Nexusguard Bastions

The Ultimate DDoS Protection and Productization Solution for Communications Service Providers

Consistent, Reliable Hybrid Protection with Nexusguard Bastions

Nexusguard Bastions represents the next generation of fully managed solutions, delivering Nexusguard services to virtually any on-premises or edge location for a truly consistent and seamless hybrid experience. Built for Communications Service Providers (CSPs) facing the growing challenges of cyber attacks, Nexusguard Bastions combines carrier-grade hardware with proprietary technology, and is a culmination of over a decade of continuous development and expertise in combating cyber crime, making it a trusted ally in the fight against evolving cyber threats.

On-Premise and Always-On Threat Detection and Mitigation

Through Bastions servers, the Nexusguard Network Protection module delivers on-premise and always-on attack detection and mitigation for CSPs' infrastructure, keeping threats well at bay for maximum availability. As an extension to Network Protection, Clean Pipe offers CSPs a fully productized and ready to deliver DDoS protection-as-a-service to its customers that will benefit from additional layers of security, visibility and control.

Hybrid Cloud Protection for Low Latency and localized Data Residency

With Bastions, CSPs can deploy co-branded Nexusguard Cloud Services locally and at the same time enjoy Nexusguard's Extended Cloud Protection from the cloud. Bastions supports business requirements for low latency access to on-premises systems, local data processing and data residency regulations, while the protection by the Nexusguard Cloud provides security during trans-global security events.

How it works

On-Premise and Always-On Threat Detection and Mitigation

Through Bastions servers, the Nexusguard Network Protection module delivers on-premise and always-on attack detection and mitigation for CSPs' infrastructure, keeping threats well at bay for maximum availability. As an extension to Network Protection, Clean Pipe offers CSPs a fully productized and ready to deliver DDoS protection-as-a-service to its customers that will benefit from additional layers of security, visibility and control.

Hybrid Cloud Protection for Low Latency and localized Data Residency

With Bastions, CSPs can deploy co-branded Nexusguard Cloud Services locally and at the same time enjoy Nexusguard's Extended Cloud Protection from the cloud. Bastions supports business requirements for low latency access to on-premises systems, local data processing and data residency regulations, while the protection by the Nexusguard Cloud provides security during trans-global security events.

End-to-End DDoS Protection for Modern Networks

Consistent and Seamless Hybrid Experience

Experience the best of both worlds: Nexusguard Cloud’s robust hardware infrastructure, tools, and management controls combined with Bastions — delivering a seamless, unified hybrid solution with fully automated protection capabilities.

Comprehensive Security Services in a Single-Paned Dashboard

Security services shouldn’t operate in silo. Bastions allows the CSP to offer a full range of services to protect customer applications, networks and infrastructure, connectivity, and domain name services from all possible cyber attacks — all on the CSP's branded single-paned glass.

True Hybrid Protection

Nexusguard on-premise Bastions operates simultaneously with the Nexusguard Cloud to detect and mitigate threats in real-time, in contrast to traditional sequential-hybrid models that require activations that are often gated procedurally, technically and financially. Bastions and Nexusguard Extended Cloud protection offers a fully customizable solution that puts the control back into the CSP's hand on selecting the best strategy during each and every individual event.

Backed by Nexusguard Cloud 

Even the most robust on-premise systems can be overwhelmed when bandwidth is exhausted by massive attacks, leaving them ineffective. Bastions ensures your network stays secure by intelligently diverting and reducing risk through the Nexusguard Cloud during large-scale attacks — delivering uninterrupted protection and peace of mind.

24/7 Access to Dedicated Experts to Immediately Address your Concerns

Our 24/7 SOC and technical support team continuously monitor your network, ensuring rapid detection and mitigation of threats to keep your network protected and optimized at all times.

Built-in Return-on-Investment Mechanisms

With turnkey services ready to be delivered out of the box, CSP Product Teams can immediately roll out enterprise-grade DDoS protection and other Managed Security Services.

