Carrier-grade DDoS protection
Detection in under 2 seconds, automated BGP mitigation, and full control on your own infrastructure. No traffic limits, no per-Gbps fees, no data shipped to a cloud.
See DDoS protection in actionReal-time detection
- NetFlow v5/v9/IPFIX, sFlow and PCAP analysis in one unified data model
- Hierarchical thresholds: network, protocol, port (single, lists and ranges), TOS — matched most-specific-first
- Adaptive per-host baselines (p95) grade severity against learned normals — CDN caches, web farms and IPTV head-ends stop flooding your SOC with false alarms
- Full dual-stack: IPv4 and IPv6 across thresholds, whitelists and intelligent signals (including ICMPv6 floods)
- Source-country risk scoring and traffic weighting
Automated BGP mitigation
- RTBH blackholing with community tagging — FRR, Huawei NE8000, Cisco ASR; IPv6 /128 under the ipv6 address-family
- BGP FlowSpec: drop or rate-limit only the attack traffic — services on the same IP keep running
- BGP traffic diversion: redirect the attacked prefix to a scrubbing path instead of a full blackhole, with auto-trigger and auto-revert
- Mitigation mode set per threshold (blackhole / flowspec / both / alert-only) — no mid-attack flapping
- What-If simulator: preview outcomes before anything touches routing; alert-only by default
Spoofing & reflection defense
- BCP38 monitor: detects forged-source traffic leaving your network, with source-MAC attribution pinpointing the offending port
- SYN-ACK reflection victim detection — with guidance to divert rather than blackhole the victim
- Attacker source blocklist built from real incidents in your network — exportable to iptables/ipset and XDP/eBPF
- Threshold Advisory: standing rate-limit recommendations in FlowSpec syntax, mined from your attack history and baselines