Generated by All in One SEO Pro v5.0.1.1, this is an llms.txt file, used by LLMs to index the site. # FastNetMon DDoS Detection Tool FastNetMon Official Site ## Sitemaps - [XML Sitemap](https://fastnetmon.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Solving a large DDoS attack problem for a leading telecommunications consultancy provider](https://fastnetmon.com/2023/06/11/solving-a-large-ddos-attack-problem-for-a-leading-telecommunications-consultancy-provider/) - Discover how FastNetMon empowered MKE Solutions, a top telecom consultancy, to combat 35 daily DDoS attacks effectively. Uncover invaluable network protection and visibility. - [See you at NOG.HR Meetup 7](https://fastnetmon.com/2026/07/15/nog-hr-meetup-7-event-page/) - We'll be attending NOG.HR Meetup 7 on September 10, 2026, in Zagreb, Croatia, and we're looking forward to joining the Croatian network operator community for a full day of technical talks and discussions. Outi Maria Pietilänaho from FastNetMon will be presenting "Tracking today's botnets – Threat intel & lessons to defend against DDoS." The session - [See you at MDNOG!](https://fastnetmon.com/2026/07/14/see-you-at-mdnog/) - FastNetMon will be attending MDNOG 1 on October 8–9, 2026, in Chișinău, Moldova. As the first national Network Operators Group meeting in Moldova, this is an exciting milestone for the country's networking community, and we're proud to be there and support its first edition. Virgil Truică from the FastNetMon team will be presenting “DDoS attacks - [See you at DENOG 18!](https://fastnetmon.com/2026/07/12/see-you-at-denog-18/) - FastNetMon will be attending DENOG 18 on November 15–17, 2026, in Essen, Germany, and we're looking forward to connecting with the German network operator community. Members of the FastNetMon team will be there. If you're working on DDoS detection and mitigation, traffic visibility, routing or network security, we'd be happy to hear about the challenges - [See you at NANOG 89](https://fastnetmon.com/2026/07/13/nanog-89-event-page/) - FastNetMon will be attending NANOG 98 on October 19–21, 2026, in Miami, Florida, and we're looking forward to three days with the network operator community. Several members of the FastNetMon team will be there, so it's a great opportunity to meet us in person. If you're working on DDoS detection and mitigation, traffic visibility, routing - [See you at RONOG 11!](https://fastnetmon.com/2026/07/14/see-you-at-ronog-11/) - FastNetMon will be attending RONOG 11 on September 29, 2026, in Bucharest, Romania, and we're looking forward to connecting with the network operator community. Virgil Truica from the FastNetMon team will be there. If you're working on DDoS detection and mitigation, traffic visibility, or network security, we'd be happy to hear about the challenges you're - [Network Engineering Community News: August 2026](https://fastnetmon.com/2026/08/27/network-engineering-community-news-august-2026/) - ⚡️ Network Engineering Community News - from FastNetMon Welcome to the August edition of Network Engineering Community News! This month, we’re covering key FastNetMon product updates, the recent launch of Netomics, DDoS simulation at 100GbE, the latest botnet research, and a look back at the history of the first transatlantic cable. Plus, find out where - [See you at NONOG-8 / NIX-2026](https://fastnetmon.com/2026/07/16/snonog-8-nix-2026-event-page/) - FastNetMon will be attending NONOG-8 / NIX-2026 on September 9, 2026, in Oslo, Norway, and we're looking forward to a full day of technical talks and discussions with the Nordic network operator community. Pavel Odintsov will be speaking at the event about FastNetMon Community Edition right before the lunch break at 11:45 am - we - [DDoS News: Evooo1Bot Linux Botnet Hijacks Routers and Firewalls](https://fastnetmon.com/2026/08/19/ddos-news-evooo1bot-linux-botnet-hijacks-routers-and-firewalls/) - A newly observed Linux botnet dubbed Evooo1Bot is targeting internet-facing edge devices, including enterprise firewalls, SOHO routers, IP cameras, and industrial RTUs. FortiGuard Labs reports that the malware reuses the DDoS engine from the publicly leaked Mirai source code while adding capabilities including encrypted command-and-control (C2) communications, SOCKS5 proxy relaying, credential sniffing, SSH brute-force scanning, - [The First Transatlantic Cable: How Victorian Engineers Wired an Ocean](https://fastnetmon.com/2026/08/11/the-first-transatlantic-cable-how-victorian-engineers-wired-an-ocean/) - Occasionally on the FastNetMon blog, we venture into the history of communications infrastructure and the engineering stories that helped shape the Internet we know today. This time, it’s the remarkable story of how Victorian engineers attempted to wire an ocean—and what happened when their first transatlantic connection lasted only a few weeks. On August 16, - [Introducing sFlowgen: Lightweight sFlow Traffic Generator](https://fastnetmon.com/2026/08/11/introducing-sflowgen-lightweight-sflow-traffic-generator/) - Testing DDoS mitigation can be surprisingly difficult. You may want to see how your monitoring system reacts to a 10 or 15 Gbps attack, but generating that much real traffic requires suitable hardware and network capacity — and is not always practical or desirable in a test environment. To make this kind of testing easier, - [Simulating DDoS Attacks at 100GbE Line Rate with TRex](https://fastnetmon.com/2026/08/10/simulating-ddos-attacks-at-100gbe-line-rate-with-trex/) - This post is a repost of a technical blog originally published by Denys Haryachyy, shared here with permission as part of ongoing research and engineering work around FastNetMon’s inline traffic processing capabilities. TL;DR. TRex’s stateless mode can simulate every common volumetric DDoS class at full 100 GbE line rate (142 Mpps), and they are all one generator template with a different - [Learning TRex: Generating 100GbE Line-Rate Traffic on a Mellanox ConnectX-5](https://fastnetmon.com/2026/08/10/learning-trex-generating-100gbe-line-rate-traffic-on-a-mellanox-connectx-5/) - This post is a repost of a technical blog originally published by Denys Haryachyy, shared here with permission as part of ongoing research and engineering work around FastNetMon’s inline traffic processing capabilities. TL;DR. Cisco TRex 3.06 pushes full 100GbE line rate — 142 Mpps, 100.01 Gbps L1, tx_util 100 % — from one desktop Ryzen 7 5800X and a single ConnectX-5 Ex (PCIe Gen4). The rate is - [Tuning a VPP Data Plane to 100GbE Line Rate: Cycle Budget, NIC Rings, and RSS](https://fastnetmon.com/2026/08/17/tuning-a-vpp-data-plane-to-100gbe-line-rate-cycle-budget-nic-rings-and-rss/) - This post is a repost of technical blog originally published by Denys Haryachyy, shared here with permission as part of ongoing research and engineering work around FastNetMon’s inline traffic processing capabilities. TL;DR. A VPP software data plane drops packets at full 100GbE line rate (~140 Mpps) on one server — but staying there is a systems problem, not an algorithm - [Action Required: Upgrade to FastNetMon Advanced v2.0.383](https://fastnetmon.com/2026/08/06/action-required-upgrade-to-fastnetmon-advanced-v2-0-383/) - IMPORTANT: Action is required for all customers using online licensing. We have released FastNetMon Advanced v2.0.383 as part of a CA certificate rotation for our online licensing infrastructure. All customers using online licensing are REQUIRED to upgrade to FastNetMon Advanced v2.0.383 no later than August 14, 2026. After August 14, 2026, older FastNetMon versions will - [FastNetMon Advanced 2.0.383](https://fastnetmon.com/2026/08/06/fastnetmon-advanced-2-0-383/) - Release date: 5 August, 2026Version: 2.0.383 FastNetMon Advanced 2.0.383 is a mandatory update for customers using online licensing. This release includes a new CA certificate required for communication with the FastNetMon licensing service as part of our infrastructure update. All customers using online licensing must upgrade to FastNetMon Advanced v2.0.383 no later than August 14, 2026, to - [FastNetMon Community is Now Available on the Ubuntu Snap Store](https://fastnetmon.com/2026/08/04/fastnetmon-community-is-now-available-on-the-ubuntu-snap-store/) - We're pleased to announce that FastNetMon Community is now available as an official package on the Ubuntu Snap Store. FastNetMon Community is a high-performance DDoS detection sensor that monitors network traffic using NetFlow, IPFIX, sFlow, PCAP, and port-mirrored traffic. It detects traffic anomalies based on configurable thresholds and can automatically notify operators, execute custom scripts, - [VyOS and FastNetMon announce an integration](https://fastnetmon.com/2020/06/30/vyos-and-fastnetmon-integration/) - FastNetMon and VyOS established a partnership to provide for customers reliable router and protection against various DDoS attacks service at the same time. - [FastNetMon integration with Radware DefenseFlow](https://fastnetmon.com/2017/02/17/fastnetmon-integration-with-radware-defenseflow/) - FastNetMon was built with interoperability in mind. Every day we are working hard on protocols and their corner cases. Modern Internet consist of hundreds of protocols and thousands of brands. It’s very complicated to support them all without cooperation. And we are pleased to share result of our cooperation with one of top vendors on - [FastNetMon and IP Infusion introduce automated DDoS protection with OcNOS + FastNetMon](https://fastnetmon.com/2026/03/16/fastnetmon-and-ip-infusion-collaborate-on-automated-ddos-protection-with-ocnos/) - FastNetMon and IP Infusion are collaborating to deliver an open, standards-based DDoS protection solution built on IP Infusion’s OcNOS network operating system and the FastNetMon traffic analysis and mitigation platform. The joint solution combines real-time traffic detection with automated mitigation, enabling operators to detect and stop attacks in seconds using native routing protocols within a - [Network Engineering Community News: July 2026](https://fastnetmon.com/2026/07/30/network-engineering-community-news-july-2026/) - ⚡️ Network Engineering Community News - from FastNetMon Big news this month: we've launched Netomics, a new self-hosted routing intelligence platform for network operators. We've also shipped a ton of new features, launched our own podcast, rounded up the latest DDoS news, and published two in-depth engineering articles. We hope you enjoy this month's edition! - [Network Engineering Community News: June 2026](https://fastnetmon.com/2026/06/30/network-engineering-community-news-june-2026/) - ⚡️ Network Engineering Community News - from FastNetMon We’ve given the newsletter a bit of a fresh coat of paint, but the goal is the same: keeping you in the loop on what we’re building, sharing interesting DDoS and NetSec updates, and staying connected with the community. Let us know what you think! In this - [Network Engineering Community News: May 2026](https://fastnetmon.com/2026/05/31/network-engineering-community-news-may-2026/) - ⚡️ Network Engineering Community News - from FastNetMon We’ve given the newsletter a bit of a fresh coat of paint, but the goal is the same: keeping you in the loop on what we’re building, sharing interesting DDoS and NetSec updates, and staying connected with the community. Let us know what you think! In this - [Learning VPP: Inside TupleMerge, the ACL Plugin’s Classifier](https://fastnetmon.com/2026/09/07/learning-vpp-inside-tuplemerge-the-acl-plugins-classifier/) - This post is a repost of a technical blog originally published by Denys Haryachyy, shared here with permission as part of ongoing research and engineering work around FastNetMon’s inline traffic processing capabilities. TL;DR. TupleMerge, the classifier inside VPP’s ACL plugin, is tuple-space search plus one liberty: a rule may live in a table coarser than its own mask. - [Hardware-in-the-Loop CI: Line-Rate VPP Testing over Tailscale](https://fastnetmon.com/2026/08/28/hardware-in-the-loop-ci-line-rate-vpp-testing-over-tailscale/) - This post is a repost of a technical blog originally published by Denys Haryachyy, shared here with permission as part of ongoing research and engineering work around FastNetMon’s inline traffic processing capabilities. TL;DR. Testing a data plane at 100GbE line rate needs real NICs running VPP — which no cloud CI runner has. So an ephemeral GitHub Actions runner joins a private - [Learning VPP: Inside bihash, the Lock-Free Hash Table](https://fastnetmon.com/2026/07/31/learning-vpp-inside-bihash-the-lock-free-hash-table/) - This post is a repost of a technical blog originally published by Denys Haryachyy, shared here with permission as part of ongoing research and engineering work around FastNetMon’s inline traffic processing capabilities. TL;DR — everything that matters, in one paragraph. bihash (the bounded-index extensible hash, clib_bihash in VPP) is the hash table behind almost every VPP table — FIB, L2, - [Learning VPP: Filtering Packets at 100GbE Line Rate](https://fastnetmon.com/2026/07/02/learning-vpp-filtering-packets-at-100gbe-line-rate/) - This post is a repost of technical blog originally published by Denys Haryachyy, shared here with permission as part of ongoing research and engineering work around FastNetMon’s inline traffic processing capabilities. TL;DR. A VPP software data plane classifies and drops packets using a tuple-space search (TSS): rules are grouped by mask shape into per-mask bihash tables, and each packet probes one - [Learning Mellanox ConnectX-5: CQE Compression Tuning](https://fastnetmon.com/2026/07/22/learning-mellanox-connectx-5-cqe-compression-tuning/) - This post is a repost of technical blog originally published by Denys Haryachyy, shared here with permission as part of ongoing research and engineering work around FastNetMon’s inline traffic processing capabilities. TL;DR. On a Mellanox ConnectX-5, the firmware setting CQE_COMPRESSION=AGGRESSIVE is the biggest receive-side win — +17–21 Mpps. Instead of one 64-byte completion (CQE) per packet over PCIe, the NIC packs many - [Learning DPDK: Eliminating NIC Receive Drops at 100GbE](https://fastnetmon.com/2026/06/17/learning-dpdk-eliminating-nic-receive-drops-at-100gbe/) - This post is a repost of technical blog originally published by Denys Haryachyy, shared here with permission as part of ongoing research and engineering work around FastNetMon’s inline traffic processing capabilities. The article examines the underlying performance mechanics needed to run DPDK-based packet processing at 100GbE without packet loss, and how subtle operating system and - [FastNetMon Advanced 2.0.381](https://fastnetmon.com/2026/07/13/fastnetmon-advanced-2-0-381/) - Release date: 13 July, 2026Version: 2.0.381 FastNetMon Advanced 2.0.381 delivers major improvements to BGP FlowSpec capabilities, including full IPv6 manual announcement support, enhanced route propagation and mirroring, and expanded FlowSpec integration across callbacks and automation. This release also introduces MongoDB TLS support, improves ClickHouse reliability, upgrades a wide range of core dependencies and toolchains, and adds numerous - [FastNetMon Advanced 2.0.382](https://fastnetmon.com/2026/07/20/fastnetmon-advanced-2-0-382/) - Release