FAQ
Frequently asked questions about the NaWas
NaWas is working hard on a “distributed network architecture” that will be available in as many European countries as possible. With NaWas, you can request an overview of all available locations. The distributed network architecture will soon be operational outside Europe as well.
All parties with their own AS number can connect to the NaWas.
To connect to the NaWas, a port must be available at one of the following parties: AMS-IX, ERA-IX (Amsterdam/Frankfurt/Vienna), NL-ix, LINX, Top-IX, MIX, VIX. You can also connect to the NaWas with a cloud interconnect from DCspine or Equinix Fabric.
If you don’t have a port at one of the connected Internet Exchanges, NaWas can return the clean traffic via a GRE tunnel.
NaWas is part of NBIP; a non-profit foundation established by the internet community and technical specialists. This means that its operation and connection are easily understood by the target audience. The goal is to make the internet safer. By connecting to NaWas, you make the internet a bit safer.
NaWas participates in multiple initiatives, such as the Anti-DDoS Coalition, and shares knowledge with its own participants and several universities, like the University of Twente (UT). Additionally, NaWas also contributes to the development of non-profit institutes such as the DDoS ClearingHouse.
The NaWas infrastructure is developed as an on-demand service. After detection of an attack, the traffic is routed via BGP to NaWas hardware, and then the mitigation process begins. We redirect the traffic through our own connections. This means you don’t have to invest in extra capacity yourself, which will save you costs. After the attack, the traffic is routed back, so it no longer passes through NaWas. As a result, NaWas only needs to be set up based on attack traffic, keeping costs low. Currently, NaWas is exploring the possibilities of offering an always-on solution.
The mitigation process starts within a few minutes after the traffic is redirected to NaWas hardware.
Attacks can be detected either manually or using an automated tool. NaWas recommends installing detection tools, as attacks occur 24 hours a day. NaWas has extensive knowledge of Fastnetmon and GENIE ATM tools and can assist with the supply and implementation of detection tools
You can sign up immediately by using the contact form on the website, by sending an email to bureau@nbip.nl or, in the event of a direct attack, by sending an email to support@nbip.nl
NaWas is among the largest anti-DDoS scrubbing centers in Europe. However, more important is how large and numerous the connections of our participants and the network are. This determines how efficiently NaWas can process attacks.
NaWas operates three mitigation platforms, two of which are located in a redundant setup in Amsterdam and one in Denmark. NaWas is developing a ‘distributed architecture’ that enables traffic to be mitigated on a global scale.
In relation to the OSI model, NaWas can mitigate DDoS traffic on all layers. For Layer 7 (application layer), NaWas will mitigate based on header fields and not through (deep) packet inspection.
NaWas uses a multi-vendor setup where multiple Triple A vendor devices are arranged in line (funnel). The operation is comparable to a car wash, where multiple devices in sequence first wash the rough part and later the smaller parts, thus removing attack traffic. NaWas continuously innovates the anti-DDoS solution and always applies the most effective and newest techniques.
The pricing model consists of a flat-fee model. The price is determined by the number of prefixes (based on /24) you want to protect. You pay slightly more for larger quantities. Prices are invoiced on a monthly, quarterly, or yearly basis.
In addition to the fee for NaWas, you pay a small monthly contribution for NBIP membership and a one-time contribution for the setup. Due to the non-profit nature of the services, the costs are low compared to similar services from other providers.
NaWas has a BGP session with participants on the clean side (with IXPs) on a private VLAN. A member can redirect a specific prefix or /24 by advertising that prefix on the NaWas BGP session. NaWas advertises the prefix on our upstreams (transits & peering). So the trigger for redirecting is done manually or automated by the participants.
After receiving a prefix or receiving a new DDoS attack on an existing prefix, the NaWas support team receives a notification of the event. The support team checks if the attack is being mitigated well enough and if adjustment is necessary. When the attack is over, the member receives an email with a report on the details of the attack.
If an attack lasts longer, NaWas sends an interim report. Participants can view the report on the portal.
Yes, the internet does not accept subnets smaller than a /24. However, we are working on an architecture based on a /32 setup that can be used alongside the /24.
In principle, there is no packet loss. Parties that don’t yet know the more specific follow the less specific. Learning the more specific happens very quickly, usually within a few seconds.
The more parties know the more specific, the more the attack traffic disappears. We assume that clean traffic still passes through. Furthermore, it depends very much on the type of attack to what extent the mitigation systems can immediately reduce the malicious traffic. Most attacks are mitigated immediately. In some cases, it may take a few seconds
In some cases, a portion of the attack traffic below a certain threshold may still be allowed through. If that’s the case, the advice is to contact NaWas as soon as possible if the residual traffic causes disruption. After advertising, traffic will route through NaWas within a second, and it may take a few seconds for the entire internet to know the route.
Contact
Heb je een vraag of opmerking? Neem dan contact met ons op via onderstaand formulier.