymous. The company helps enterprises, managed service providers, system integrators, and carriers source, design, deploy, and manage internet and private connectivity across more than 190 countries, all under one contract, one invoice, and one point of contact.

Our client does not own the last-mile infrastructure. Instead, the company works with more than 3,000 ISPs worldwide, selecting the best local provider for each site and orchestrating connectivity through an automated platform.

The provider’s customers run global operations over the connectivity it provides, so any disruption affects not only the company itself but also every enterprise that depends on its services. Downtime carries direct commercial, contractual, and reputational consequences. For a provider whose product is uptime, resilience is not an added feature — it is the baseline its customers expect every day.

Challenge: a Growing Network Needed Scalable Protection 

The provider was expanding its presence in the Middle East, particularly in Dubai, Abu Dhabi, and Fujairah. The region is a fast-growing, high-value market for connectivity. As an operator running public-facing internet infrastructure, the company had been regularly targeted by DDoS attacks for several years. Most of these were volumetric and network-layer attacks designed to exhaust available bandwidth.

This created a constant background risk and required a high level of protection for the provider’s critical network infrastructure. The company detected and mitigated a significant portion of the attacks on its own. However, as the network scaled, relying on standard cloud-based filtering was no longer enough. The provider needed a specialized protection layer that could scale beyond what the company could reasonably absorb on its own. 

Solution: Protection Built to Fit the Network 

To evaluate specialized DDoS protection options for its network, the company conducted online research, compared offerings from different vendors, and ultimately selected StormWall.

We offered the provider a solution designed to fit the way its network operates. The company deployed StormWall for Networks, which was integrated at the BGP level and activated on demand when an attack was detected.  

This protection model aligns closely with the provider’s network architecture. The company detects and mitigates smaller attacks independently, while larger incidents trigger external traffic scrubbing. This gives the company the scale it needs without giving up control over its network.

StormWall’s distributed network, including a scrubbing center in the UAE, allows malicious traffic to be filtered closer to the sources of attacks.

“StormWall adds a dedicated, high-capacity traffic-cleaning layer behind our own defenses. When traffic is rerouted for scrubbing, clean traffic keeps flowing to our customers while the attack is filtered out, so we can handle far larger events with confidence,”

says the CTO of a global connectivity provider.

Deployment: From AntiDDoS Service to Network Node 

StormWall specialists traveled to the provider’s data center, completed the physical connection, and integrated the solution into the Middle East network at the routing level. This means the service does not operate simply as an external “cloud filter” based on DNS redirection. Instead, it is integrated directly into the network topology as a full-fledged transit node.

The provider routes traffic through this node using BGP announcements. StormWall assigned the company a dedicated IP address, which was used for routing. Under normal conditions, traffic flows directly to the provider’s network. When a DDoS attack targets the protected IP prefixes, a BGP announcement is initiated. Traffic is rerouted for scrubbing, malicious traffic is blocked, and legitimate traffic is returned to the provider’s network.

The ability to activate protection on demand via BGP was an important advantage for the company’s AS. It provides a cost-efficient protection model while allowing the provider to adjust its protection strategy to changing business needs. We worked through the interfaces and prefix lists in detail and also planned for additional tunnels and prefixes to be added in the future.

The provider later configured five firewall rules to process UDP and TCP traffic. It also configured rate limits, filters, and a rule to drop specific packets.

“Bringing the service online fit comfortably within our normal network change process and did not require major reengineering on our side. Adding a new mitigation path to a live, multi-site network always requires careful planning and testing. We worked closely with StormWall to validate routing and failover before relying on it, and the setup went smoothly,”

adds the CTO of a global connectivity provider.

Results: Confidence in Network Stability Under Attack 

After StormWall was deployed in late 2025, the provider’s network continued to face regular low-volume DDoS attacks. When traffic of a particular type exceeded the thresholds defined by the rules, the company received an email alert indicating that an attack was underway and could respond promptly.

When traffic of a particular type exceeded the thresholds defined by the rules, the company received an email alert indicating that an attack was underway and could respond promptly.

Since deploying StormWall, a global connectivity provider has gained:

  • A reliable additional layer of protection.
  • Confidence in its ability to withstand even the most powerful attacks, including those exceeding the company’s own mitigation capacity.
  • Improved network resilience.
  • The ability to meet its service availability commitments to customers.
  • A trusted partner with expertise in DDoS protection that goes beyond simply providing a service.
  • Responsive technical support.

“We value StormWall acting as an extension of our own team and giving us an extra layer of protection we can rely on. Knowing StormWall is ready to scrub traffic at scale lets us protect our customers with complete confidence. Keep doing what you do well: fast, knowledgeable support and a genuine partnership approach,”

says the CTO of a global connectivity provider.

Network Protection from DDoS Attacks

  • Activate protection within 10 minutes
  • 24/7 technical support