date: 20 July, 2026Version: 2.0.382 FastNetMon Advanced 2.0.382 is a security-focused maintenance release that strengthens the platform's resilience against malformed network telemetry and configuration validation issues. This release addresses multiple security advisories by improving the robustness of sFlow, NetFlow v9/IPFIX, and packet parsing, eliminating a potential race condition in template handling, and adding strict validation for - [FastNetMon Now Supports HTTP and HTTPS Proxies](https://fastnetmon.com/2026/07/20/fastnetmon-now-supports-http-and-https-proxies/) - Many enterprise and service provider networks tightly control outbound Internet access. Whether you're deploying FastNetMon in a secure data centre, a regulated environment, or behind a corporate firewall, direct outbound connectivity isn't always an option. We've recently introduced HTTP and HTTPS proxy support for FastNetMon, making it easier to deploy and operate in environments where - [DDoS Scrubbing Centre Automation Explained](https://fastnetmon.com/2025/08/06/ddos-scrubbing-centre-automation-explained/) - As DDoS attacks grow in scale and complexity, modern mitigation strategies are evolving to meet the challenge. Organisations today have more powerful tools than ever—but success hinges on speed, automation, and adaptability. At FastNetMon, we believe that efficiency of DDoS defence lies in real-time detection and intelligent traffic diversion—especially when integrating with scrubbing centres. In - [New IoT Botnet Reveals How LLMs Are Changing Malware Development](https://fastnetmon.com/2026/07/16/new-iot-botnet-reveals-how-llms-are-changing-malware-development/) - Remember Script Kiddies? Well, it seems like we need to start talking about "Prompt Kiddies." Evidence that large language models are making their way into malware development has emerged from the analysis of TuxBot v3 Evolution, a newly discovered IoT botnet investigated by Palo Alto Networks Unit 42. According to the researchers, the botnet's developers - [Press Release: FastNetMon launches Netomics, a self-hosted routing intelligence platform](https://fastnetmon.com/2026/07/09/press-release-fastnetmon-launches-netomics-a-self-hosted-routing-intelligence-platform/) - New platform gives network operators complete visibility into Internet routing while keeping all routing intelligence inside their own infrastructure. London, UK – July 8, 2026 – FastNetMon is introducing Netomics, a self-hosted BGP routing intelligence platform that combines live routing data, registry information, RPKI validation, routing history and AI-assisted querying into a single application. Built - [Press release: FastNetMon announces leadership transition with CEO Kate Fateeva stepping down](https://fastnetmon.com/2025/10/16/press-release-fastnetmon-announces-leadership-transition-with-ceo-kate-fateeva-stepping-down/) - London, UK — October 16, 2025 — FastNetMon, a leading provider of network traffic visibility and DDoS protection solutions, today announced that Kate Fateeva, Co-founder and CEO, will step down from her role, effective October 24, 2025. Fateeva co-founded FastNetMon in 2014 and has led the company from its early days as an open-source GitHub - [NetUK3 - Event Recap](https://fastnetmon.com/2026/07/07/netuk3-event-page/) - NetUK3: Two great days with the UK network engineering community Over the past two days, we had the pleasure of attending NetUK3, spending some time with network operators, ISPs, vendors and infrastructure engineers from across the UK at The Brewery in London. We've travelled to quite a few conferences around the world this year, so - [Introducing Netomics: a self-hosted routing intelligence platform for network operations](https://fastnetmon.com/2026/07/06/introducing-netomics-a-self-hosted-routing-intelligence-platform-for-network-operations/) - Network operators have more routing data available today than ever before. Yet in practice, the data is still scattered across multiple tools, external services, and ad hoc workflows. When investigating a routing incident, engineers typically move between BGP lookup services, RPKI validators, IRR databases, WHOIS tools, historical route collectors, and internal monitoring systems. Each provides - [FastNetMon Community expands Fedora and EPEL support](https://fastnetmon.com/2026/07/06/fastnetmon-community-expands-fedora-and-epel-support/) - We’ve made FastNetMon Community easier to install and maintain across Fedora and Enterprise Linux environments. You can now find the updated Fedora package here. On the Fedora side, the package has been updated to the latest version, ensuring smoother upgrades and better alignment with current Fedora releases. For Enterprise Linux users, FastNetMon Community is now - [New RustDuck botnet targets internet-exposed devices and servers](https://fastnetmon.com/2026/07/02/new-rustduck-botnet-targets-internet-exposed-devices-and-servers/) - A newly discovered botnet called RustDuck is targeting internet-connected routers, IP cameras, Android TV boxes, and exposed servers to build a DDoS attack network. Researchers at QiAnXin XLab have been tracking the malware since February 2026. While RustDuck is still relatively small, its rapid technical evolution makes it worth watching. Unlike many existing IoT botnets, - [The Current Reality of Residential Proxy DDoS Botnets](https://fastnetmon.com/2026/06/24/the-current-reality-of-residential-ddos-botnets/) - If you track cybersecurity headlines, it looks like the global battle against DDoS has entered a quiet period. The massive, record-breaking multi-terabit attacks that regularly made the front pages last year seem to have vanished. Much of this silence follows a major international law enforcement operation, coordinated with Europol and the U.S. Department of Justice. - [Understanding Ultra Ethernet and the 1.6T Ethernet standard](https://fastnetmon.com/2026/06/25/understanding-ultra-ethernet-and-the-1-6t-ethernet-standard/) - If you work in networking, you know the drill: optimise for throughput, minimise packet loss, and let the upper layers deal with the rest. That approach has worked well for decades. However, AI workloads place very different demands on networks than traditional enterprise applications. When thousands of GPUs communicate with each other to train a - [Case Study: Enhancing network security with country lockdown - a major American insurance corporation](https://fastnetmon.com/2024/12/25/case-study-enhancing-network-security-with-country-lockdown-a-major-american-insurance-corporation/) - Case Study: FastNetMon Country Lockdown Solution in Insurance EnvironmentDownload Overview A leading North American insurance corporation, specialising in life insurance and a broad array of financial products and services, has implemented FastNetMon's advanced country lockdown feature to enhance its network security posture. This case study explores the application of this feature within the corporation's network - [Engineering deep dive: How AMS-IX uses FastNetMon for automated DDoS mitigation](https://fastnetmon.com/2026/01/27/engineering-deep-dive-how-ams-ix-uses-fastnetmon-for-automated-ddos-mitigation/) - Introduction DDoS attacks have long been a thorn in the side of network operators—but AMS-IX faced a particularly unusual challenge. Unlike the massive volumetric attacks that make headlines, the attacks targeting their management network were low-bandwidth but high-flow, exploiting vulnerabilities in session tables, firewall logging, and internal routing. Even small bursts of DDoS traffic could cascade - [Case Pentanet: Real-Time DDoS Detection at the Edge](https://fastnetmon.com/2026/04/06/case-pentanet-real-time-ddos-detection-at-the-edge/) - Introduction For network engineers running ISP infrastructure, DDoS activity does not always present as an obvious incident. Instead, unusual traffic patterns may only become visible during later analysis, long after the event itself. This was the operational reality at Australian ISP Pentanet. As the network grew and traffic arrived through multiple upstream and peering paths, - [Case Joy Services: Automated DDoS detection and hardware-accelerated mitigation](https://fastnetmon.com/2026/06/15/case-joy-services-automated-ddos-detection-and-hardware-accelerated-mitigation/) - Introduction For cloud infrastructure and infrastructure-as-a-service (IaaS) providers handling highly dynamic workloads, network availability is directly tied to customer retention. When volumetric DDoS attacks strike, the immediate consequence is often network congestion that can affect customer services and infrastructure availability. This was the challenge faced by Indian provider Joy Services. Following the expansion of their - [FastNetMon at Route to Networking Podcast](https://fastnetmon.com/2025/03/18/fastnetmon-at-route-to-networking-podcast/) - An in-depth discussion on all things DDoS In this episode of the Router Networking Podcast, James Dean interviews Pavel Odintsov, co-founder of FastNetMon. Pavel shares his journey from a curious child dismantling audio equipment to becoming a key figure in cybersecurity. He discusses the challenges of dealing with DDoS attacks, the evolution of network security, - [Free FastNetMon Advanced License For All Non-Profit IXPs](https://fastnetmon.com/2022/09/16/free-fnm-license-for-ixps/) - Are you a non for profit IXPs and looking for a tool for DDoS detection and traffic visibility? Contact us. We provide a FastNetMon license for you for free. - [Exploring FastNetMon at The Hedge Podcast](https://fastnetmon.com/2025/03/06/exploring-fastnetmon-at-the-hedge-podcast/) - Read the discussion on DDoS Detection and Network Security In this episode of the Hedge podcast, hosts Russ White and Pavel Odintsov explore the functionalities of FastNetMon, a powerful open-source DDoS detection software. They discuss its capabilities in monitoring network traffic, detecting potential threats, and integrating with various BGP implementations for effective traffic management. Pavel - [Layer 3 DDoS attacks explained](https://fastnetmon.com/2025/03/11/layer-3-ddos-attacks-explained/) - What are L3 DDoS attacks, and how do they work? Layer 3 DDoS attacks are a type of cyber assault that targets the third layer of the OSI (Open Systems Interconnection) model, which is responsible for routing data packets across networks. These attacks focus on overwhelming core network devices like switches and routers, which are - [FastNetMon at the Packet Pushers Podcast discussing DDoS defence](https://fastnetmon.com/2025/03/16/fastnetmon-at-the-packet-pushers-podcast-discussing-ddos-defence/) - Read the in-depth discussion on DDoS Detection and Mitigation In this episode of the Packet Pushers podcast, we dive into the world of DDoS detection with FastNetMon, an open-source solution designed to identify and mitigate distributed denial of service attacks. Hosted by the Packet Pushers, the conversation features Pavel Odintsov, the project leader of FastNetMon. - [Second visit of FastNetMon at The Hedge Podcast](https://fastnetmon.com/2025/03/18/second-visit-of-fastnetmon-at-the-hedge-podcast/) - Read the in-depth discussion on FastNetMon use cases In this episode of the Hedge, hosts Russ White and Tom Ammon are joined by Pavel Odintsov, the CTO of FastNetMon, to explore the capabilities and use cases of this open-source DDoS detection tool. The discussion delves into the unique features of FastNetMon, including its ability to - [DDoS attack cause another DigiD outage in the Netherlands](https://fastnetmon.com/2025/03/18/ddos-attack-cause-another-digid-outage-in-the-netherlands/) - Imagine trying to file your taxes or access your medical records, only to find the system completely down. That’s what happened with DigiD, the Dutch government’s login system. Twice. A large DDoS attack disrupted the service in the first week of March, leaving a lot of people unable to use important online services. It wasn’t - [DDoS defence for hosting providers](https://fastnetmon.com/2025/04/03/ddos-defence-for-hosting-providers/) - Understanding DDoS Attacks from the hosting provider’s point of view As the backbone of the internet, hosting providers are pivotal in defending against DDoS attacks. Their ability to maintain the accessibility and reliability of websites and applications is vital for customer satisfaction and their own reputation. However, this responsibility also exposes them to the threat - [Fact & Fiction of X DDoS Attack: DDoS professionals comment](https://fastnetmon.com/2025/04/04/x-formerly-twitter-ddos-attack-fact-fiction/) - What can we learn from the alleged high-profile cyber attack? Earlier this month, social media platform X (formerly Twitter) experienced a major DDoS attack that caused intermittent outages for users worldwide. While service was eventually restored, the real story began after the attack, when Elon Musk published claims about its origin. Just weeks after the - [FastNetMon becomes a Code Protector of OpenSSL Foundation](https://fastnetmon.com/2026/02/27/fastnetmon-becomes-a-code-protector-of-openssl/) - We’re pleased to share that FastNetMon is now officially a Code Protector supporter of OpenSSL, as published by the OpenSSL Foundation. This reflects our commitment to strong cryptography and to supporting the open-source projects that form the foundation of secure internet communications. Why we support OpenSSL OpenSSL is one of the most widely used open-source - [Unusual Large-Scale Outbound DDoS Activity Observed Across Indian Networks](https://fastnetmon.com/2026/03/26/unusual-large-scale-outbound-ddos-activity-observed-across-indian-networks/) - We are tracking a significant surge in outbound DDoS activity originating from residential broadband networks across India. Over the last 72 hours, traffic analysis indicates abnormal outbound UDP patterns affecting hundreds of networks. This analysis is based on telemetry from a major Broadband Network Gateway (BNG) vendor and corroborated by several operator observations. The activity - [CloudFest 2026 - Event Recap](https://fastnetmon.com/2026/03/27/cloudfest-2026-event-recap/) - From March 23–26, the FastNetMon team attended CloudFest 2026, one of the largest global gatherings for the internet infrastructure industry, held at the ever-so-fun Europa-Park in Germany. Representing FastNetMon on-site was Virgil Truica, Head of Sales, who spent four intensive days meeting partners, reconnecting with industry peers, and discussing the evolving challenges facing network operators - [Sneak peek: Building a high-performance VPP-based inline filter at FastNetMon](https://fastnetmon.com/2026/06/11/sneak-peek-building-a-high-performance-vpp-based-inline-filter-at-fastnetmon/) - For the past decade, FastNetMon has been trusted by network operators globally as an elite, ultra-fast out-of-band DDoS detection engine. It acts as the intelligent detection plane, analysing flow telemetry such as NetFlow, sFlow, and IPFIX, spotting anomalies in seconds, and orchestrating upstream mitigation via BGP FlowSpec or RTBH. But a major evolution is currently - [NANOG 97 - Event Recap](https://fastnetmon.com/2026/06/08/see-you-at-nanog-97/) - See the presentation slides hereDownload The room was packed with