Autonomous system
AS8757 NSFOC
Unclassified RIPE
Summary
NSFOCUS
hosting security legacy
NSFOCUS, Inc. (NSFOCUS) — the international arm of the security vendor
NSFOCUS, registered in Santa Clara, California. This AS is its **anti-DDoS
scrubbing cloud**, not a conventional hosting or access network.
What it's used for
- Fronting customer web properties for DDoS mitigation and WAF. Traffic destined for a protected site is redirected into these prefixes, cleaned in a scrubbing centre, and forwarded to the real origin.
- rDNS across the space is uniformly
IP-ADDR.reverse.ip.nsfocus.cloud, which is the honest witness here: every address belongs to the platform itself, not to the customers behind it.
Notable
- The shape gives it away. Roughly 3,000 IPv4 addresses but around 157 observed BGP neighbours — a ratio no ordinary network produces. That is an anycast footprint: the same small blocks announced from many scrubbing PoPs worldwide, so the closest one absorbs an attack.
- Because of that, these addresses should not be geolocated to a single country. The RIPE objects carry a mix of US and GB registration details and the prefixes appear wherever a scrubbing centre does.
- An address here is a proxy in front of someone else's site. Whatever it serves, the content owner is not NSFOCUS.
Interesting
- Mitigation networks are structurally the inverse of eyeball networks: tiny address inventory, enormous peering surface. Peering breadth, not address count, is the thing being sold.
This description is AI-generated, best-effort context — not authoritative, and provided without any guarantee of accuracy. Source, and how to suggest an edit.
Address space
Summary
| Country | Name | Prefixes |
|---|---|---|
| US | United States of America | 12 |
Registry
Allocation record
- Registry
- RIPE
- Handle
AS8757- Registry name
- NSFOCUS
- Registrant
- NSFOCUS-MNT
- Abuse contact
- abuse@nsfocusglobal.com
- Registered
- 2002-05-31
- Last changed
- 2018-09-04
- Status
- active
Reputation
Classification and threat
Unclassified Not in the curated lists. Most of the ~80,000 allocated ASNs are not.
No IC3 indicators Nothing from the FBI IC3 feed.
Threat data is alpha. Absence of an indicator is not evidence of good behaviour, only of absence from this one feed.
Elsewhere