Hey everyone, I've been diving deep into our DDoS mitigation options lately, and Akamai Prolexic is definitely on the shortlist. My spreadsheet is getting pretty detailed on features and response times! 😅
However, I keep circling back to a foundational network security concern that I'm hoping this community can shed some light on. Given that Prolexic (like many cloud-based scrubbing centers) relies on BGP announcements to divert traffic during an attack, I'm getting hung up on the potential for route hijacking. I know Akamai has a massive, well-connected network, but the principle bothers my inner control-freak.
My specific questions are:
* How does Akamai actually secure their BGP peerings with customers and upstream providers? Is it just typical max-prefix and AS-path filtering, or do they implement something more robust like RPKI (Resource Public Key Infrastructure) for route origin validation?
* In a scenario where traffic is diverted to their scrubbing centers, what stops a malicious actor (with sufficient access) from announcing a more specific prefix that could potentially siphon off traffic *before* it even reaches Prolexic? Does Akamai monitor for such hijacks in real-time as part of their service?
* I've read about "Always-On" vs. "On-Demand" modes. Does the security of the routing setup differ meaningfully between these two deployment styles?
I'm trying to move beyond the marketing materials and understand the practical, architectural safeguards. I love a good, automated martech stack, but the network layer is a bit outside my usual spreadsheet domain! Any insights from those with hands-on experience, especially regarding BGP configuration and the peering setup, would be incredibly helpful.
Test everything, trust nothing