Benefits

Flexible On-Premises Deployment for Immediate Impact

Easily expand or enhance your existing CleanPipe offerings with Bastions’ on-premises deployment option. Designed for CSPs, this solution integrates seamlessly into your infrastructure, allowing you to scale your DDoS protection instantly without overhauling your network.
Easily expand or enhance your existing CleanPipe offerings with Bastions’ on-premises deployment option. Designed for CSPs, this solution integrates seamlessly into your infrastructure, allowing you to scale your DDoS protection instantly without overhauling your network.

Hassle-Free Protection with Fully Managed Support

Eliminate the complexity of managing infrastructure with Nexusguard’s fully managed service. From maintenance and upgrades to reducing downtime and operational risks, we handle the heavy lifting so you can focus on delivering reliable service without interruptions.
Eliminate the complexity of managing infrastructure with Nexusguard’s fully managed service. From maintenance and upgrades to reducing downtime and operational risks, we handle the heavy lifting so you can focus on delivering reliable service without interruptions.

Seamless Hybrid Integration for Maximum Flexibility


Combine the power of Nexusguard Cloud with Bastions’ on-premises services to create a seamless hybrid solution. Unified tools, hardware infrastructure, and management controls work together to ensure consistent performance and protection across environments, no matter where your operations are based.

Combine the power of Nexusguard Cloud with Bastions’ on-premises services to create a seamless hybrid solution. Unified tools, hardware infrastructure, and management controls work together to ensure consistent performance and protection across environments, no matter where your operations are based.

Unified Portal for Total Network Visibility

Simplify your cybersecurity management with a single, intuitive portal. Access detection and mitigation tools, track key metrics, and monitor your network’s status in real-time — all in one place. This unified view gives you a holistic understanding of your security posture, enabling faster and more informed decision-making.
Simplify your cybersecurity management with a single, intuitive portal. Access detection and mitigation tools, track key metrics, and monitor your network’s status in real-time — all in one place. This unified view gives you a holistic understanding of your security posture, enabling faster and more informed decision-making.

Win-Win-Win Outcomes

Increased Uptime and Reliability

Safeguard your customers' online presence and critical infrastructure from crippling DDoS attacks, ensuring maximum uptime and service reliability.
Safeguard your customers' online presence and critical infrastructure from crippling DDoS attacks, ensuring maximum uptime and service reliability.

Improved Customer Satisfaction

Enhance your customers' confidence and satisfaction by providing them with robust DDoS Protection-as-a-Service, strengthening your relationships.
Enhance your customers' confidence and satisfaction by providing them with robust DDoS Protection-as-a-Service, strengthening your relationships.

Confidence to Lead Without Crisis

DDoS attacks are disruptive, but dealing with them shouldn’t dominate your day. Nexusguard Bastions stops attacks before they become problems, giving you the confidence to focus on strategic priorities instead of firefighting.
DDoS attacks are disruptive, but dealing with them shouldn’t dominate your day. Nexusguard Bastions stops attacks before they become problems, giving you the confidence to focus on strategic priorities instead of firefighting.

Reduced Operational Costs

Offload the complexities of DDoS protection and focus on your core business objectives, while benefiting from Nexusguard's cost-effective DDoS mitigation solutions.
Offload the complexities of DDoS protection and focus on your core business objectives, while benefiting from Nexusguard's cost-effective DDoS mitigation solutions.

Increased Competitive Advantage

Differentiate your service offerings by providing best-in-class DDoS protection (Clean Pipe, Application Protection, Irigin Protection, DNS Protection) that your customers demand, giving you a competitive edge in the market.
Differentiate your service offerings by providing best-in-class DDoS protection (Clean Pipe, Application Protection, Irigin Protection, DNS Protection) that your customers demand, giving you a competitive edge in the market.