operators, and the Q&A afterwards got straight to the point. The technical questions and immediate real-world challenges raised by the audience showed us that the exact problems we’re trying to solve are top-of-mind for engineering teams right now. In fact, the presentation didn't really end - [Taiwan Internet Week & TWNOG 7 - Event Recap](https://fastnetmon.com/2026/05/16/see-you-at-taiwan-internet-week-twnog-7/) - FastNetMon attended Taiwan Internet Week 2026 and TWNOG 7 in Taipei on 12–15 May 2026. It was a great week filled with impromptu meetings, technical discussions, catching up with friends, and conversations about where DDoS defence and network security are heading next. Check out our event shorts on YouTube! Taiwan Internet Week On 14 May, - [FastNetMon Advanced 2.0.380](https://fastnetmon.com/2026/05/27/fastnetmon-advanced-2-0-380/) - Release date: 27 May, 2026Version: 2.0.380 This release includes multiple security fixes and stability improvements across BGP, Flow Spec, Netflow v9, IPFIX, packet parsing, and internal buffer handling code. It addresses several vulnerabilities (CVE-2026-48682, CVE-2026-48683, CVE-2026-48684, CVE-2026-48686, CVE-2026-48688, CVE-2026-48689, CVE-2026-48690, and CVE-2026-48691) through stricter boundary validation, safer parsing logic, integer overflow protections, and expanded test coverage. The - [KimWolf DDoS botnet operator arrested](https://fastnetmon.com/2026/05/25/kimwolf-ddos-botnet-operator-arrested/) - Canadian authorities have arrested a 23-year-old man suspected of operating the KimWolf IoT DDoS-for-hire botnet as part of a coordinated international investigation involving Canada, the United States, and Germany. The suspect, Jacob Butler (alias “Dort”), is accused of developing and managing KimWolf, a large IoT-based botnet built from compromised devices, including webcams and digital photo - [RIPE 92 - Event Recap](https://fastnetmon.com/2026/05/22/see-you-at-ripe-92/) - RIPE 92 took place in Edinburgh, Scotland, bringing together ISPs, network operators, registries, and engineers for a week of working groups, plenaries, and a lot of hallway discussions. From FastNetMon, Outi Pietilanaho attended, splitting time between sessions and the usual RIPE meeting rhythm: talks, coffees, and meetings with friends and partners. of FastNetMon. Our plenary - [ITW 2026 - Event Recap](https://fastnetmon.com/2026/05/22/see-you-at-itw-2026/) - ITW is always one of those events where the telecom industry compresses months of conversations into a few very busy days. This week, Virgil Truica represented FastNetMon at International Telecoms Week 2026 in National Harbor, meeting with carriers, telecom operators, infrastructure providers, hosting companies, IXPs, and long-time industry partners from around the world. What makes - [RIPE SEE 14 - Event Recap](https://fastnetmon.com/2026/04/23/see-you-at-ripe-see-14/) - We just visited the RIPE SEE regional meeting in Belgrade, Serbia, now organised for the 14th time. More than 200 attendees from across the South East Europe Internet community gathered for two days of technical discussions, operational knowledge sharing and regional networking. Held on 21–22 April 2026 at the Crowne Plaza Belgrade, the event continued - [MAP-T in 2026: Stateless IPv4-over-IPv6 translation and what operators debate in production networks](https://fastnetmon.com/2026/05/06/map-t-in-2026-stateless-ipv4-over-ipv6-translation-and-what-operators-actually-debate-in-production-networks/) - As we move through 2026, IPv6 adoption continues to increase steadily across service provider networks, enterprise backbones, and mobile infrastructures. However, IPv4 is still far from disappearing in practice. A large portion of global internet traffic, applications, and legacy services continues to rely on IPv4 connectivity, which means operators must still maintain mechanisms to bridge - [FastNetMon Advanced 2.0.379](https://fastnetmon.com/2026/05/21/fastnetmon-advanced-2-0-379/) - Release date: 31 May, 2026Version: 2.0.379 FastNetMon Advanced 2.0.379 introduces a major rewrite of IPv4 and IPv6 network loading and lookup logic, improving scalability, concurrency, and memory management for large-scale deployments. The release also enhances traffic_db with fully asynchronous ClickHouse inserts to prevent packet drops on busy systems, alongside new Prometheus monitoring support and expanded observability options. - [Datacenter Forum 2026 - Event Recap](https://fastnetmon.com/2026/05/11/see-you-at-datacenter-world-2026/) - Last week FastNetMon attended DataCenter Forum Romania 2026 in Bucharest. Representing our team at the event was Virgil Truica, FastNetMon’s Head of Sales, who spent the day meeting with infrastructure operators, hosting providers, cloud teams, and data centre professionals from across the region. Now in its 8th edition, the event has clearly become one of - [Ubuntu and Canonical services disrupted by a DDoS attack](https://fastnetmon.com/2026/05/04/ubuntu-and-canonical-services-disrupted-by-ddos-attack/) - Ubuntu users experienced widespread service disruptions last week after a sustained DDoS attack targeted infrastructure operated by Canonical, impacting critical systems, including package updates and security-related services. According to public statements, the attack began on Thursday, May 1, with Canonical confirming that its “web infrastructure [was] under a sustained, cross-border attack.” The disruption affected multiple - [Network Engineering Community News: April 2026](https://fastnetmon.com/2026/04/30/network-engineering-community-news-april-2026/) - Welcome to our Network Engineering Community News! Hi from FastNetMon! March brought plenty to share. We released two new FastNetMon Advanced versions, added Debian 13 support and Bison router integration, welcomed a new senior engineering contributor to the team, and covered key updates and industry events. Happy reading! Want this letter straight to your inbox? - [Introducing FastNetMon LiveView](https://fastnetmon.com/2026/04/29/introducing-fastnetmon-liveview/) - Real-time visibility, DDoS analysis, and control in one interface We’re introducing FastNetMon LiveView, the official web interface add-on for FastNetMon. LiveView brings real-time traffic analytics, DDoS visibility, reporting, and configuration management into a single browser-based interface. It is designed to give network operators and security teams immediate insight into what is happening on their infrastructure. - [FastNetMon Advanced 2.0.378](https://fastnetmon.com/2026/04/27/fastnetmon-advanced-2-0-378/) - Release date: 27 April, 2026Version: 2.0.378 FastNetMon Advanced 2.0.378 improves flexible counters by fixing a minor degradation issue in the underlying fcli component. The release also enhances BGP processing with up to 2x faster table loading, additional profiling, and expanded support for standard BGP attributes. ClickHouse integrations have been strengthened with TLS connectivity, improved cloud compatibility, and - [FastNetMon Advanced 2.0.377](https://fastnetmon.com/2026/04/17/fastnetmon-advanced-2-0-377/) - Release date: 17 April, 2026Version: 2.0.377 FastNetMon Advanced 2.0.377 delivers a major refactor of the command line tool and API, making integrations more modern and maintainable. The release also improves IPv6 traffic visibility by fixing an issue that could prevent network traffic from being detected correctly. New operational controls have been added to give administrators more flexibility - [Mastodon says flagship mastodon.social server hit by DDoS attack](https://fastnetmon.com/2026/04/21/mastodon-says-flagship-mastodon-social-server-hit-by-ddos-attack/) - Mastodon says its primary public instance, mastodon.social, was targeted by a DDoS attack on 20 April 2026, causing intermittent outages and rendering the service inaccessible for some users. The incident follows the recent prolonged DDoS attack against Bluesky, another decentralised social network. According to public updates, the incident was identified at around 7:00 a.m. ET, - [Bluesky hit by prolonged DDoS attack causing widespread outages](https://fastnetmon.com/2026/04/20/bluesky-hit-by-prolonged-ddos-attack-causing-widespread-outages/) - Bluesky has confirmed that a recent wave of outages affecting its app and website was caused by a sophisticated DDoS attack that disrupted several core platform services between 15 and 17 April 2026. According to public statements, service interruptions began on 15 April at around 8:40 p.m. ET and continued intermittently through 17 April as - [Europol-backed Operation PowerOFF targets DDoS-for-hire ecosystem, contacts 75,000+ users](https://fastnetmon.com/2026/04/16/europol-backed-operation-poweroff-targets-ddos-for-hire-ecosystem-contacts-75000-users/) - A coordinated international law enforcement action supported by Europol has targeted the global DDoS-for-hire ecosystem, identifying more than 75,000 users involved in launching attacks. The operation, part of the ongoing Operation PowerOFF initiative, brought together authorities from 21 countries during a joint action week on 13 April 2026. According to Europol, enforcement and prevention measures - [Installation and configuration of FastNetMon: simple on the surface, deeply configurable underneath](https://fastnetmon.com/2026/04/16/installation-and-configuration-of-fastnetmon-simple-on-the-surface-deeply-configurable-underneath/) - We often hear the same feedback from FastNetMon users: It’s simple, it just works, and it does exactly what it’s supposed to do: detect DDoS attacks and launch mitigation actions. That’s not by coincidence. It reflects a core philosophy we’ve followed from day one: build simple, functional tools for network operators that hold up in - [Event recap - Bucharest Cybersecurity Conference 2025](https://fastnetmon.com/2025/10/09/event-recap-bucharest-cybersecurity-conference-2025/) - The Bucharest Cybersecurity Conference 2025 (BCC2025) is wrapping up today - and it has been an interesting week! Hosted by the Romanian National Cyber Security Directorate (DNSC) with support from ENISA, ECCC, and ANSSI, this three-day event brought together policymakers, industry leaders, and technical experts from across Europe. With hundreds of participants and dozens of - [NANOG 96 - Event Recap](https://fastnetmon.com/2026/02/06/nanog-96-event-recap/) - FastNetMon attended NANOG 96, held 2–4 February 2026 in San Francisco, joining over 800 network engineers, operators, and architects for three days of technical talks, hallway debates, and community catch-ups. As always, NANOG delivered exactly what makes it unique. The conference combined deeply practical presentations with open sharing of operational experience, alongside the informal conversations - [APRICOT 2026 - Event Recap](https://fastnetmon.com/2026/02/12/apricot-2026-event-recap/) - APRICOT 2026 in Jakarta brought together one of the most technically sharp and operationally focused Internet communities we’ve seen this year. As Asia Pacific’s largest Internet operations conference, APRICOT continues to be a place where engineers, operators, researchers, and policy communities meet to exchange very practical knowledge about running and protecting real networks at scale. - [FastNetMon strengthens engineering team with Sergei Mamonov](https://fastnetmon.com/2026/03/10/fastnetmon-welcomes-sergei-mamonov-as-senior-systems-engineer/) - We’re pleased to be working with Sergei Mamonov, who will be contributing to FastNetMon as a Senior Systems Engineer, strengthening our engineering team as adoption of FastNetMon continues to grow across hosting providers, ISPs, and telecom operators worldwide. Sergei brings more than 15 years of hands-on experience operating large-scale production infrastructure in the hosting and - [FastNetMon collaborates with NLnet Labs on Rotonda BGP and Flow Spec development](https://fastnetmon.com/2026/03/12/fastnetmon-collaborates-with-nlnet-labs-on-rotonda-bgp-and-flow-spec-development/) - FastNetMon is collaborating with NLnet Labs to advance the development of Rotonda, an open source routing platform designed for high-performance routing data processing. The collaboration focuses on expanding Rotonda into a fully functional BGP daemon with BGP Flow Spec support, enabling new capabilities for routing automation, traffic filtering, and network security applications. Functionality developed through - [FastNetMon Advanced Adds Support for Debian 13](https://fastnetmon.com/2026/03/23/fastnetmon-advanced-adds-support-for-debian-13/) - FastNetMon Advanced now officially supports Debian 13 (Trixie), enabling deployment on the latest stable release of one of the most widely used Linux distributions in server and network environments. This ensures that network operators can take advantage of the newest system libraries, toolchains, and kernel improvements while maintaining the stability and reliability they expect from - [Alleged DDoS-for-hire operator behind Fluxstress arrested in Thailand](https://fastnetmon.com/2026/04/14/alleged-ddos-for-hire-operator-behind-fluxstress-arrested-in-thailand/) - Thai authorities have arrested a 27-year-old German national suspected of operating major DDoS-for-hire platforms, following a multi-year international investigation involving European law enforcement and INTERPOL. The suspect, identified as Noah Christopher, was detained in Bangkok’s Thong Lo district during a joint operation by Thailand’s Cyber Crime Investigation Bureau (CCIB) and Immigration Bureau. The arrest was - [The Strait of Hormuz & Beyond: Cables, conflict and connectivity analysed](https://fastnetmon.com/2026/04/10/the-strait-of-hormuz-beyond-tracking-data-routes-across-the-gulf/) - Introduction: The Strait of Hormuz and Gulf Connectivity While the world watches the Strait of Hormuz for its energy impact, for network engineers, the story runs deeper. This narrow waterway is a primary artery for international data, where a dense cluster of subsea cables follows the same channels that carry global energy. Today, these waters - [Significant DDoS disruption affects Russian state telecom and online services](https://fastnetmon.com/2026/04/08/significant-ddos-disruption-affects-russian-state-telecom-and-online-services/) - On 6 April 2026, Russian state-run telecommunications provider Rostelecom was hit by a large-scale DDoS attack, affecting internet access, online banking, and government platforms across 30 major cities. The disruptions started unfolding around 9:00 p.m. Moscow time, according to Downdetector reports. Rostelecom confirmed the intrusion to state media, saying the attack was “neutralised” by 11:09 - [FastNetMon Advanced 2.0.375](https://fastnetmon.com/2026/03/30/fastnetmon-advanced-2-0-375/) - Release date: 30 March, 2026Version: 2.0.375 FastNetMon Advanced 2.0.375 delivers improvements to traffic visibility, flow tracking, and analytics, alongside expanded protocol parsing and ClickHouse enhancements. This release introduces deeper sFlow observability with new parsing success and error counters, PPP traffic extraction support, and improved MPLS handling across NetFlow v9, IPFIX, XDP, and AF_PACKET inputs. Flow tracking has - [FastNetMon Advanced 2.0.376](https://fastnetmon.com/2026/04/07/fastnetmon-advanced-2-0-376/) - Release