Summary
- ESpanix has deployed Nokia Deepfield Defender across its internet exchange infrastructure in Madrid and Barcelona.
- More than 200 connected networks can use the optional service, with malicious traffic detected and mitigated inside the network.
- Keeping mitigation in Spain reduces reliance on external scrubbing infrastructure and turns the exchange into a shared security layer.
Spain’s largest internet exchange, ESpanix, has deployed Nokia’s Deepfield Defender across its Madrid and Barcelona infrastructure, turning the exchange network itself into a point for detecting and blocking distributed denial-of-service attacks before malicious traffic reaches the businesses, public services, and network operators behind it.
The deployment gives more than 200 national and international networks connected to ESpanix access to an optional DDoS protection service, with Nokia’s software analysing network telemetry and triggering automated mitigation inside the exchange. ESpanix says those connected networks collectively serve the majority of internet users in Spain, giving a single infrastructure deployment reach across a significant part of the country’s digital economy.
Rather than sending suspicious traffic to a separate third-party scrubbing centre for inspection and filtering, Deepfield Defender can identify and remove unwanted traffic within ESpanix’s own network. The system combines traffic analytics with Nokia’s Deepfield Secure Genome, a continually updated dataset describing the security context of internet addresses and traffic patterns, then uses network equipment to apply mitigation while legitimate traffic continues to flow.
Javier Achirica, chief technology officer at ESpanix, said: “Crucially, this protection is delivered entirely within our network and within Spain, across the six datacentres in Madrid and Barcelona where we connect with our members. This ensures that local traffic remains local, eliminating any need for detours through third-party scrubbing infrastructure and thereby guaranteeing strict data sovereignty.”
The exchange becomes part of the security perimeter
Internet exchanges occupy a useful position in DDoS defence because they sit where traffic from numerous networks meets. A traditional mitigation service is often deployed by an individual network operator or relies on redirecting traffic towards specialised infrastructure, whereas protection at an exchange can intercept attack traffic before it is passed further downstream and can extend one security capability across many connected networks.
ESpanix operates six points of presence in Spain and reports more than 2Tbps of switched traffic, alongside 260Tbps of installed capacity. Its members gain direct interconnection with other networks rather than sending every packet through upstream transit providers, which can reduce latency and cost while improving resilience; adding DDoS mitigation turns some of that shared interconnection infrastructure into a shared defensive layer as well.
The technical proposition also reflects changes in DDoS attacks themselves. Large botnets built from compromised connected devices, residential proxy networks, and other distributed sources can generate both high-volume attacks and more targeted application-layer traffic, making static thresholds and manually triggered mitigation awkward for networks that need attacks identified in seconds.
Nokia says Deepfield Defender uses machine-learning rules, internet-wide security intelligence, and network telemetry including routing and DNS information to distinguish legitimate flows from malicious ones. Automated mitigation can then be applied using compatible routers or dedicated mitigation systems, reducing the delay between detection and response without forcing all traffic through a central security appliance.
Sovereignty meets network economics
Keeping traffic within Spain is partly a performance issue, since sending packets to remote scrubbing centres introduces additional routes and dependencies, but it also fits a broader European emphasis on control over digital infrastructure and data flows. DDoS filtering does not automatically create the same legal questions as storing personal data abroad, although regulated organisations increasingly examine where security services operate, which third parties can inspect traffic, and how dependent critical services are on infrastructure outside their immediate control.
For ESpanix, security also creates a commercial layer on top of the exchange business. The company can offer DDoS protection as an additional service to members already buying connectivity, while smaller operators can access mitigation capabilities without building a dedicated platform independently. Nokia has deployed Deepfield with other European internet exchanges, making the model part of a wider attempt to turn shared network infrastructure into a place where security services are aggregated as well as traffic.
The deployment extends an existing relationship between the two companies. During 2025, ESpanix became the first internet exchange in Spain to offer 400G connectivity to customers using Nokia routing and optical technology, so the security service sits on top of network infrastructure that was already being modernised for higher capacity.
That combination of capacity and automated defence is likely to become more useful as cloud services, AI workloads, and public digital services raise the commercial cost of network disruption. A DDoS attack does not need to compromise data to create business damage; saturating connectivity or exhausting application resources can be enough to interrupt transactions, communications, and access to services.
By placing mitigation at one of the points where Spanish internet traffic is already concentrated, ESpanix is treating resilience as part of interconnection rather than a separate product bolted on afterwards. The test will be whether enough connected networks adopt the service to make exchange-level defence a routine part of Spain’s internet architecture rather than another capability procured individually.