New Revenue Opportunities

Capitalize on the growing need for DDoS mitigation services and generate additional revenue from your customer base.
Capitalize on the growing need for DDoS mitigation services and generate additional revenue from your customer base.
We want to make the network environment for our customer as safe as they feel at home. Nexusguard offers a customized internet security solution so that our customers can continue to interact with us the way supposed to be and the way they want to—all the way without interruption.
We chose to partner with Nexusguard because of its specialty in DDoS mitigation. In fact, they not only focus on DDoS attacks, they are also curious about and strive to address the pain points they face.
Our customers are extremely satisfied with Nexusguard DDoS Protection solutions because they have sophisticated tools that give them visibility into their networks. With Netpluz mitigation facility commissioned in Singapore, powered by Nexusguard, our customers can expect proactive and intelligent mitigations to ensure only clean traffic reaches their network.
The Nexusguard solution secures our network with enterprise-grade SLAs. Most importantly, it ensures all business-essential applications have the uptime that they require.
When we have queries and new service requests, the Nexusguard team were able to attend to us promptly. This is a good partnership that every business would want to ensure our business plans are implemented smoothly.

FAQs

How does the deployment process work for Nexusguard Bastions DDoS Protection?

The deployment process involves an initial assessment, setup, configuration, integration with existing systems, and continuous support to ensure seamless implementation and operation.

Can Nexusguard Bastions be customized to meet specific needs?

Yes, Nexusguard Bastions offers customizable solutions tailored to the unique security requirements of different industries and customer segments.

How does Nexusguard Bastions integrate with existing security infrastructure?

Nexusguard Bastions is designed for seamless integration with existing security systems, enhancing overall protection without disrupting operations.

How does Nexusguard ensure continuous improvement of its DDoS protection services?

Nexusguard continuously innovates and updates its platform, providing partners with the latest features, security updates, and best practices to maintain a competitive edge.

How does Nexusguard ensure data privacy and compliance?

Nexusguard services are certified with PCI DSS, ISO 27001 and SOC type 2 compliant. Moreover, Nexusguard adheres to strict data protection and privacy policies, ensuring compliance with relevant regulations and secure handling of customer data.

Servers

Deliver Robust DDoS Protection-as-a-Service to your customers

Nexusguard Bastions Server MX7000

Download Datasheet
Rack Unit:
?
Capacity:
100G
DDoS Detection & Mitigation:
L3/L4 Network layer
DDoS Protection as a Service supported:
DDoS Protection service supported:
Hybrid mode extension:
Nexusguard Edge Protection
  • Efficient, high-performance, highly redundant chassis-based data center servers
  • 100 ~ 800 Gbps scrubbing capacity
  • High availability (HA) and off-ramp architecture
  • Ideal for mega sites and 100 Gbps+ deployments

Nexusguard Bastions Server R660

Download Datasheet
  • Small footprint, efficient, and high-performing rack-mount data center servers with AC or DC power supply options
  • 40 ~ 200 Gbps scrubbing capacity
  • Standalone, off-ramp architecture
  • Ideal for satellite sites and deployments under 200 Gbps
Rack Unit:
1U
Capacity:
100G
DDoS Detection & Mitigation:
L3/L4 Network layer
DDoS Protection as a Service supported:
Hybrid mode extension:
Nexusguard Edge Protection
Enter Text

Nexusguard Bastions Server X12

Download Datasheet
Rack Unit:
1U
Capacity:
100G
DDoS Detection & Mitigation:
L3/L4 Network layer
DDoS Protection as a Service supported:
DDoS Protection service supported:
Hybrid mode extension:
Nexusguard Edge Protection
    • Small footprint, efficient, and high-performing rack-mount data center servers with AC or DC power supply options
    • 40 ~ 200 Gbps scrubbing capacity
    • Standalone, off-ramp architecture
    • Ideal for satellite sites and deployments under 200 Gbps

FAQs

In which countries will Bastions services be available?

Bastions services are available anywhere we can get our Bastion Servers to. To check if Bastions is available in your location, contact us.

Can I reuse my existing servers to deploy my Bastions service?

No, Bastions servers leverage Nexusguard designed infrastructure, and are only supported on a Nexusguard platform that is optimized for secure, high-performance, and reliable operations with specific hardware specification and configuration settings.

Can I order my own hardware that can be installed as part of my Bastions service?

Yes, so long as the Bill of Materials (BOM) is strictly followed.

