Work out ddos mitigation capacity instantly with clear inputs, formula shown and shareable results.
Mitigation capacity must exceed attack plus legitimate traffic, since both traverse the scrubbing centre. Equally important is leakage tolerance: scrubbing is never perfect, and the origin link has to absorb whatever fraction gets through alongside real traffic. With a 10 Gbps origin under a 180 Gbps attack, even three percent leakage saturates the link.
Mitigation headroom
headroom = scrubbing capacity - (attack + legitimate); tolerable leakage = (origin capacity - legitimate) / total attack traffic
Because the origin link is orders of magnitude smaller than the attack. A single-digit percentage of a large attack still exceeds a typical enterprise circuit.
For latency-sensitive services yes, because BGP-based on-demand diversion takes minutes to take effect, during which the origin is fully exposed.