Summary
- ESpanix has deployed Nokia Deepfield Defender across six data-centre locations in Madrid and Barcelona.
- More than 200 connected national and international networks can use the optional mitigation service.
- Attack traffic can be filtered within ESpanix’s Spanish network instead of being diverted through an external scrubbing centre.
ESpanix has deployed Nokia’s Deepfield Defender across six data-centre locations in Madrid and Barcelona, adding distributed denial-of-service detection and mitigation for more than 200 networks connected to the Spanish internet exchange.
The optional service is designed to identify attack traffic within seconds and remove it inside the ESpanix network rather than diverting customer traffic to an external scrubbing centre.
ESpanix says its connected national and international networks collectively serve the majority of internet users in Spain. Deploying mitigation at the exchange layer gives the operator an opportunity to remove hostile flows before they travel deeper into individual members’ networks.
That changes where part of the security function sits. A conventional external scrubbing model redirects traffic to specialist infrastructure elsewhere, where malicious packets are removed before legitimate traffic is returned to the customer.
ESpanix instead intends to perform mitigation within its own Spanish exchange environment. The operator says this keeps local traffic within the country and reduces dependence on third-party mitigation paths.
The sovereignty claim should not be confused with complete control of the wider internet route. Traffic sources and destinations remain global, and member networks continue to depend on their own security controls. The change does, however, provide more control over where the mitigation function itself is performed.
Nokia’s platform combines network telemetry with information used to classify internet traffic and identify compromised systems and hostile sources. The objective is to distinguish attack flows quickly enough to protect network capacity without indiscriminately blocking legitimate traffic.
That is increasingly important because DDoS attacks can exhaust network links before servers or application-layer controls become the limiting point. A target may have resilient compute infrastructure but still become unavailable if its upstream connectivity is overwhelmed.
Internet exchanges are useful mitigation locations because they sit at concentration points between carriers, cloud platforms, content networks, hosting providers, and other networks. Filtering closer to that interconnection layer can reduce the volume of hostile traffic carried further across the infrastructure.
The deployment also shows how cyber resilience and physical data-centre operations overlap. Exchange routers, security appliances, optical systems, and cross-connect infrastructure consume rack space, power, and cooling inside the facilities hosting them.
Attack events can also produce sudden changes in traffic patterns and network utilisation, making capacity planning and operational monitoring part of the security response.
ESpanix already uses Nokia equipment in its network. The companies announced a 400G connectivity upgrade in 2025, and the DDoS service expands that relationship from transport and routing into active traffic protection.
For members, the exchange-level service will provide an additional defensive layer rather than replace controls at the customer edge. Large organisations generally use several mitigation points because attacks can vary in size, protocol, duration, and target.
That layered approach is particularly important for data-centre tenants and service providers whose availability depends simultaneously on servers, facility power, internal networking, upstream carriers, DNS, and internet routing.
The practical measure of the new service will be how accurately and quickly ESpanix can distinguish hostile flows during significant attacks while maintaining legitimate traffic. By placing mitigation directly across its Madrid and Barcelona exchange infrastructure, the operator is moving part of Spain’s DDoS defence closer to one of the points where a large number of networks already meet.

