Oh, is that vRack thingie not a kind of VPN-on-steroids that is done in hardware by the router? Without you even knowing?
I understood it worked somehow in this way:
You have one or several "real" (externally visible) IP addresses and their magic system forwards requests to these to servers within your virtual private network, with failover if you want (and inside the VPN e.g. the webserver and the database server can be in different datacenters and can talk to each other independently of surrounding traffic, with a minimum bandwidth guarantee and encryption, as if plugged into the same router, without knowing).
And if they notice that a couple of hosts start sending e.g. 1000 requests per second each, they will just drop packets coming from these directly at the IX (or as close to it as possible), and still allow the other traffic through.