Are there any prerequisites for deploying Bastions servers at my location?

The prerequisites are rack space, air conditioning and dual-power supply. There is a specific requirement for the power connectors if Bastions server MX7000 is to be deployed. Apart from these physical elements, there are also network connections for data transfer and out-of-band management. Typically, multiple fibre connections of 10Gbps/100Gbps are required depending on the solution design. Please refer to the datasheets for the exact details.

How does Nexusguard maintain Bastions servers infrastructure?

When your Bastions service is installed, everything including the Bastions servers, hardware, platform components and service will be monitored 24/7 by Nexusguard’s dedicated Platform Team.

Technology

Efficient, High-performance Data Center Servers

  • For large-scale mega PoPs demanding 100 Gbps+ capacity, the MX7000 offers unmatched multi-chassis redundancy and scalability, ensuring reliability for modern network environments. For smaller satellite PoPs with under 200 Gbps needs, the R660/X12 combines compact design with powerful performance, delivering efficiency without compromising on capability.
  • All hardware complies with Internet standards for physical, network connectivity, and flow collection, while adhering to CSP best practices such as BGP route announcements and robust access control. Additionally, hybrid cloud deployment provides comprehensive protection, combining on-premise and cloud resources for maximum flexibility and security across all network scenarios.
DDoS Detection & Mitigation Engine

At the core of Nexusguard’s defense system is a cutting-edge Network Protection Engine, augmented by a suite of intelligent modules. These modules activate sequentially upon detecting abnormal traffic patterns, working harmoniously to neutralize threats and ensure uninterrupted service. 

  • Attack Detection
    Our advanced system monitors traffic 24/7, comparing it to baselines to pinpoint anomalies like traffic spikes or unusual patterns. This enables rapid detection of threats, from volumetric DDoS to sophisticated application-layer attacks, for immediate response.
  • Peace Time Baselining
    Powered by deep learning, Smart Baselining analyzes your network traffic to establish precise baseline thresholds. This reduces false alarms, accelerates anomaly detection, and ensures swift threat mitigation — keeping operations running smoothly.
  • Alerts
    Nexusguard’s Event Notifier App delivers alerts via email, SNMP Trap, or syslog, with customizable alert levels for proactive incident management.
  • Traffic Diversion
    The Cloud Diversion App automatically redirects traffic to Nexusguard’s network when thresholds are exceeded. With no on-premise equipment or manual intervention required, it ensures seamless mitigation and uninterrupted legitimate traffic flow.
  • Attack Mitigation
    Our multi-layered defense combines heuristic algorithms, static/dynamic content caching, and acceleration techniques to block volumetric and application-layer attacks while optimizing network performance.
  • Clean Traffic Delivery
    During an attack, Nexusguard announces the targeted /24 IP prefix via BGP, routing traffic through global scrubbing centers. Malicious traffic is filtered out, and clean traffic is securely returned via GRE tunnels, keeping networks safe and operational.
Core Services Enabled

Network Protection

  • Nexusguard's Network Protection safeguards CSP infrastructure through continuous monitoring, advanced threat detection, and proactive mitigation. Central to this service is an on-premise Bastions server and ample backbone bandwidth to maintain both network protection and uninterrupted Clean Pipe service delivery during attacks.


Clean Pipe

  • The Clean Pipe service is designed for downstream clients directly connected to ISPs in partnership with Nexusguard, leveraging the advanced capabilities of Nexusguard Bastions. These clients prioritize seamless and secure connectivity, relying on the ISP’s internet access to reach their critical network assets. By subscribing to the Clean Pipe service, they gain an additional layer of security, effectively mitigating network congestion caused by the disruptive impact of volumetric DDoS attacks.


Origin Protection

  • Nexusguard Origin Protection is a leading-edge, purpose-built service designed to safeguard mission-critical services across large-scale networks. Tailored to meet the unique demands of environments managing hundreds of Class C networks, Origin Protection provides robust protection against evolving threats while adapting to diverse infrastructure requirements.


