Datafex LogoDatafex

Data Centre and Colocation

Host your own hardware in the Datafex data centre. Cabinet, power, network and attack protection from us; the server is yours. 21U and 42U cabinets, 10G–20G uplink and two layers of DDoS protection.

What is colocation?

Colocation means housing your own server hardware in a data centre cabinet. The hardware stays yours — you choose the processor, the disks and the RAID layout. The data centre provides power, cooling, physical security, network connectivity and attack protection. The difference from a rented server is this: with a rental the hardware belongs to the provider and you are left with nothing when the contract ends, while with colocation the hardware investment stays with you and you buy only the hosting.

Colocation is usually chosen in three situations: you already own server hardware and want to run it in a real data centre rather than an office; you need a hardware configuration that standard rental plans do not cover; or data ownership and physical access control matter to you.

Cabinet options

Cabinet size is measured in rack units; 1U is roughly 4.45 cm of rack height. A typical 1U server occupies exactly that space, while 2U servers take two units. Your choice is shaped as much by the airflow clearance you leave and your power commitment as by how many servers you install.

21U cabinet

A half cabinet. Enough room for a few servers, a switch and a power unit. It suits single-project setups and teams that plan to grow their hardware gradually.

42U cabinet

A full cabinet. It lets you host dense server installations, separate storage units and your own network equipment together. If you run infrastructure for several projects or customers, this is the right starting point.

Uplink and committed bandwidth

These two are often confused but they are different things. Uplink is the capacity of the port your cabinet connects through — 10 Gbps or 20 Gbps. Committed bandwidth is the actual throughput you commit to over that port; it is chosen between 100 Mbps and 1 Gbps and it is what billing is based on.

Why keep them separate? Because port capacity and the bandwidth you use continuously are not the same. A 10 Gbps port lets you absorb short surges — a backup transfer, a software rollout, a campaign moment — without saturating, while the committed bandwidth reflects your average use across the month. A high port with a modest commitment is usually both the economical and the comfortable choice.

A 20 Gbps uplink also lets you build redundancy across two separate lines, so service continues if one goes down. A single-line 10 Gbps setup does not have that redundancy.

In short: size the port for your peak and the committed bandwidth for your average. If you are unsure which values fit, share your current traffic graph and we will work it out together.

Two layers of attack protection

Attacks do not arrive from a single place, so protection cannot sit in a single layer. At Datafex traffic is filtered at two separate points: volumetric attacks at the router on the network edge first, then source- and behaviour-based filtering in the Fexwall layer.

Layer 2 — Fexwall

End-to-end filtering

Our DPDK-based L3/L4 security layer. It blocks traffic built on forged source addresses at the network edge, separates botnet-driven requests by their behaviour, and lets you define rules specific to your project. You can build profiles for your own ports and protocols.

Attacks covered: end-to-end spoofing (forged source addresses), botnet-driven request floods, project-specific rule requirements.

Layer 1 — Router

Volumetric attack filter

Volumetric attacks do not tire your server; they fill your pipe. That is why the traffic has to be stopped at the router on the network edge, before it reaches the cabinet. In reflection and amplification attacks the attacker sends requests to third-party servers using your address as the source; the replies come back to you and traffic you never generated clogs your line. Blocking IPs does not help here, because the address you block is probably an innocent third party.

Attacks covered: DNS amplification, NTP amplification, TCP amplification, TCP reflection and similar reflection or amplification attacks.

The two layers work together: the router level cuts the volume that would fill your line, while Fexwall separates the forged and malicious requests inside what passes. Neither is enough alone — you cannot stop a volumetric attack at the application layer, and you cannot separate a behaviour-based attack with a volume filter.

Let's talk about your project

Tell us how many servers you plan to install, your power requirement and your traffic profile, and we will work out the right cabinet and protection setup together.