date: 7 April, 2026Version: 2.0.376 FastNetMon Advanced 2.0.376 introduces protocol parsing improvements, enhanced flow visibility, and platform lifecycle updates, while continuing to refine analytics and integrations. This release adds PPPoE IPv6 parsing and expanded counter handling for the sFlow plugin, alongside a new option to process counters delivered via sFlow. Flow Spec workflows are improved with - [FastNetMon Advanced now supports PagerDuty integration](https://fastnetmon.com/2026/04/01/fastnetmon-advanced-now-supports-pagerduty-integration/) - FastNetMon Advanced now supports sending attack notifications directly to PagerDuty, enabling organisations to route DDoS detection events into their existing incident response workflows. Teams using PagerDuty for on-call management and escalation can now receive FastNetMon alerts as structured incidents, allowing network attacks to be handled through standard operational processes. Incident-driven DDoS response FastNetMon detects abnormal - [Network Engineering Community News: March 2026](https://fastnetmon.com/2026/03/31/network-engineering-community-news-march-2026/) - Network Engineering Community News - from FastNetMon Welcome to our Network Engineering Community News! Hi from FastNetMon! March brought plenty to share. We released two new FastNetMon Advanced versions, added Debian 13 support and Bison router integration, welcomed a new senior engineering contributor to the team, and covered key updates and industry events. Happy reading! - [Aisuru and KimWolf disrupted, but the botnet cycle continues](https://fastnetmon.com/2026/03/20/aisuru-and-kimwolf-disrupted-but-the-botnet-cycle-continues/) - Record-breaking botnets disrupted as a new challenger quietly appears March 19, 2026, international law enforcement announced one of the largest coordinated disruptions of IoT DDoS infrastructure to date. Authorities in the United States, Germany, and Canada targeted command-and-control infrastructure behind the Aisuru, KimWolf, JackSkid, and Mossad botnets: the networks responsible for hundreds of thousands of - [Cloud vs on-prem DDoS protection](https://fastnetmon.com/2025/06/03/cloud-vs-on-prem-ddos-protection/) - DDoS protection in cloud or on-premise: pros, cons, and the rise of hybrid defences Distributed-Denial-of-Service attacks used to be the headache of large carriers and gaming giants. Today they reach everyone from small hosting firms to municipal websites. That change has pushed security teams to decide where DDoS filtering should live: in the cloud, on - [FastNetMon Advanced 2.0.374](https://fastnetmon.com/2026/03/09/fastnetmon-advanced-2-0-374/) - Release date: 9 March, 2026Version: 2.0.374 FastNetMon Advanced 2.0.374 introduces multiple stability improvements, protocol enhancements, and new observability features. This release adds full MPLS parsing support for the sFlow v5 plugin, expanded Nokia SR Shim capabilities, and improved BGP functionality including better IPv6 next hop handling, BMP support, and per-hostgroup community configuration. It also introduces new API - [Understanding the BGP Monitoring Protocol (BMP)](https://fastnetmon.com/2026/03/04/understanding-the-bgp-monitoring-protocol/) - This is a guest contribution from Brian Wilson (BGP Brian), creator of the BGP Black Belt community and educator focused on BGP operations. Border Gateway Protocol (BGP) is the routing protocol of the Internet. It determines how traffic moves between autonomous systems and ultimately decides where packets go. But while BGP makes routing decisions, it - [Geofeed RFC 9632: Why Operators Should Publish Their IP Geolocation Data](https://fastnetmon.com/2026/02/19/geofeed-rfc-9632-why-operators-should-publish-their-geoip-data/) - IP geolocation in the modern network stack IP geolocation data quietly influences a large number of operational decisions on today’s Internet. It affects: Geo-based cybersecurity policies Compliance and sanctions enforcement Content licensing restrictions Fraud detection systems Traffic analytics and reporting Yet in most cases, the geographic location of IP address space is still determined by - [ASPA: the next layer of routing security](https://fastnetmon.com/2026/02/25/aspa-the-next-layer-of-routing-security/) - For more than a decade, RPKI and Route Origin Validation (ROV) have helped reduce accidental prefix hijacks. Today, it is much harder for a network to incorrectly announce someone else’s address space without being detected. But origin validation never answered a deeper question: Is this AS path economically and topologically plausible? That gap is what - [Network Engineering Community News: November 2025](https://fastnetmon.com/2024/11/30/network-engineering-community-news-november-2025/) - Network Engineering Community News – FastNetMon Welcome to our Network Engineering Community News! Hi from FastNetMon! November came with plenty to talk about. We’ve got a standout guest post from one of the most recognisable voices in BGP, a very cool webinar to help you shape your DDoS strategy for 2026, an early look at - [Network Engineering Community News: June 2025](https://fastnetmon.com/2025/06/25/network-engineering-community-news-june-2025/) - Greetings from FastNetMon, your fast and reliable DDoS detection solution provider. Here's your monthly dosis of hottest industry events, network security threats, and useful product updates we think you should know to keep your networks safe. Enjoy! ⚡️ Network Engineering Community News Hello from FastNetMon! This month’s newsletter includes two sharp DDoS strategy insights you - [Network Engineering Community News: September 2025](https://fastnetmon.com/2025/09/25/network-engineering-community-news-september-2025/) - Welcome to our Network Engineering Community News! Hi from FastNetMon! September has been anything but quiet: record-scale DDoS attacks, new botnets, and plenty of network security updates kept us busy. In this issue, we’re sharing a practical telemetry guide, recapping our recent webinar, and bringing news from RONOG 10. And as usual, we're rounding up - [Network Engineering Community News: October 2025](https://fastnetmon.com/2025/10/30/network-engineering-community-news-october-2025/) - Welcome to our Network Engineering Community News! Hi from FastNetMon! October brought plenty of tricks and treats on the network front: outbound DDoS attacks, new botnets lurking in misconfigured servers, Linux updates that improve resilience under DDoS attacks, and much more. Happy reading! Want this letter straight to your inbox? Sign up to our monthly - [Network Engineering Community News: February 2026](https://fastnetmon.com/2026/02/26/network-engineering-community-news-february-2026/) - Welcome to our Network Engineering Community News! If you’re new here, welcome. This monthly update goes out to everyone who has used or trialed FastNetMon. In February, we were at APRICOT in Jakarta and NANOG in San Francisco, rolled out major web updates, and kicked off a new community initiative, while also covering key industry - [Aisuru botnet sets a new DDoS record at 31.4 Tbps](https://fastnetmon.com/2026/02/01/aisuru-botnet-sets-a-new-ddos-record-at-31-4-tbps/) - Another DDoS record has been reported, and once again, it is the same botnet setting it. In late January 2026, Cloudflare disclosed details of what is now the largest publicly reported DDoS attack to date, an incident that occurred in December 2025 and peaked at 31.4 Tbps. The attack was attributed to the Aisuru botnet. - [Network Engineering Community News: December 2025](https://fastnetmon.com/2025/12/27/network-engineering-community-news-december-2025/) - Welcome to Network Engineering Community News – End of Year 2025 Hello from all of us at FastNetMon, your trusted partner in DDoS detection and mitigation. While the year is coming to a close, December was far from quiet in the network security field. In this issue, we cover some of the key activities from - [Case Study: DDoS detection and automated mitigation at Link3 with FastNetMon](https://fastnetmon.com/2025/12/17/case-study-ddos-detection-and-automated-mitigation-at-link3-with-fastnetmon/) - Case study summary As one of Bangladesh’s leading internet service providers, Link3 Technologies operates a high-traffic network that must remain stable and responsive under all conditions. To support this, Link3 deployed FastNetMon as the central platform for real-time DDoS detection and automated mitigation. By integrating FastNetMon directly into their network automation and remote scrubbing workflows, - [Event Recap – LINX125](https://fastnetmon.com/2025/11/21/event-recap-linx125/) - FastNetMon had the opportunity to attend LINX125 in London on 19–20 November 2025 as a guest, in the capacity of an ascending LINX member. It was a valuable chance for us to learn more about LINX, meet the community, and understand the current conversations shaping one of the world’s most influential internet exchanges. We are - [End may be near for Aisuru and Kimwolf botnets after large-scale C2 disruption](https://fastnetmon.com/2026/01/19/end-may-be-near-for-aisuru-and-kimwolf-botnets-after-large-scale-c2-disruption/) - One of the largest DDoS botnet operations observed in recent years may be facing sustained disruption after hundreds of command-and-control (C2) servers linked to the Aisuru and Kimwolf botnets were taken offline. According to research published by Lumen’s Black Lotus Labs, more than 550 C2 servers used by the botnets have been null-routed over the past four - [OCCRP reports sustained DDoS attack targeting its investigative journalism website](https://fastnetmon.com/2026/01/14/occrp-reports-sustained-ddos-attack-targeting-its-investigative-journalism-website/) - The Organized Crime and Corruption Reporting Project (OCCRP) has reported that its website has been targeted by a large-scale DDoS attack, slowing access and making it difficult for readers to reach its investigative reporting. According to OCCRP, the attack began on Monday and was still ongoing as of January 13, 2026. While the website has - [Venezuela’s routing anomaly and the bigger problem with BGP security](https://fastnetmon.com/2026/01/09/venezuelas-routing-anomaly-and-the-bigger-problem-with-bgp-security/) - In early January 2026, unusual Internet routing behaviour was observed involving AS8048, operated by CANTV, Venezuela’s state-owned telecommunications provider. The anomalies were highlighted by Graham Helton, a red team engineer writing on his blog Low End Orbit, based on publicly available BGP data. Soon after, Cloudflare published its own technical analysis of the same routing events, presenting another - [DDoS attacks disrupt Final Fantasy XIV Savage raid launch](https://fastnetmon.com/2026/01/07/ddos-attacks-disrupt-final-fantasy-xiv-savage-raid-launch/) - The launch of Final Fantasy XIV’s latest Savage raid tier in patch 7.4 was disrupted by a sustained wave of DDoS attacks, primarily affecting North American gamers. While European and Japanese regions remained largely stable, players in the US experienced repeated disconnects throughout the launch window, including during the high-profile race to world first. Community - [Orange Polska mitigated a large multi-vector DDoS attack on Christmas Eve](https://fastnetmon.com/2026/01/02/orange-polska-mitigated-a-large-multi-vector-ddos-attack-on-christmas-eve/) - Orange Polska mitigated a sizable DDoS attack on Christmas Eve, peaking at 1.5 Tbps. Orange Polska is the Polish national telecommunications operator and part of the Orange Group. The incident was first reported by the operator’s CERT team. The timing of the attack is notable. Christmas Eve typically coincides with elevated baseline traffic levels and reduced - [Kimwolf: possible Aisuru successor capable of multi-Tbps DDoS attacks](https://fastnetmon.com/2025/12/26/kimwolf-possible-aisuru-successor-capable-of-multi-tbps-ddos-attacks/) - A new “super botnet” Kimwolf reported by researchers Security researchers at XLab recently disclosed Kimwolf, a newly identified Android-based botnet that has allegedly infected more than 1.8 million devices worldwide. According to XLab’s findings, the botnet has issued over 1.7 billion DDoS attack commands in just three days, making it one of the largest active - [DDoS attack disrupts La Poste services just before Christmas](https://fastnetmon.com/2025/12/23/ddos-attack-disrupts-la-poste-services-just-before-christmas/) - DDoS News: France’s national postal service, La Poste, has confirmed that a DDoS attack disrupted its digital infrastructure, partially taking services offline and slowing parcel deliveries just before Christmas — one of the busiest periods of the year for the organisation. The incident began this Monday, December 22nd, and has persisted over 12 hours, affecting multiple public-facing - [Solana reports stable network operation during sustained multi-terabit DDoS attack](https://fastnetmon.com/2025/12/18/solana-reports-stable-network-operation-during-sustained-multi-terabit-ddos-attack/) - On December 16, 2025, Solana reported that its network had been under a sustained DDoS attack for approximately a week, with traffic peaking near 6 Tbps. Solana described the event as the fourth-largest DDoS attack ever recorded against any distributed system. Traffic volumes at this level are no longer exceptional in today’s DDoS environment and can be generated using - [CISA warns of hacktivist DDoS attacks on critical infrastructure OT systems](https://fastnetmon.com/2025/12/12/cisa-warns-of-hacktivist-ddos-attacks-on-critical-infrastructure-ot-systems/) - CISA, together with the FBI, the Department of Energy, the EPA, and international partners, have issued a joint advisory highlighting ongoing DDoS and intrusion attacks targeting operational technology (OT) and industrial control systems (ICS) within critical infrastructure. The alert focuses on opportunistic campaigns conducted by pro-Russia hacktivist groups, which continue to exploit exposed OT devices—including - [DDoS Defense by Design: Architecture That Survives When Everything Else Fails](https://fastnetmon.com/2025/12/12/ddos-defense-by-design-architecture-that-survives-when-everything-else-fails/) - This article is written by Herve Hildenbrand and was originally published on LinkedIn. Reposted with the author’s permission. A DDoS attack almost ruined my 40th birthday. Not the party, but the infrastructure I was responsible for. Friends texted “happy birthday.” Colleagues texted… differently. Even though they were kind enough to shield me that day, I couldn’t stay on - [The good and the bad of GRE tunnels in DDoS scrubbing](https://fastnetmon.com/2025/12/05/the-good-and-the-bad-of-gre-tunnels-in-ddos-scrubbing/) - One of the most common ways to protect a network from large volumetric DDoS attacks is to divert the malicious traffic to a scrubbing centre. These dedicated networks remove harmful packets and return only the clean traffic back to your network. GRE tunnels are often used for this return path because they work with any network - [New record-breaking DDoS: 29.7 Tbps Aisuru attack marks new high in hyper-volumetric threats](https://fastnetmon.com/2025/12/04/new-record-breaking-ddos-29-7-tbps-aisuru-attack-marks-new-high-in-hyper-volumetric-threats/) - DDoS