Application Protection

  • Nexusguard Application Protection is a premium, purpose-built service designed to combat the growing complexity and sophistication of modern DDoS attacks. Powered by proprietary technology, Application Protection provides always-on, multi-layered defense spanning Layers 3 through 7, ensuring comprehensive security for your public-facing websites, applications, APIs, and other critical web assets.


DNS Protection

  • Nexusguard DNS Protection delivers always-on domain resolution through our globally distributed, high-capacity scalable DNS infrastructure. The fully redundant platform is engineered to absorb even the largest DNS-based DDoS attacks while maintaining uninterrupted service for legitimate users — ensuring 100% DNS uptime for critical websites and applications.


Edge Protection

  • Nexusguard Edge Protection is designed to safeguard CSP partners by mitigating attacks that could exceed their allocated bandwidth or overwhelm their Bastions server capacity. By seamlessly diverting malicious traffic to the Nexusguard Cloud, this service ensures uninterrupted service availability and optimal network performance.

Modular Add-ons and Tools

Network Behavior Threat Detection (NBTD)

The NBTD App employs machine learning (ML) to monitor and analyze traffic patterns to a site over time. Based on this analysis, it dynamically recommends adaptive detection thresholds that align with prevailing traffic behavior. These recommendations serve as a reliable benchmark, enabling accurate initial threshold configuration and ongoing refinement for optimal security.


Event Notifier

Event Notifier provides comprehensive security alerting capabilities designed to maintain operational awareness and accelerate incident response. The solution delivers real-time notifications through multiple integrated channels including email, SNMP traps, and syslog, ensuring critical security events are immediately communicated to the appropriate teams. 


Cloud Diversion

Nexusguard's Origin Protection incorporates Cloud Diversion App to automatically manage traffic surges. When bandwidth exceeds predefined thresholds, the system initiates traffic diversion — typically within minutes — without requiring manual intervention or on-premises hardware. This automated process maintains continuous service while simplifying operations through fully automated threshold-based triggers and appliance-free implementation.


SMART Filter

SMART Filter App is an advanced mitigation capability within the NetShield platform, powered by proprietary Smart Detection technology. This intelligent solution dynamically generates and optimizes mitigation rules in real-time, continuously adapting to evolving attack methodologies to ensure maximum protection effectiveness.


At the heart of the system lies an intelligent feedback mechanism that establishes baseline traffic patterns, monitors for deviations, and automatically implements appropriate mitigation responses.


Flow Spec

Nexusguard’s implementation of its FlowSpec App enhances precision by dynamically identifying and acting on specific traffic flows. Using criteria such as source and destination IPs, Layer 4 parameters, and packet attributes (e.g., length, fragmentation), it enforces real-time mitigation policies at border routers. These policies can selectively drop malicious traffic, redirect suspicious flows to a Virtual Routing and Forwarding (VRF) instance for deeper analysis, or apply rate-limiting to throttle unwanted traffic without complete disruption.


Reporting

The Nexusguard platform captures comprehensive attack traffic data, delivering full visibility into key security metrics. The Report App transforms this data into actionable insights, enabling the generation of detailed analyses of bandwidth utilization, mitigation performance, and security events.


Key metrics include:

  • Top application-layer DDoS attacks
  • Most significant volumetric attacks
  • Historical trends and patterns


Accessible through the Nexusguard Portal, the Report App serves as a centralized reporting hub. Users can quickly generate both standardized reports or customized analyses tailored to specific operational or compliance requirements.


Logger

Nexusguard’s Logger App provides a centralized log management solution, consolidating and storing critical network data including TCP, WAF, and web access logs. The system maintains comprehensive historical records, facilitating the ability to easily retrieve and analyze log files as needed.

