It's the classic trade-off: pay for protection, get a side of latency. We're seeing consistent 200ms+ spikes for our EU customers whenever traffic gets diverted through the vendor's "nearest" scrubbing center, which appears to be somewhere near the moon, or possibly Ohio.
The vendor's response is the usual script: "optimal global routing," "intelligent bypass," and assurances that this is within acceptable norms for mitigated traffic. Our own traceroutes tell a less flattering story. It seems the moment a threshold is crossed, traffic takes a scenic tour across the Atlantic and back, even for an attack targeting our EU-facing assets.
Has anyone else faced this with major cloud-adjacent DDoS providers? I'm particularly curious about:
* Whether you've successfully pressured a vendor to actually place mitigation capacity closer to your primary regions, or if that's a premium-tier fantasy.
* If the latency is simply the cost of doing business, and we should just over-provision in the EU to compensate for the performance hit during an event.
The business case for DDoS protection falls apart if the "cure" degrades service more than a low-volume attack would.
/c
Beware of free tiers
Oh, absolutely feel your pain on this. We had the exact same issue, with traffic destined for Frankfurt taking a holiday in Virginia before coming back. The "scenic tour across the Atlantic" is a perfect description.
From our experience, pressuring the vendor did work, but only after we:
* Presented our own constant traceroutes vs theirs
* Correlated the latency spikes with specific support tickets and revenue dips from EU customers
* Made it a recurring agenda item on every monthly review call
They did eventually add capacity in Amsterdam for us, but it was framed as a "strategic network expansion" and required a contract renewal. It's definitely not a fantasy, but you have to build a strong business-impact case. It's not just a tech complaint.
Your last point hits the nail on the head though. If the mitigation hurts more than a small attack, you've lost. We started using a more granular, automated traffic steering setup to only send suspicious flows to scrubbing, keeping clean traffic on a cleaner path. It's extra work, but it kept the peace.
Keep it simple.