news: December 4th 2025 A new world-record DDoS attack has been confirmed, peaking at 29.7 terabits per second (Tbps) and launched by the Aisuru botnet, a large DDoS-for-hire network using an estimated one to four million compromised routers and IoT devices worldwide. The attack lasted 69 seconds and was mitigated by Cloudflare, fending off a stream of randomised junk traffic targeting - [Why DDoS botnets are so hard to take down?](https://fastnetmon.com/2025/12/02/why-ddos-botnets-are-so-hard-to-take-down/) - Every time law enforcement announces a major DDoS botnet operation, the Internet seems to exhale in relief. Servers are seized, operators arrested, domains pulled out from under them. For a moment, attack volumes dip, and the collective hum of malicious traffic grows quieter. But the silence rarely lasts. Within days – sometimes within hours – - [ShadowV2 resurfaces: IoT botnet activity amid AWS outage highlights persistent device vulnerabilities](https://fastnetmon.com/2025/11/26/shadowv2-resurfaces-iot-botnet-activity-amid-aws-outage-highlights-persistent-device-vulnerabilities/) - During late October 2025, a new Mirai-derived botnet dubbed ShadowV2 was observed exploiting unpatched IoT devices across multiple sectors and 28 countries. While the activity lasted only a day, it underscores the ongoing risks posed by unsecured connected hardware. Technical summary of the current ShadowV2 campaign Industry research reports that ShadowV2 primarily targeted consumer and enterprise IoT - [Aisuru isn’t done with DDoS — and the Azure attack shows why the industry isn’t ready](https://fastnetmon.com/2025/11/21/aisuru-isnt-done-with-ddos-and-the-azure-attack-shows-why-the-industry-isnt-ready/) - This week, Microsoft confirmed it had mitigated the largest DDoS attacks ever observed on Azure: a 15.72 Tbps, 3.64 Bpps barrage against a single public IP endpoint in Australia. The attack was powered by Aisuru — the same TurboMirai-class botnet behind the 22 Tbps attack recently reported by Cloudflare. That alone is noteworthy. But the - [US, UK and Australia sanction Russian hosting providers behind major ransomware and DDoS activity](https://fastnetmon.com/2025/11/21/us-uk-and-australia-sanction-russian-hosting-providers-behind-major-ransomware-and-ddos-activity/) - The U.S. Department of the Treasury, together with the UK and Australia, has announced coordinated sanctions against a network of Russian “bulletproof” hosting providers (BPH) used to run ransomware operations and repeated DDoS attacks against organisations in the U.S. and allied countries. The action focuses on Media Land, a long-standing St. Petersburg–based hosting operator, as well - [ShadowRay 2.0: Self-replicating botnet turns Ray clusters into DDoS weapons](https://fastnetmon.com/2025/11/21/shadowray-2-0-self-replicating-botnet-turns-ray-clusters-into-ddos-weapons/) - Researchers are tracking a self-replicating botnet campaign, ShadowRay 2.0, that is targeting internet-facing Ray clusters, the open-source distributed computing framework used to run AI and other workloads. The attackers exploit a two-year-old, unpatched vulnerability (CVE-2023-48022) to take control of exposed clusters. The malware uses the exposed Ray dashboards to submit jobs without authentication, allowing it to spread automatically across clusters - [DDoS trends in public administration – new data from ENISA report](https://fastnetmon.com/2025/11/14/ddos-trends-in-public-administration-new-data-from-enisa-report/) - The European Union’s cybersecurity agency, ENISA, has published a new sectorial threat landscape report and a press release showing that public administrations are increasingly targeted by cyber-attacks, with DDoS emerging as the most common threat. Public administration, classified as highly critical under the NIS2 Directive, delivers essential services such as education, healthcare, transportation, and government functions. This - [Belgium hit by twin DDoS campaigns — what we know](https://fastnetmon.com/2025/11/14/belgium-hit-by-twin-ddos-campaigns-what-we-know/) - In early November 2025, Belgian networks were hit by two related DDoS campaigns targeting telecom operators, healthcare services, and military-intelligence websites. The pro-Russian hacktivist group NoName057 publicly claimed responsibility, citing Belgium’s political stance as the motive. Telecom and healthcare impact On 5 November, Proximus and Scarlet reported brief website outages after technicians detected unusual traffic - [BGP Blackhole for DDoS Mitigation — and How to Automate It with FastNetMon](https://fastnetmon.com/2025/11/14/bgp-blackhole-for-ddos-mitigation-and-how-to-automate-it-with-fastnetmon/) - We are pleased to welcome a guest contributor: BGP Brian (Brian Wilson). Brian leads the BGP Black Belt training community and the consultancy BGP Engineering and Design Group, and is an active voice on LinkedIn discussing all things BGP. Border Gateway Protocol (BGP), as you’re probably aware, is the routing protocol of the Internet. It - [Aisuru botnet shifts focus from DDoS to residential proxy services](https://fastnetmon.com/2025/11/07/aisuru-botnet-shifts-focus-from-ddos-to-residential-proxy-services/) - The Aisuru botnet, responsible for multiple record-breaking DDoS attacks this year, has reportedly altered its operations to supply infected IoT devices for use as residential proxies. This marks a shift from high-volume, short-term attacks toward a more sustainable, revenue-generating model. First identified in August 2024, Aisuru has infected by now at least 700,000 IoT devices, - [DDoS attacks disrupt Poland’s leading mobile payment system BLIK](https://fastnetmon.com/2025/11/07/ddos-attacks-disrupt-polands-leading-mobile-payment-system-blik/) - Poland’s largest digital payment service, BLIK, has suffered periodic outages after being targeted by distributed denial-of-service attacks over the weekend and into Monday. The incidents caused intermittent disruption for customers attempting to complete transactions through their mobile banking apps. BLIK confirmed that its infrastructure was hit by “external DDoS-type attacks” and noted that mitigation efforts - [Hezi Rash – new hacktivist group claims over 350 DDoS attacks worldwide](https://fastnetmon.com/2025/11/07/hezi-rash-new-hacktivist-group-claims-over-350-ddos-attacks-worldwide/) - A newly emerged hacktivist collective calling itself Hezi Rash (‘Black Force’) has sharply increased DDoS activity across multiple countries. Between August and October 2025, researchers observed around 350 attacks — a remarkable volume for a group that had only surfaced recently. Unlike more traditional hacktivist campaigns, Hezi Rash does not limit its focus to one region or sector. - [FastNetMon partners with Gcore for automated DDoS scrubbing](https://fastnetmon.com/2025/10/15/fastnetmon-partners-with-gcore-for-automated-ddos-scrubbing/) - We’re excited to announce our new integration with Gcore, enabling fully automated DDoS mitigation through real-time detection and instant redirection to Gcore’s scrubbing centres. With this integration, networks using FastNetMon Advanced can automatically detect and redirect DDoS traffic for scrubbing in under one second — with no manual operator intervention. How it works FastNetMon Advanced - [The DDoS Protection FAQ](https://fastnetmon.com/2023/01/09/ddos-protection-faq/) - Everything you’ve ever asked about DDoS attacks, and a few things you haven’t. - [Why DDoS Mitigation Should Be Built Into Your Digital Transformation Strategy](https://fastnetmon.com/2023/01/09/why-you-need-ddos-mitigation/) - We explore how enterprises’ growing reliance on digital tools and services leaves them susceptible to cyber attacks. - [Your Anti-DDoS Strategy: Three Ways to Prevent Attacks](https://fastnetmon.com/2023/02/01/anti-ddos-strategy-three-ways-to-prevent-attacks/) - Having an anti-DDoS platform is a crucial part in your website cybersecurity strategy. We explore three ways in which you can prevent DDoS attacks. - [2022 Roundup: What Happened in the World of DDoS?](https://fastnetmon.com/2023/02/14/2022-roundup-ddos/) - We reflect on the DDoS developments of 2022, as well as exploring the latest trends, news, and advice. - [Network Observability: A Key Component of Your Anti-DDoS Strategy](https://fastnetmon.com/2023/03/20/network-observability/) - Network observability is the first step in preventing any network-based cyberattack such as DDoS. 5 reasons you should be including network observability for anti-DDoS. - [Why is Network Traffic Visibility Important?](https://fastnetmon.com/2023/03/20/why-is-network-traffic-visibility-important/) - What is Network Traffic Visibility and why is it so important? Here are 5 Cybersecurity Use Cases for Network Traffic Visibility. - [How To Choose the Right Network Monitoring Tool](https://fastnetmon.com/2023/04/06/how-to-choose-the-right-network-monitoring-tool/) - Choosing which network monitoring tool to pick can unlock the power to monitor, manage and protect your business network, here are six things you should consider. - [IT Leaders Believe Visibility is Key to Network Security](https://fastnetmon.com/2023/04/06/it-leaders-believe-visibility-is-key-to-network-security/) - 81% of IT leaders believe network visibility is essential for strong network security and response, but why is it so important for network security? - [The Threat of DNS Amplification Attacks: Safeguarding Your Infrastructure](https://fastnetmon.com/2023/10/24/the-threat-of-dns-amplification-attacks-safeguarding-your-infrastructure/) - Learn about the threat of DNS amplification attacks and discover essential strategies to protect your infrastructure. - [Mitigating Application Layer DDoS Attacks: Best Practices for Online Businesses](https://fastnetmon.com/2023/10/24/mitigating-application-layer-ddos-attacks-best-practices-for-online-businesses/) - Discover the ins and outs of Application Layer DDoS attacks and learn essential strategies to protect your online business. Keep your web applications secure and available. - [The Rise of IoT Botnets: Protecting Your Network from Mirai Attacks](https://fastnetmon.com/2023/10/24/the-rise-of-iot-botnets-protecting-your-network-from-mirai-attacks/) - Discover the ongoing threat of Mirai botnets and learn how to mitigate it and other advanced DDoS threats, including UDP, TCP, and ICMP flooding attacks. - [Rise of carpet bombing DDoS attacks and ways to detect and defend against them using FastNetMon Advanced](https://fastnetmon.com/2023/10/24/rise-of-carpet-bombing-ddos-attacks-and-ways-to-detect-and-defend-against-them-using-fastnetmon-advanced/) - Learn about the rising threat of carpet bombing DDoS attacks and how FastNetMon Advanced offers powerful configuration options to help you detect and defend against them - [The importance of having a rapid DDoS protection to defend from flash attacks](https://fastnetmon.com/2023/10/24/the-importance-of-having-a-rapid-ddos-protection-to-defend-from-flash-attacks/) - Discover the importance of rapid DDoS protection to defend against flash attacks. Learn how FastNetMon accelerates DDoS response and protect networks. - [The Evolution of DDoS Attacks: Trends and Countermeasures](https://fastnetmon.com/2024/02/14/the-evolution-of-ddos-attacks-trends-and-countermeasures/) - How have DDoS attacks evolved over time? And how can you protect against them? - [The Benefits of FastNetMon for Small and Medium-sized Enterprises](https://fastnetmon.com/2024/02/14/the-benefits-of-fastnetmon-for-small-and-medium-sized-enterprises/) - FastNetMon’s powerful enterprise-grade quality DDoS detection and mitigation is perfect for all businesses – including SMEs - [Network Security Best Practices: Insights from FastNetMon Experts](https://fastnetmon.com/2024/02/14/network-security-best-practices-insights-from-fastnetmon-experts/) - Our experts lay out their advice for properly securing your network against cyberattacks. - [FastNetMon vs. Traditional Network Monitoring Solutions: A Comparative Analysis](https://fastnetmon.com/2024/02/27/fastnetmon-vs-traditional-network-monitoring-solutions-a-comparative-analysis/) - Discover how FastNetMon offers faster detection, cloud-ready analysis, instant automated traffic diversion, vendor neutrality, simple installation, and more. - [FastNetMon's Role in Protecting Cloud Infrastructure from DDoS Attack](https://fastnetmon.com/2024/02/29/fastnetmons-role-in-protecting-cloud-infrastructure-from-ddos-attack/) - How FastNetMon protects cloud-based assets from distributed denial of service attacks - [A Guide to FastNetMon's Advanced Features](https://fastnetmon.com/2024/02/14/a-guide-to-fastnetmons-advanced-features/) - DDoS protection is an essential defence against cybercrime. Discover how FastNetMon can secure your network. - [Ministry of defence in South Korea under DDoS attack](https://fastnetmon.com/2024/11/12/ministry-of-defence-in-south-korea-under-ddos-attack/) - In recent weeks, South Korea has found itself at the center of a series of distributed denial-of-service (DDoS) attacks, coinciding with heightened geopolitical tensions. The South Korean President’s Office has reported an uptick in cyber-attacks from politically motivated hacktivist groups, primarily targeting government websites and private companies. Among the targets have been the websites of - [Card readers malfunctioning in Israel due to a DDoS attack](https://fastnetmon.com/2024/11/13/card-readers-malfunctioning-in-israel-due-to-a-ddos-attack/) - On Sunday November 10th, a DDoS attack caused widespread disruption to credit card readers across Israel, affecting several payment systems in supermarkets and gas stations. The incident, which lasted approximately an hour, targeted the communications services of Hyp’s CreditGuard product, a key payment gateway company in the country. According to reports from the local media, - [FastNetMon Advanced 2.0.366](https://fastnetmon.com/2024/06/27/fastnetmon-advanced-2-0-366/) - FastNetMon has released a new update with several enhancements and additions. The update includes options for pcap reader to load networks list, a counter for tracking UDP packets, and improved logic for IPv6 address use in Netflow and IPFIX plugin. It also introduces FerretDB support for community configuration import and Ubuntu 24.04 support to the - [FastNetMon Advanced 2.0.363](https://fastnetmon.com/2024/03/26/fastnetmon-advanced-2-0-363/) - The version update 2.0.363 is packed with many requested updates from our users. We migrated from Patricia tree to a new lookup_tree_128bit_t and implemented full support for gobgp_next_hop_host_ipv6 and gobgp_next_hop_subnet_ipv6. We've also added logic to provide additional BGP communities on a hostgroup basis and unified various functions and types for improved efficiency. We've also introduced - [FastNetMon Advanced 2.0.361](https://fastnetmon.com/2024/03/04/fastnetmon-advanced-2-0-361/) - In our latest release, we've made significant enhancements to improve efficiency and user control. We've enabled netflow_ipfix_inline and netflow_v9_lite support by default, and added the option for custom password setting via the installer flag reset_visual_passwords. We've also implemented