Service Management & Integration

Multi-tenant Administration Portal

  • Nexusguard Bastions delivers a seamless and unified experience for CSPS by integrating continuous traffic analysis, real-time attack alerts, traffic redirection, advanced scrubbing, and the delivery of clean traffic — all in a single platform. Central to this system is an intuitive, multi-tenant administration portal, where each customer enjoys their own personalized profile. CSP administrators gain full control, with the ability to effortlessly manage individual customers and tailor their security settings.
  • The dynamic dashboard brings everything together, presenting a wealth of metrics, event logs, and detailed reports in an easy-to-understand format.
Customer Portal & Reporting

  • Our Customer Portal offers end-clients a smooth, self-service experience, empowering them to independently monitor events, incidents, traffic graphs, and more — all without relying on their CSP partner. Each client is equipped with their own dedicated dashboard portal, tailored to their individualized service. These personalized portals feature unique security profiles and customizable parameters, ensuring they align perfectly with the specific needs and requirements of each business.
API for Seamless CSP Integration

Nexusguard’s proprietary API enables tight integration with partner CSP operations, helping streamline workflows, enhance efficiency, and simplify management for a more cohesive service experience.

Upgrades & Maintenance

  • Nexusguard’s SaaS model replaces capital-intensive (CapEx) investments with a predictable operational expenditure (OpEx) model, eliminating lifecycle concerns and the risk of end-of-support scenarios. This transition removes the need for periodic technology refresh cycles and large capital outlays.
  • Our subscription-based approach guarantees uninterrupted licensing and support, maintaining operational effectiveness indefinitely. This sustainable model delivers increasing value over time, with total cost of ownership (TCO) that progressively declines the longer the solution remains in service.

Support

Training & Certification

  • Included as a standard feature with every deployment, Nexusguard provides comprehensive training, enablement, evaluation, and ongoing re-training for our sales and pre-sales teams, partners and their teams. Our courses are designed by seasoned practitioners with years of hands-on experience, ensuring they are practical, realistic, and highly effective.
Managed SOC service

  • Nexusguard’s SOC is staffed by a team of highly skilled security professionals who work around the clock to monitor and defend against emerging threats, including zero-day attacks. Leveraging advanced threat intelligence systems and real-time monitoring capabilities, our SOC ensures rapid detection and swift response to security incidents, keeping your systems safe and secure at all times.

DDoS Productization: Turning DDoS Protection into a Seamless Solution

Nexusguard Bastions empowers Communications Service Providers (CSPs) to productize DDoS-protection-as-a-services, providing a technical solution that benefits both internal stakeholders and external clients. While commercial teams focus on monetizing these services, network operations teams can rely on Bastions to deliver unrivaled protection, reliability, and peace of mind. 

FAQs

What is the the difference between Nexusguard Bastions and traditional Anti-DDoS appliance?
How can CSPs benefit from Nexusguard's DDoS productization approach?

CSPs can differentiate themselves in the market by offering comprehensive DDoS protection services, increasing their value proposition, attracting more clients, and boosting revenue streams.

What is the partnership model for Nexusguard Bastions?

Nexusguard offers whitelabeling and cobranding partnership models

What support does Nexusguard offer to its partners?

Through Nexusguard's Transformational Alliance Partner program, Nexusguard provides extensive support, including technical assistance, marketing resources and trainings to help partners effectively deliver and manage DDoS Protection services.

How does Nexusguard Bastions help shift from CAPEX to OPEX?

Nexusguard Bastions enables partners to adopt a service-based model, reducing the need for upfront capital expenditures (CAPEX) and shifting to operational expenditures (OPEX) through scalable, subscription-based services.te attacks effectively and responsively.

Resources

Datasheet

Nexusguard Bastions Server X12 Datasheet

Nexusguard Bastions Server R660 Datasheet

Nexusguard Bastions Server MX7000 Datasheet

Whitepaper

View All

Multi-layered Protection for Public-facing Websites, Applications and Critical Web Assets

We explore the extensive features and capabilities offered by Nexusguard's Application Protection service, specifically designed to protect public-facing websites, applications, APIs, and other critical web assets.

The Cost of DDoS Security

Nexusguard identifies and breaks down the direct and indirect capital and operations costs involved in deploying and maintaining a DDoS detection and mitigation strategy that works.

Looking for Simpler DDoS Protection?

Protect your infrastructure and grow your service portfolio with a friendly, seamless DDoS solution tailored for Communications Service Providers.