FastNetMon BGP Flow spec based DDoS mitigation

In BGP Flow spec mode FastNetMon can detect and isolate patterns of malicious traffic and filter it out using high performance filters on your routers. For some platforms which do not support BGP Flow Spec natively we provide API or CLI based integrations: Bison...

FastNetMon Advanced threshold types

To achieve better DDoS detection, FastNetMon offers a number of predefined threshold types. For each entity (host or group of hosts) in your network, FastNetMon maintains a set of counters for different traffic types. FastNetMon calculates all counter types for...

Automatic blocks for remote attackers

FastNetMon has an experimental (not recommended for production use) ability to detect remote attackers (/32 hosts) and announce them using BGP Unicast announces. You can use it for a production environment only if you run sFlow or sampled Netflow / IPFIX. Known...

FastNetMon Advanced BGP mitigation modes

FastNetMon can work in two mutually exclusive modes:- BGP Blackhole- BGP Flow spec In BGP Blackhole mode, FastNetMon can announce your own host (or subnet for this host) with a specified BGP community. You can use this approach for traffic diversion to a cloud...