complete logic for BGP Flow Spec redirect action and improved its rate and discard encoding. Additionally, we've - [FastNetMon Advanced 2.0.359](https://fastnetmon.com/2024/02/09/fastnetmon-advanced-2-0-359/) - Our latest release introduces several enhancements and fixes. We've added support for IPFIX UDP and TCP port encoding used by AMD Pensando, and extracted Netflow v5, v9, and IPFIX into separate modules. We've also fixed a bug with IPFIX sampling rate persistence. New features include support for multiple flows per packet for IPFIX inline monitoring - [BGP Flow Spec for DDoS Mitigation](https://fastnetmon.com/2025/02/10/bgp-flow-spec-for-ddos-mitigation/) - Introduction to BGP Flow Spec The frequency and scale of DDoS attacks are continuing to rise. Incidents involving hundreds of gigabits are becoming increasingly routine, and organisations face severe threats to their network infrastructures. BGP Flow Spec has become an essential tool for combating large volumetric attacks. Using BGP to propagate detailed traffic filtering rules - [How FastNetMon can reduce the cost of cloud based DDoS scrubbing](https://fastnetmon.com/2023/10/24/how-fastnetmon-can-reduce-the-cost-of-cloud-based-ddos-scrubbing/) - Automated attack detection, lightning-fast response times, and resource optimisation make FastNetMon a vital addition to your cybersecurity defenses. Try it free for a month. - [Virgil Truica joins the FastNetMon team as Growth & Partnerships Lead](https://fastnetmon.com/2024/11/27/virgil-truica-joins-the-fastnetmon-team-as-growth-partnerships-lead/) - Welcome to the FastNetMon, Virgil Truica! We are delighted to welcome Virgil Truica to the FastNetMon team. Virgil brings with him over 16 years of experience in the International Telecom industry, with a particular focus on DDoS solutions, network security, and enterprise solutions. Virgil's extensive knowledge and experience will be instrumental in helping our customers - [Dutch hosting provider Argeweb battles week-long DDoS attack](https://fastnetmon.com/2025/04/14/dutch-hosting-provider-argeweb-battles-week-long-ddos-attack/) - Late March, a well-known Dutch web hosting provider, Argeweb, found itself under fire from a DDoS attack that spiralled into a week-long struggle to stay online. What started as a few complaints about slow-loading sites turned into widespread disruption as DNS servers were overwhelmed. The incident seemed like a simple technical issue, but after a - [DDoS, DoS, RDoS explained](https://fastnetmon.com/2025/04/16/ddos-dos-rdos-explained/) - What’s the difference between DoS, DDoS, RDoS, and how to prevent these cyberattacks? Not all cyberattacks are created equal. If you’ve ever heard terms like DoS, DDoS or RDoS and wondered what they mean, and why they keep showing up in the news, here’s a simple breakdown. DoS: The digital jam-up A Denial of Service - [BreachForums seized again, but who’s behind it this time?​](https://fastnetmon.com/2025/04/16/breachforums-seized-again-but-whos-behind-it-this-time/) - The notorious cybercrime marketplace BreachForums has gone offline once more, but this time, no one’s quite sure who’s behind it. While some suspect another FBI takedown, a group calling itself the Dark Storm Team claims they launched a DDoS attack on the site ‘for fun.’ ​ Dark Storm Team is a pro-Palestinian hacktivist group known - [How did DDoS begin? A short history of DDoS reviewed](https://fastnetmon.com/2025/04/23/how-did-ddos-begin-a-short-history-of-ddos-reviewed/) - Evolution of DDoS: From single PCs to Terabit floods Twenty‑five years ago a teenager with a dial‑up modem discovered he could knock Yahoo! offline by hammering it with junk traffic. Since then denial‑of‑service attacks have morphed into a multi‑billion‑pound headache that can rattle entire countries. Let’s trace that journey, chapter by chapter, to see how - [Massive Power Outage Hits Spain, Portugal, and Parts of France](https://fastnetmon.com/2025/04/28/massive-power-outage-hits-spain-portugal-and-parts-of-france/) - Speculation of a cyber attack and data centre vulnerability raises concerns amidst a blackout in southern Europe In a dramatic turn of events, a widespread power outage has left millions across Spain, Portugal, and parts of France in the dark. This blackout, which began on April 28, 2025, has disrupted daily life, halting operations at - [Most infamous DDoS booter services - and user consequences](https://fastnetmon.com/2025/04/30/most-infamous-ddos-booter-services-and-user-consequences/) - Some of the largest IP booter services listed - and what happens if you use them Hiring a DDoS attack used to mean building a botnet or knowing someone who had. Booter services changed all that: pay a small fee, enter your target’s IP address, and a DDoS booter service does the rest. Schools, banks, - [DDoS booters and IP stressers explained by experts](https://fastnetmon.com/2025/04/10/ddos-booters-and-ip-stressers-explained-by-experts/) - "DDoS for hire" - how anyone can pay to take down a website You don’t need to be a hacker to launch a cyberattack anymore. These days anyone with £20 and a few minutes can rent a tool online and knock a website offline. These services are called DDoS booters, and while they may sound - [DDoS in geopolitics: when network traffic becomes a digital weapon](https://fastnetmon.com/2025/05/19/ddos-in-geopolitics-when-network-traffic-becomes-a-digital-weapon/) - The rise of DDoS in global conflicts With societies increasingly dependent on online services, the front lines of geopolitical conflict are no longer limited to physical borders. Increasingly, state-sponsored actors and politically motivated groups are turning to cyber tactics to assert influence, sow disruption, or make public statements. Among these tactics, Distributed Denial-of-Service (DDoS) attacks - [Building a Multi-Layered DDoS Defense Architecture](https://fastnetmon.com/2025/05/28/building-a-multi-layered-ddos-defense-architecture/) - Effective DDoS Mitigation Strategies: Building a Tiered Defence System DDoS attacks still remain one of the most persistent and disruptive cyber threats in today’s internet infrastructure. From volumetric floods to subtle, low-rate protocol attacks, the scale and variety of DDoS techniques demand more than a one-size-fits-all solution. That’s why resilient organisations rely on a multi-layered - [Tier 1 transit and the DDoS comfort myths](https://fastnetmon.com/2025/06/11/tier-1-transit-and-the-ddos-comfort-myths/) - If your organisation buys bandwidth from one of the big backbone carriers, you already sit behind formidable pipes and global scrubbing clouds. Sales decks often call this ‘built-in DDoS protection’. It sounds reassuring: why invest in extra defences when petabit routers stand between you and the internet? Yet every quarter we see outages at banks, - [Anatomy of a Botnet](https://fastnetmon.com/2025/06/18/anatomy-of-a-botnet/) - Botnets are behind some of the biggest online attacks we’ve seen in recent years. They don’t usually rely on advanced hacking techniques or zero-day exploits. Instead, they quietly take over poorly secured devices connected to the internet. The result is a network of infected machines—controlled remotely and used to flood targets with traffic until their - [When is BGP blackholing a good choice for DDoS mitigation — and when is it not?](https://fastnetmon.com/2025/06/18/when-is-bgp-blackholing-a-good-choice-for-ddos-mitigation-and-when-is-it-not/) - BGP Blackholing, also known as RTBH (Remotely Triggered Black Hole), is a well-established technique in the DDoS mitigation playbook. It’s fast, effective, and uses your upstream providers’ infrastructure to stop attack traffic before it ever reaches your network. But despite its power, RTBH is not always the right tool for the job. In this post, - [DDoS attacks are now targeting journalists, universities, NGOs. What has changed?](https://fastnetmon.com/2025/06/19/ddos-attacks-are-now-targeting-journalists-universities-ngos-what-has-changed/) - Historically, DDoS attacks focused on obvious targets: banks, telecoms, gaming platforms, and government services. But in 2025, the landscape has shifted. Today’s DDoS campaigns are increasingly aimed at organisations that weren’t considered strategic targets just a few years ago. Nonprofits, universities, and independent media outlets are now regularly under fire. These attacks aren’t always large - [Book Review: DDoS – Understanding Real-Life Attacks and Mitigation Strategies by Stefan Behte](https://fastnetmon.com/2025/06/25/book-review-ddos-understanding-real-life-attacks-and-mitigation-strategies-by-stefan-behte/) - Comprehensive resources on Distributed Denial of Service (DDoS) attacks are surprisingly hard to come by—especially ones that are both technically accurate and grounded in real-world experience. That’s why Stefan Behte’s new book,"DDoS: Understanding Real-Life Attacks and Mitigation Strategies" (2025), caught our attention right away. Why this book is worth your time As one of the - [A new variant of the Flodrix botnet has entered the scene…](https://fastnetmon.com/2025/06/26/a-new-variant-of-the-flodrix-botnet-has-entered-the-scene/) - A new variant of the Flodrix botnet has entered the scene, and it’s taking aim at poorly secured open-source tools with an unusual level of stealth and versatility. The newest Flodrix variant builds on the same old principles: find vulnerable software, exploit it for remote access, and quietly conscript the machine into a global network - [FastNetMon Interviewed by Safety Detectives: Rethinking DDoS Protection for a Faster, Safer Internet](https://fastnetmon.com/2025/07/02/fastnetmon-interviewed-by-safety-detectives-rethinking-ddos-protection-for-a-faster-safer-internet/) - FastNetMon was recently featured in an interview with Safety Detectives, a cybersecurity blog. The conversation covers the rising threat of Distributed Denial of Service (DDoS) attacks and how FastNetMon is addressing these challenges with innovative solutions. In today’s environment, DDoS attacks are becoming more frequent, larger in scale—often reaching terabits per second—and increasingly accessible through - [How to set a threshold for RTBH/BGP Blackhole: A practical guide to threshold-based DDoS defence](https://fastnetmon.com/2025/07/02/how-to-set-a-threshold-for-rtbh-bgp-blackhole-a-practical-guide-to-threshold-based-ddos-defence/) - Threshold-based DDoS defence is one of the most effective ways to automate blackhole routing for high-volume attacks, without the need for constant manual oversight. In this post, we’ll break down how threshold-based mitigation works, how to configure it in FastNetMon, and how it differs from rate limiting. Whether you're an ISP, hosting provider, or enterprise - [Filtering L3/L4 DDoS attacks with BGP Flow Spec and RTBH: A practical guide for engineers](https://fastnetmon.com/2025/07/08/filtering-l3-l4-ddos-attacks-with-bgp-flow-spec-and-rtbh-a-practical-guide-for-engineers/) - Distributed Denial of Service (DDoS) attacks at layers 3 and 4 are blunt, fast, and disruptive. If you’re running networks at any scale, chances are you’ve already seen your fair share of UDP floods, TCP SYN storms, and other packet-level abuse. Detection is step one. But what comes next, or how (how fast) you mitigate - [FastNetMon Interviewed by Website Planet: The Real Reason Websites Crash During DDoS Attacks](https://fastnetmon.com/2025/07/15/fastnetmon-interviewed-by-website-planet-the-real-reason-websites-crash-during-ddos-attacks/) - FastNetMon was recently featured in an interview with Website Planet, an expert blog focused on hosting, infrastructure, and web technologies. In the conversation, our Founder Pavel Odintsov shares insights into the growing scale and speed of DDoS attacks, the limitations of traditional protection methods, and how automation is changing the landscape for network defense. When - [Meet the botnets breaking the Internet: Part 2](https://fastnetmon.com/2025/07/03/meet-the-botnets-breaking-the-internet-part-1/) - For over two decades, botnets have been at the heart of some of the most disruptive activity online - from large-scale DDoS campaigns to credential theft and malware distribution. While the end goals haven’t changed much, the technical machinery behind them has evolved in significant ways. In the first part of this learning series, we - [Meet the Botnets Breaking the Internet: Part 3](https://fastnetmon.com/2025/07/15/meet-the-botnets-breaking-the-internet-part-3/) - The Modern Era: from modular loaders to multi-vector flood engines As defenders have become more aware of the classic tactics used by earlier botnets like BASHLITE, Mirai, and GameOver Zeus, threat actors have shifted focus to more resilient and evasive designs. In this second part of our botnet learning series, we explore how newer botnets - [Europol Disrupts Notorious DDoS Group NoName057(16)](https://fastnetmon.com/2025/07/16/europol-disrupts-notorious-ddos-group-noname05716/) - In a major win for cybersecurity defenders across Europe, Europol and Eurojust have successfully coordinated an international operation—Operation Eastwood—to disrupt the infrastructure and operations of the pro-Russian hacktivist group NoName057(16). This group has been responsible for hundreds of DDoS attacks targeting critical infrastructure and institutions since the beginning of the war in Ukraine. The Background: - [Making Sense of Network Traffic Visibility in Modern Infrastructure](https://fastnetmon.com/2025/07/31/making-sense-of-network-traffic-visibility-in-modern-infrastructure/) - In 2025, network traffic visibility isn’t just a technical requirement—it’s a strategic necessity. As networks grow in size and complexity, visibility has become critical to performance, security, and resilience. Without it, network engineers and security teams are flying blind in an environment that’s increasingly fast, fragmented, and encrypted. In this blog post, we’ll break down: - [Understanding Volumetric & Amplification DDoS Attacks](https://fastnetmon.com/2025/07/30/understanding-volumetric-amplification-ddos-attacks/) - How bandwidth-focused DDoS campaigns work—and why they’re still effective at scale Volumetric DDoS attacks remain one of the most common and disruptive forms of denial-of-service activity across the internet. Despite evolving tactics, the core objective is the same: exhaust the network capacity of a target by overwhelming it with traffic. This article explores how volumetric - [Understanding Transport and State-Exhaustion DDoS Attacks](https://fastnetmon.com/2025/08/12/understanding-transport-and-state-exhaustion-ddos-attacks/) - How connection state exhaustion attacks threaten your firewalls and proxies Transport and state-exhaustion DDoS attacks represent a growing and sophisticated category of denial-of-service threats targeting the resource limitations of network infrastructure. Instead of flooding bandwidth, these attacks exploit the costly state and CPU resources needed to manage connections and sessions in firewalls, proxies, load balancers, - [Classification of DDoS attacks: every modern DDoS attack vector explained](https://fastnetmon.com/2025/07/25/classification-of-ddos-attacks-every-modern-ddos-attack-vector-explained/) - A