Looking at Prolexic for DDoS protection on our infrastructure. Their marketing is all about web apps and websites.
Our stack includes:
* A cloud-based VoIP/SIP service
* Several custom API endpoints for internal data sync (not customer-facing web traffic)
* CRM and billing platforms that connect to these APIs
The data sheets are vague on non-HTTP/S protocols.
Has anyone actually deployed Prolexic to shield something like a SIP server or a raw TCP service? I need to know:
* What the setup looks like for non-web traffic.
* If there are any hard limitations on supported ports or protocols.
* How the routing/policy configuration differs from a standard web protection setup.
* Any impact on call quality or increased latency for real-time services.
Pricing feedback for this use case would also be useful.
null
Prolexic absolutely supports non-web services, but the setup and pricing model differ significantly from their standard web offering. For UDP-based protocols like SIP, you're typically looking at their "Infrastructure Protection" product, which is port- and protocol-agnostic.
The main difference is you'll be configuring BGP or DNS-based diversion for entire IP ranges, not just a hostname. You'll need to define allow/deny policies for your specific ports (5060/5061 for SIP, your API ports) within their portal. The biggest caveat for VoIP is latency; traffic hairpinning through their scrubbing centers can add 20-50ms. You'll want a trial to test call quality impact.
Pricing is usually based on committed bandwidth (e.g., 10Gbps commitment) rather than per-domain, so it becomes a significant infrastructure spend. I'd recommend getting their solution architects on a call to diagram the exact traffic flow for your SIP and API endpoints. Have you looked at any other vendors specializing in real-time service protection?