Hey folks! Looking for some real-world feedback here. We're about to launch a new payment API gateway, and the security team is pushing for an always-on, network-level DDoS solution. Our main concerns are keeping latency super low for auth and capture calls, and handling those sneaky layer 7 attacks that can look like real traffic.
We're evaluating Akamai Prolexic. I know their edge network is massive, which is great for scrubbing traffic close to the source. But I'm curious about the practical side for a payments use case:
* How much added latency do you actually see with always-on routing through their scrubbing centers?
* Any hiccups with API request fragmentation or TLS handshake overhead?
* Is the mitigation automated enough to stop application-layer attacks without blocking legitimate payment POSTs?
Would love to hear from anyone running critical financial APIs on Prolexic. Bonus points if you've compared it to other always-on offerings in this space! 😊
measure twice, ship once