600Gbps Corero DDoS Protection: Why Fast2Host Runs World-Class Edge Defence
How Fast2Host’s always-on 600Gbps Corero SmartWall DDoS protection works — sub-second mitigation, attack types covered, capacity stats, benefits vs scrubbing centres, and why it’s included free on AS48825.
DDoS attacks are still one of the fastest ways to take a UK website, game server or SaaS API offline — without ever stealing a password. Fast2Host defends every customer service with always-on, in-line 600Gbps Corero SmartWall filtering on our AS48825 network edge. Corero is widely regarded as a world-leading DDoS mitigation platform for service providers; we run it as standard infrastructure — not an emergency bolt-on.
This guide covers the numbers, benefits, how it works, and how that compares with on-demand scrubbing.
| Metric | Fast2Host figure |
|---|---|
| Mitigation capacity | 600 Gbps |
| Typical time to mitigate | Under 1 second |
| Operating mode | 24/7 always-on, in-line |
| Coverage | 100% of services (hosting, VPS, dedicated, colo, connectivity) |
| Extra fee | £0 — included free |
| No null-routes | Surgical per-packet filter — clean traffic keeps flowing |
Full product detail: DDoS protection.
Why Corero SmartWall is world-class
Service-provider DDoS gear is a short list. Corero SmartWall sits among the leaders for real-time, hardware-accelerated, in-line mitigation — the kind carriers and hosting platforms use when “turn scrubbing on later” is not acceptable.
What that means in practice:
- In-line at the edge — every packet entering AS48825 is inspected continuously.
- Hardware acceleration — line-rate filtering without turning the internet into molasses.
- Surgical drops — attack packets removed; legitimate users are not blackholed.
- Sub-second response — detection and mitigation typically complete in under a second, not after a ticket and a BGP divert.
We pair that platform with Cambridge NOC ownership: monitoring, attack analysis on request, and engineering for colo customers who announce their own prefixes.
The speed gap: always-on vs scrubbing centres
| Approach | Typical delay before mitigation starts | Risk window |
|---|---|---|
| Fast2Host Corero (always-on) | <1 second | Minimal |
| Manual / ticket “enable DDoS” | ~5 minutes (if someone is awake) | Cart / VoIP already failing |
| Classic on-demand scrubbing | Often 15–30+ minutes (detect → escalate → BGP redirect) | Full outage for the wait |
Industry outage studies regularly put online downtime in the thousands of pounds per hour for mid-size retailers once cart and payment fail. Using a simple illustrative peak of ~£2,000/hour:
| Mitigation delay | Illustrative revenue at risk (@ £2k/hour) |
|---|---|
| <1 second (Corero) | ~£0 material cart loss |
| 5 minutes | ~£170 |
| 15 minutes | ~£500 |
| 30 minutes | ~£1,000 |
Illustrative only — reputation damage, SLA credits and staff overtime often dwarf the cart line. The point is the wait, not the exact pound figure.
Always-on edge defence is how we keep that wait near zero.
What we stop (attack classes)
| Class | Examples | How the edge helps |
|---|---|---|
| Volumetric | UDP/ICMP floods, DNS/NTP/SSDP reflection | 600Gbps headroom absorbs floods before your port saturates |
| Protocol / state | SYN/ACK floods, fragments, table exhaustion | Dropped at line rate before firewalls melt |
| Application (L7) | HTTP(S) floods, low-and-slow, abusive GET/POST | Behavioural heuristics; surgical filter |
| Multi-vector | Carpet-bombing, rotating vectors, short bursts | Always-on inspection follows the shift — no re-ticket |
Edge DDoS is not a full application WAF. Keep WordPress firewalls / Imunify360 / ModSecurity for SQLi and plugin exploits — network DDoS plus app security is the working stack.
Benefits for Fast2Host customers
- Included, not upsold — VPS, dedicated, colo, hosting and connectivity sit behind the same edge. No “DDoS insurance” panic upgrade mid-attack.
- No null-route culture — we filter; we do not “protect” you by announcing your IP into a blackhole.
- Predictable latency — in-line hardware path; traffic is not hairpinned to a far scrubbing PoP after the blast starts.
- 100% coverage — new services inherit defence when they go live on AS48825. Zero customer config.
- UK ops — 24/7 Cambridge NOC visibility; sustained campaigns get human analysis when needed.
- Colo-ready — BYO ASN / prefixes engineered with the same philosophy — mitigation designed with you, not a generic cloud ticket.
- Capacity headroom — 600Gbps is sized for large, complex volumetric events, not brochure “1Gbps magical scrubbing”.
Services covered include Cloud VPS, dedicated & bare metal, gaming servers, colocation, web/reseller hosting, and ethernet/connectivity.
How it works (four steps)
- Continuous inspection — packets hit Corero SmartWall appliances in-line at the AS48825 edge. Nothing to enable.
- Real-time detection — hardware heuristics and behavioural analysis separate attack from legit.
- Automatic mitigation — bad traffic dropped at line rate (typically <1s); clean traffic continues.
- Visibility — NOC watches events; ask for attack detail on unusual or long campaigns.
Capacity in context
Public DDoS reports from large CDNs have shown multi-terabit peaks on the global internet. Provider edge capacity is still meaningful when:
- Attacks target your access / hosting uplink (not the whole internet)
- Amplification and carpet-bombing hit provider prefixes where SmartWall sits
- You need seconds, not a scrubbing appointment
Our 600Gbps mitigation capacity is the engineered headroom on the Fast2Host edge for the services we operate — combined with always-on Corero intelligence — which is why we can offer it free on every plan.
Quick comparison checklist
| Question | Fast2Host answer |
|---|---|
| Always-on or on-demand? | Always-on in-line |
| Vendor platform | Corero SmartWall (world-leading SP class) |
| Capacity | 600Gbps |
| Time to mitigate | <1 second typical |
| Null-routes your IP? | No — surgical filtering |
| Extra monthly fee? | No — included |
| Who watches it? | 24/7 UK NOC |
For the buying-criteria short version of always-on vs scrubbing, see also DDoS for UK businesses.
Bottom line
Fast2Host’s DDoS story is not a checkbox — it is world-class Corero SmartWall, 600Gbps of edge capacity, sub-second always-on mitigation, and zero fee on every service. That combination keeps UK hosting, game stacks and colo prefixes online while delayed scrubbing models are still dialling a ticket.
Explore the full service page: DDoS protection, or the AS48825 network that carries it. Questions about colo prefix coverage — talk to the team.