practical breakdown of DDoS attack vectors, built for network operators When your NOC wallboard lights up red, you don’t have 5 seconds. And if you’re relying on manual triage at that point, it is a tough job. Ideally, you’ve preloaded mitigation rules for the most common vectors. But when something new slips through, classification - [How to defend against a DDoS attack?](https://fastnetmon.com/2025/08/19/how-to-defend-against-a-ddos-attack/) - DDoS defence explained: how to detect and mitigate a DDoS attack? DDoS attacks are easier than ever to launch, harder to trace, and can cause real damage if you're not prepared. The end result is typically the same: your users can’t reach you or your systems are unavailable. This article is a starting point. We’ll - [Why do DDoS attacks happen? Top motivations behind DDoS cybercrime](https://fastnetmon.com/2025/08/27/why-do-ddos-attacks-happen-top-motivations-behind-ddos-cybercrime/) - We often talk about how DDoS attacks happen — via botnets, traffic floods, vectors — but rarely do we ask the more human question: why? The truth is, behind every DDoS attack is a motive. Sometimes it's financial. Sometimes it’s political. And sometimes it’s just personal. Here’s a closer look at the most common reasons - [Understanding Application-Layer & Low-and-Slow DDoS Attacks](https://fastnetmon.com/2025/09/04/understanding-application-layer-low-and-slow-ddos-attacks/) - Application-layer and “low-and-slow” DDoS attacks explained by DDoS defence professionals Application-layer (L7) and “low-and-slow” DDoS attacks are among the most insidious forms of denial-of-service threats. Rather than saturating bandwidth, they burn server CPU, memory, and database resources by forcing expensive operations—TLS handshakes, header decompression, routing, authentication, or cache misses—while looking deceptively like normal client traffic. - [DDoS FAQ for beginners](https://fastnetmon.com/2025/09/03/ddos-faq-for-beginners/) - Introduction: Questions you always wanted to ask about DDoS DDoS is one of those topics that everyone in the industry has heard about, but few feel confident they fully understand. Maybe you’ve sat in a meeting where terms like “RTBH,” “FlowSpec,” or “amplification” were thrown around and thought, I should probably know all this… but - [Common myths and misconceptions about DDoS attacks](https://fastnetmon.com/2025/09/10/common-myths-and-misconceptions-about-ddos-attacks/) - Despite being a decades-old threat, DDoS attacks still come with a cloud of misunderstanding. Every time a myth goes unchecked, organisations risk underestimating threats or misallocating resources. This post debunks the most stubborn DDoS myths and explains what actually matters in DDoS defence. Myth 1: DDoS attacks are only a problem for big companies It’s - [Cambridge study examines global law enforcement efforts against DDoS-for-hire services](https://fastnetmon.com/2025/09/11/cambridge-study-examines-global-law-enforcement-efforts-against-ddos-for-hire-services/) - Researchers from the University of Cambridge’s Security Group recently published important findings on the effectiveness of global law enforcement actions against DDoS-for-hire services, also known as booters. Their study, Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services, was presented at the USENIX Security Symposium 2025 and awarded an Honourable Mention. The - [How to tell if you’re under a DDoS attack](https://fastnetmon.com/2025/09/16/how-to-tell-if-youre-under-a-ddos-attack/) - DDoS attacks remain one of the most disruptive threats facing ISPs, backbone networks, hosting providers, and enterprises. Detecting the attacks quickly is essential to keeping networks stable and services running. This guide looks at how network engineers can recognise the signs of an attack and how FastNetMon provides the visibility needed to detect them in - [Understanding Layer 3 and Layer 4 DDoS attacks](https://fastnetmon.com/2025/09/23/understanding-layer-3-and-layer-4-ddos-attacks/) - What L3 and L4 DDoS attacks are, how they work, and what defenders need to know DDoS attacks at Layers 3 and 4 (the Network and Transport layers) are some of the most common and disruptive seen on the public internet. While often lumped together, they behave differently, and defending against them requires understanding how - [ShadowV2: A new botnet that turns misconfigured Docker APIs into a pay-to-use cloud DDoS platform](https://fastnetmon.com/2025/10/01/shadowv2-a-new-botnet-that-turns-misconfigured-docker-apis-into-a-pay-to-use-cloud-ddos-platform/) - ShadowV2 has been identified as a new DDoS-as-a-service platform that stands out for its use of cloud infrastructure. Instead of relying on home routers or compromised IoT devices, it exploits misconfigured Docker daemons running in public cloud environments. Many of these daemons were deployed on Amazon Web Services, but the same exposure exists across providers. - [The IPv6 Divide: How Slow Adoption Creates Digital Vulnerabilities and Economic Inequality](https://fastnetmon.com/2025/10/08/the-ipv6-divide-how-slow-adoption-creates-digital-vulnerabilities-and-economic-inequality/) - Guest post by Vincentas Grinius, Co-Founder at IPXO The shift to IPv6 has escalated into a matter of national security, as nations lagging in adoption are increasingly exposed to cyber threats and diminished control over their digital infrastructure due to the limited availability of IPv4. With IPv6-only environments becoming more common, reliance on IPv4 may - [Outbound DDoS: The attack you might be unknowingly hosting](https://fastnetmon.com/2025/09/24/outbound-ddos-the-attack-you-might-be-unknowingly-hosting/) - When we talk about DDoS attacks, the focus is almost always on protecting services from inbound floods. But there’s another side to the story that often goes unnoticed: outbound DDoS attacks. These are attacks where malicious traffic originates from inside your network and targets external systems. While the victim suffering the most damage is outside - [Help — I’ve Been Sent a Ransom Note from a DDoS Group: What Should I Do?](https://fastnetmon.com/2025/10/16/help-ive-been-sent-a-ransom-note-from-a-ddos-group-what-should-i-do/) - Every now and then, a network operator’s inbox lights up with a DDoS ransom note — bold claims, big threats, and a bitcoin address waiting for payment. We’ve seen plenty of them ourselves. Some come from actors with real bandwidth behind them; others are clearly written by people who just discovered a booter service. A - [FastNetMon Advanced 2.0.370](https://fastnetmon.com/2024/12/16/fastnetmon-advanced-2-0-370/) - In our latest update, we've added several safety checks in our IPFIX and Netflow v9 code to prevent reading outside of our memory region and potential division by zero. We've also blocked zero length data and options templates for Netflow v9 to reduce chances of DoS attacks. We've fixed a DoS vulnerability in our sFlow - [Event recap – RIPE 91](https://fastnetmon.com/2025/10/24/event-recap-ripe-91/) - Packets, People, and Post-Quantum Coffee – Notes from a RIPE Newbie After ten years, the RIPE community returned to Bucharest — a city that’s clearly spent the last decade delightfully upgrading its vibrant tech scene. With 485 participants onsite and another 180 online, RIPE 91 packed a full week of routing revelations, hallway debates, and - [Event recap - RITE 2025](https://fastnetmon.com/2025/10/28/event-recap-rite-2025/) - FastNetMon joined the Romanian Internet Technologies Event (RITE) this week in Bucharest — a gathering focused on how decentralisation, enhanced security and shifting traffic dynamics are reshaping the Internet. Organised by ANISP together with the Internet Society, RITE brings together ISPs, content providers, and infrastructure operators to debate some of the most critical topics driving - [Indian ISP Protects Against Large Volumetric DDoS Attacks with FastNetMon](https://fastnetmon.com/2023/02/01/indian-isp-protects-against-ddos-with-fastnetmon/) - Learn how an Indian ISP used FastNetMon to protect against large volumetric DDoS attacks, and prevent any future cybersecurity attacks. - [Russias food safety under DDoS attack](https://fastnetmon.com/2025/10/31/russias-food-safety-under-ddos-attack/) - Russia’s national food-safety regulator, Rosselkhoznadzor, faced a DDoS incident last week that took down its digital certification systems and disrupted product shipments across the country. What happened? On 22 October 2025, a DDoS attack flooded the public-facing services of VetIS and Saturn. The Mercury interface became unreachable, blocking certificate generation and validation. Suppliers could not - [FastNetMon Advanced 2.0.373](https://fastnetmon.com/2025/10/16/fastnetmon-advanced-2-0-373/) - Release date: 16 October, 2025Version: 2.0.373 FastNetMon Advanced 2.0.373 has been released with security hardening, telemetry enhancements, and new integrations. We’ve added device allow-lists for Netflow v5/v9 and IPFIX collectors and introduced a Flow Spec–based allow list to tighten policy control. AF_PACKET mode now populates input/output interfaces using kernel interface indices, and usage telemetry can - [DDoS botnet Aisuru drives record outbound floods from infected ISP-hosted IoT](https://fastnetmon.com/2025/10/15/ddos-botnet-aisuru-drives-record-outbound-floods-from-infected-isp-hosted-iot/) - Aisuru, a massive IoT botnet, recently pushed outbound traffic close to 30 Tbps from infected devices inside major U.S. ISPs — one of the largest DDoS events ever recorded. Outbound DDoS attacks, where malicious traffic leaves your network rather than entering it, are increasingly straining upstream capacity and exposing operators to significant operational and reputational - [Event recap - BalticNOG 2025](https://fastnetmon.com/2025/09/30/event-recap-balticnog-2025/) - Last week we joined the Baltic network operator community in Vilnius for BalticNOG 2025. The two-day event brought together engineers, researchers, and operators from across the region to share knowledge and experiences on building and securing the internet. The programme was packed with technical depth and practical insights. From Geoff Huston’s thought-provoking “Networking in the - [Behind the screen. Non-technical story of FastNetMon: From GitHub to a Brand with the Global Name.](https://fastnetmon.com/2025/10/13/behind-the-screen-non-technical-story-of-fastnetmon-from-github-to-a-brand-with-the-global-name/) - Today, FastNetMon protects networks of all sizes from DDoS attacks and serves customers in dozens of countries worldwide. But how did it all begin? This is the story of the company's early days—not from a technical perspective, but from the journey of building the brand, operations, and community that shaped what FastNetMon is today. I - [Linux 6.18 improves server performance under DDoS attacks](https://fastnetmon.com/2025/10/09/linux-6-18-improves-server-performance-under-ddos-attacks/) - Recent kernel updates led by Google engineer Eric Dumazet, and first reported by Michael Larabel (Phoronix), show that Linux 6.18 delivers significant improvements in how servers handle high-rate DDoS traffic. The work focuses on optimising the UDP receive path under stress—scenarios where multiple CPU cores handle massive packet floods targeting one or more sockets. Dumazet’s - [Another record-breaking DDoS? Aisuru botnet suspected behind 29.69 Tbps gaming outages](https://fastnetmon.com/2025/10/08/another-record-breaking-ddos-aisuru-botnet-suspected-behind-29-69-tbps-gaming-outages/) - Incident summary: Date: October 6, 2025 Targets: Steam, Riot Games, PlayStation Network, AWS, and others Peak bandwidth (unconfirmed): 29.69 Tbps Suspected source: Aisuru botnet Attack vector (reported): TCP-based carpet bomb traffic Status: Under investigation — no official confirmation What we know so far Several major gaming platforms — including Steam and Riot Games — experienced - [Event recap - RONOG 10](https://fastnetmon.com/2025/09/29/event-recap-ronog-10/) - On 18 September 2025, the Romanian Network Operators Group hosted RONOG 10 in Bucharest. The one-day conference, organised by InterLAN, brought together network operators, engineers, regulators, and technology providers to share technical knowledge and exchange ideas. Held at the Radisson Blu Hotel, the event combined presentations, networking breaks, and plenty of hallway conversations — creating - [A new world record DDoS attack: 22.2 Tbps](https://fastnetmon.com/2025/09/23/a-new-world-record-ddos-attack-22-2-tbps/) - The cybersecurity landscape witnessed a new benchmark in DDoS attacks as Cloudflare reported mitigating a hyper-volumetric assault that peaked at 22.2 terabits per second (Tbps) and 10.6 billion packets per second (Bpps). This attack more than doubled the previous UDP flood record of 11.5 Tbps only a few weeks ago, underlining the accelerating capabilities of - [Press Release: FastNetMon detects a record-scale DDoS attack](https://fastnetmon.com/2025/09/09/press-release-fastnetmon-detects-a-record-scale-ddos-attack/) - London, UK – Tuesday, September 9th 2025 – FastNetMon today announced that it detected a record-scale distributed denial-of-service (DDoS) attack targeting the website of a leading DDoS scrubbing vendor in Western Europe. The attack reached 1.5 billion packets per second (1.5 Gpps) — one of the largest packet-rate floods publicly disclosed. The malicious traffic was - [1.5 billion packets per second DDoS attack detected with FastNetMon](https://fastnetmon.com/2025/09/09/1-5-billion-packets-per-second-ddos-attack-detected-with-fastnetmon/) - Breaking DDoS news from FastNetMon At FastNetMon, we recently worked with a customer — a DDoS scrubbing provider — who faced one of the largest DDoS attacks ever publicly recorded. The target: the provider’s website The scale: 1.5 billion packets per second in a sustained UDP flood The source: compromised CPE, including IoT devices and - [Cloudflare mitigates record-breaking 11.5 Tbps DDoS attack](https://fastnetmon.com/2025/09/03/cloudflare-mitigates-record-breaking-11-5-tbps-ddos-attack/) - Cloudflare has disclosed that it successfully mitigated the largest DDoS attack recorded to date — a hyper-volumetric UDP flood peaking at 11.5 terabits per second (Tbps). The attack lasted only 35 seconds, but its scale tells something about the growing headaches network operators face in defending against cloud-enabled botnets capable of overwhelming infrastructure in seconds. - [Network Engineering Community News: August 2025](https://fastnetmon.com/2025/08/28/network-engineering-community-news-august-2025/) - In this month's issue: register for our webinar with Inter.link, see where to meet us at RONOG10, learn about scrubbing centre automation, read our APNIC feature on 10 years in open-source security, and catch up with fresh DDoS and network security news. If you want to get even cooler version of this newsletter straight to - [Making Sense of Network Telemetry: FastNetMon Featured on LACNIC](https://fastnetmon.com/2025/08/26/making-sense-of-network-telemetry-fastnetmon-featured-on-lacnic/) - FastNetMon was recently featured on LACNIC, where our Founder, Pavel Odintsov provides a practical guide to network telemetry for