Summary
- ESpanix has deployed Nokia Deepfield Defender across its Madrid and Barcelona internet-exchange infrastructure.
- More than 200 connected national and international networks can use the optional DDoS protection service.
- The design keeps mitigation within ESpanix's Spanish network rather than sending traffic through an external scrubbing centre.
Spain’s largest internet exchange has moved distributed denial-of-service mitigation into its exchange infrastructure, making an optional defence service available to more than 200 national and international networks connected through Madrid and Barcelona.
ESpanix has deployed Nokia Deepfield Defender across its exchange platform, with the suppliers saying the service can identify and mitigate attacks crossing the infrastructure within seconds.
The connected networks collectively serve the majority of internet end users in Spain, according to Nokia’s announcement. ESpanix says the design allows unwanted traffic to be handled within its own network rather than diverting Spanish traffic through an external DDoS scrubbing centre.
That architecture addresses one of the operational trade-offs involved in large-scale DDoS defence. External scrubbing services can absorb substantial volumes of attack traffic before returning legitimate flows to their intended destination, but the process can introduce routing changes, latency, and dependency on additional infrastructure.
Mitigation at an internet exchange moves part of that control closer to the networks exchanging the traffic. Internet exchanges already occupy a strategic position between carriers, internet service providers, content networks, cloud operators, and other participants.
A defensive capability deployed at that layer can consequently serve multiple connected organisations without each participant operating an equivalent mitigation environment independently.
The concentration also increases the operational importance of the exchange itself. IXPs improve efficiency and resilience by allowing networks to exchange traffic directly, but their position means a major operational or security failure can affect a broad ecosystem.
Adding automated mitigation creates another control plane whose availability, accuracy, and change management need to be treated as infrastructure concerns. An effective system has to identify malicious flows rapidly without causing unacceptable disruption to legitimate traffic passing through the same exchange.
DDoS capacity has also grown as attackers gain access to compromised consumer devices, servers, proxy networks, and high-bandwidth systems. Operators increasingly have to distinguish straightforward volumetric flooding from attacks that attempt to resemble legitimate application traffic.
Nokia says Deepfield Defender analyses network telemetry and threat intelligence to identify and mitigate malicious traffic. Those performance claims originate with the supplier and will ultimately be tested by ESpanix’s operational experience rather than the deployment announcement itself.
There is also a sovereignty element to the design. Keeping Spanish internet traffic and mitigation within Spain reduces the need to reroute traffic through external facilities during an attack, although the security platform itself remains supplied by Finland-based Nokia.
The deployment therefore combines two resilience models: shared defence at a significant national interconnection point, and greater control over where attack traffic is processed. For networks connected to the exchange, the result is an additional mitigation option positioned closer to the infrastructure carrying their traffic.