operators. The article explains the differences between flow-based protocols like NetFlow and IPFIX, and packet-based approaches such as sFlow and PSAMP, highlighting their trade-offs, use cases, and real-world performance. Drawing on a decade of experience testing - [Arch Linux Confirms Week-Long DDoS Attack on Core Infrastructure](https://fastnetmon.com/2025/08/26/arch-linux-confirms-week-long-ddos-attack-on-core-infrastructure/) - The Arch Linux project has confirmed that its core infrastructure has been under sustained DDoS attack for more than a week. The campaign, which began on August 16, 2025, has disrupted user access to the project’s main website, the Arch User Repository (AUR), and the community forums. Service interruptions remain ongoing, with many users reporting - [Reflecting on 10 Years of Open Source DDoS Defense: FastNetMon Featured on APNIC](https://fastnetmon.com/2025/08/20/reflecting-on-10-years-of-open-source-ddos-defense-fastnetmon-featured-on-apnic/) - FastNetMon was recently featured on the APNIC blog, where FastNetMon Founder Pavel Odintsov reflects on a decade of the DDoS landscape while building the open source DDoS detection platform. What started as a small proof-of-concept tool in a home lab has grown into a globally deployed system trusted by ISPs, hosting providers, and enterprises. The - [U.S. Authorities Take Down “RapperBot” DDoS-for-Hire Service After 370,000 Attacks](https://fastnetmon.com/2025/08/19/u-s-authorities-take-down-rapperbot-ddos-for-hire-service-after-370000-attacks/) - The U.S. Department of Justice has charged a 22-year-old Oregon man for operating RapperBot, a large-scale botnet-for-hire that powered more than 370,000 DDoS attacks between April and August 2025. Built on tens of thousands of compromised IoT devices, the botnet was linked to some of the most disruptive attacks of the past year, including the - [MadeYouReset: The New HTTP/2 DDoS Threat and Mitigation Strategies](https://fastnetmon.com/2025/08/13/madeyoureset-the-new-http-2-ddos-threat-and-mitigation-strategies/) - MadeYouReset is a new HTTP/2 DDoS vector related to 2023’s Rapid Reset. By provoking the server to reset streams with malformed frames, an attacker keeps backend request processing alive while freeing the stream from HTTP/2 accounting. One TCP connection can drive an effectively unbounded number of in-flight requests through a proxy to origins. Patching affected - [Win-DoS: New Windows Zero-Click Vulnerabilities Enable Domain Controller-Powered DDoS Botnets](https://fastnetmon.com/2025/08/11/win-dos-new-windows-zero-click-vulnerabilities-enable-domain-controller-powered-ddos-botnets/) - SafeBreach Labs researchers Or Yair and Shahak Morag disclosed a new class of Windows denial-of-service (DoS) vulnerabilities that can be exploited to crash critical infrastructure or conscript publicly accessible Windows Domain Controllers (DCs) into high-bandwidth DDoS attacks. The researchers have dubbed the discovery the “Win-DoS Epidemic” and have released proof-of-concept tooling demonstrating exploitation across multiple - [What Is a DDoS Attack? History, Motives, and Methods Explained](https://fastnetmon.com/2025/08/05/what-is-a-ddos-attack-history-motives-and-methods-explained/) - If you’ve managed a network for more than a week, chances are you’ve seen it, or at least worried about it: the DDoS attack. You know the symptoms. Traffic spikes. Routing instability. Customers raising tickets before monitoring even kicks in. But how did we get here? What exactly qualifies as a DDoS attack today, and - [DDoS or Drama? Qubic’s Monero Takeover Attempt Sparks Controversy](https://fastnetmon.com/2025/08/05/ddos-or-drama-qubics-monero-takeover-attempt-sparks-controversy/) - August 3, 2025, a crypto mining pool called Qubic claimed it was hit by a Distributed Denial-of-Service (DDoS) attack after launching an aggressive bid to gain control of the Monero blockchain. While no impact was observed on the Monero network itself, the events raised new questions about the intersection of cyber attacks, economic rivalry, and - [SVF Botnet Campaign Targets Linux SSH Servers Using Discord-Based C2](https://fastnetmon.com/2025/07/29/svf-botnet-campaign-targets-linux-ssh-servers-using-discord-based-c2/) - AhnLab Security Intelligence Center (ASEC) has recently uncovered a wave of malicious activity involving the SVF Botnet, a lightweight yet capable Python-based malware used to launch DDoS attacks via compromised Linux SSH servers. The campaign highlights the continuing abuse of weak or default SSH credentials on internet-facing infrastructure. Infection Tactics: Fast and Scripted ASEC researchers - [Network Engineering Community News: July 2025](https://fastnetmon.com/2025/07/29/network-engineering-community-news-july-2025/) - ⚡️ Network Engineering Community News Summer greetings from FastNetMon! While temperatures rise, so do DDoS attack volumes—and we’re here to help you stay cool under pressure. This month, we’re sharing two practical guides for tackling attacks, a press interview on SafetyDetectives, and major botnet updates, a peek at some of the biggest attacks we’ve seen - [Hungarian Police arrest alleged DDoS attacker targeting IPI and independent media](https://fastnetmon.com/2025/07/23/hungarian-police-arrest-alleged-ddos-attacker-targeting-ipi-and-independent-media/) - On July 21, 2025, the Hungarian National Investigation Bureau’s Cybercrime Investigation Unit announced the arrest of a 23-year-old suspect behind a series of coordinated DDoS attacks targeting the International Press Institute (IPI) and over 40 independent media websites in Hungary between 2023 and 2024. The suspect, operating under the alias “Hano”, allegedly used “DDoS-for-hire” services - [New Junos OS Vulnerability Can Cause BGP Session Resets](https://fastnetmon.com/2025/07/14/new-junos-os-vulnerability-can-cause-bgp-session-resets/) - Juniper Networks has disclosed a new vulnerability (CVE-2025-52953) affecting Junos OS and Junos OS Evolved, which allows an unauthenticated adjacent attacker to send a valid BGP UPDATE packet that resets live BGP sessions, leading to a sustained denial of service (DoS) condition.The issue resides in the routing protocol daemon (rpd) and impacts both iBGP and - [New Botnet “RondoDox” Targets Unpatched DVRs and Routers for Stealthy DDoS Campaigns](https://fastnetmon.com/2025/07/08/new-botnet-rondodox-targets-unpatched-dvrs-and-routers-for-stealthy-ddos-campaigns/) - In a continuing wave of new malware activity, researchers have uncovered a botnet dubbed RondoDox, which is actively exploiting known vulnerabilities in TBK digital video recorders (DVRs) and Four-Faith routers to take over Linux-based devices. These devices—often unpatched and deployed in retail, warehouse, or small office environments—are easy targets for long-term compromise. RondoDox follows a - [New Botnet “Hpingbot” Emerges with Pastebin-Based Payload Delivery and Hping3 DDoS Engine](https://fastnetmon.com/2025/07/07/new-botnet-hpingbot-emerges-with-pastebin-based-payload-delivery-and-hping3-ddos-engine/) - A newly discovered botnet family dubbed Hpingbot is gaining attention in the cybersecurity community for its novel approach to malware delivery and DDoS execution. Detected by NSFOCUS’s Fuying Lab in June 2025, Hpingbot is a cross-platform Go-based botnet actively targeting both Windows and Linux/IoT environments—and it’s evolving fast. Payload Delivery via Pastebin Unlike most botnets - [Path of Exile tightens DDoS protection following service disruptions](https://fastnetmon.com/2025/07/02/path-of-exile-tightens-ddos-protection-following-service-disruptions/) - Grinding Gear Games (GGG), the developer of the action RPG Path of Exile, has implemented new security updates to strengthen its protection against Distributed Denial‑of‑Service (DDoS) attacks. The changes follow a period of significant server instability after the release of the game’s latest expansion, Secrets of the Atlas. In a post published on June 26, - [Internet Under Fire: Analysis of the record-breaking 7.3 Tbps DDoS attack](https://fastnetmon.com/2025/06/23/internet-under-fire-analysis-of-the-record-breaking-7-3-tbps-ddos-attack/) - The Internet Just Survived the Largest DDoS Attack Ever—Here’s What You Need to Know A new milestone in Distributed Denial of Service (DDoS) attacks has been reached: 7.3 terabits per second (Tbps) of malicious traffic launched in a single, ultra-short burst lasting just 45 seconds. The attack delivered 37.4 terabytes of data—equivalent to streaming an - [Event Recap - Infosecurity Europe 2025](https://fastnetmon.com/2025/06/05/event-recap-infosecurity-europe-2025/) - Infosec Europe: Key Takeaways from London’s Leading Cybersecurity Event FastNetMon’s CEO Kate Fateeva and Maria Pietilanaho visited Infosecurity Europe 2025—this year marking the event’s 30th anniversary at ExCeL London. As always, it was a great mix of catching up on the latest cybersecurity trends, meeting old friends and new faces, and yes… grabbing some seriously - [DDoS attack targets BYOND game engine in push to open-source it](https://fastnetmon.com/2025/06/05/ddos-attack-targets-byond-game-engine-in-push-to-open-source-it/) - As of June 2025, the BYOND game engine continues to face a persistent and disruptive Distributed Denial-of-Service (DDoS) attack that began on May 10. This sustained assault has severely impacted BYOND's central services, including its website, multiplayer lobby, and update servers, leading to widespread disruption across its community. What’s Happening? The attack involves large volumes - [FastNetMon Advanced 2.0.372](https://fastnetmon.com/2025/06/03/fastnetmon-advanced-2-0-372/) - FastNetMon Advanced 2.0.372 has been released with a critical fix and several improvements. This release addresses a stability issue that could cause FastNetMon to crash when processing malformed ASN feed data. We've also enhanced IPv6 address formatting, improved ASN allocation performance, and made refinements across Netflow, IPFIX, and sFlow logic. Additionally, this release introduces support - [6.3 Tbps in 45 Seconds: what the latest assault on KrebsOnSecurity tells us about hyper-volumetric DDoS](https://fastnetmon.com/2025/05/27/6-3-tbps-in-45-seconds-what-the-latest-assault-on-krebsonsecurity-tells-us-about-hyper-volumetric-ddos/) - On 12 May 2025, digital-forensics journalist Brian Krebs watched his site absorb a flood of traffic that briefly touched 6.3 terabits per second. The surge lasted just 45 seconds, delivering about 585 million UDP packets per second to random ports - enough throughput to overwhelm all but the biggest carrier links. Size and technique point - [Event Recap – TRNOG Izmir](https://fastnetmon.com/2025/05/27/event-recap-trnog-izmir/) - FastNetMon was pleased to attend TRNOG event in Izmir on May 24, 2025. This was the second official event organised by the Turkish Network Operators Group (TRNOG), following the successful launch in Ankara earlier this year. TRNOG is a non-profit community of network engineers committed to advancing internet infrastructure and collaboration across Turkey. The Izmir - [HTTPBot: A New Breed of Windows-Based DDoS Botnet](https://fastnetmon.com/2025/05/20/httpbot-a-new-breed-of-windows-based-ddos-botnet/) - New Windows botnet HTTPBot zeroes in on game and tech portals For years, most DDoS botnets have operated from compromised routers, IoT devices, or Linux servers. HTTPBot breaks that pattern. Written in Go and compiled specifically for Windows, this new botnet has emerged as a stealthy and precise threat. Since April 2025, it has targeted - [Event Recap: RIPE 90](https://fastnetmon.com/2025/05/19/event-recap-ripe-90/) - From 12–16 May, the RIPE community gathered in Lisbon for RIPE 90, bringing together over 820 attendees from 55 countries. With 648 joining in person and 172 online, the event once again proved to be a vital space for collaboration across network operations, policy, and research. A Strong Start and Key Themes The event kicked - [India-Pakistan conflict evokes a wave of cross-boarder DDoS attacks](https://fastnetmon.com/2025/05/15/india-pakistan-conflict-evokes-a-wave-of-cross-boarder-ddos-attacks/) - DDoS escalates alongside India-Pakistan hostilities When military tensions flared between India and Pakistan in early May, a parallel cyber campaign unfolded at speed. Threat-hunting data show a clear pattern: each round of air- or missile-strikes was mirrored by larger, longer Distributed Denial-of-Service (DDoS) assaults on networks. What happened? 7 May – India carried out ‘Operation - [Event Recap: DataCenter Forum Romania](https://fastnetmon.com/2025/05/12/event-recap-datacenter-forum-romania/) - FastNetMon at DataCenter Forum Romania 2025: AI, Sustainability, and Growth in Southeastern Europe Last week, FastNetMon had the pleasure of attending the DataCenter Forum Romania 2025, held at the Face Convention Center in Bucharest. The event brought together over 600 data centre professionals, technology leaders, and policymakers to explore the future of digital infrastructure in - [50+ Dutch public services flooded by NoName057(16) in one week as a ‘punishment’](https://fastnetmon.com/2025/05/08/50-dutch-public-services-flooded-by-noname05716-in-one-week-as-a-punishment/) - NoName057(16) ‘punishes’ the Dutch government by sending the largest single DDoS burst at their public services sector NoName057(16), the infamous hacktivist crew that has spent two years peppering Europe with nuisance floods, has turned its sights back on the Netherlands. Starting on Monday, the group launched three waves of DDoS traffic, knocking municipal portals in - [DDoS-for-Hire Network shut down in Poland](https://fastnetmon.com/2025/05/07/ddos-for-hire-network-shut-down-in-poland/) - A successful international operation takes down several IP booter services In a major international crackdown on cybercrime, Polish authorities have arrested four individuals suspected of running a network of platforms that facilitated thousands of DDoS attacks worldwide. These platforms, known as stresser/booter services, allowed users to pay as little as 10 euros to flood websites - [Record-size DDoS batters betting site during a major NHL event](https://fastnetmon.com/2025/04/30/record-size-ddos-batters-betting-site-during-a-major-nhl-event/) - On 3 April 2025, an online bookmaker was battered by the largest public DDoS disclosed so far in 2025. As reported by Techradar, the traffic began spiking at 11:15 UTC, jumped from 67 Gbps to 217 Gbps in eight minutes, and peaked at 965 Gbps by 11:36. The flood faded after 90 minutes, but not - [Three DDoS waves in one evening: Adyen’s payments put to the test](https://fastnetmon.com/2025/04/24/three-ddos-waves-in-one-evening-adyens-payments-put-to-the-test/) - Dutch payment processor experiences multiple DDoS attacks in one day An evening of false starts Just after 7 p.m. on 8 April, diners in Dutch cafés and shoppers across Europe noticed card readers freezing. The culprit wasn’t a bad internet connection, but a flood of DDoS traffic aimed at Adyen, the Amsterdam-based payment processor that - [Russian railways RZD app crashes in major cyber disruption](https://fastnetmon.com/2025/04/05/russian-railways-rzd-app-crashes-in-major-cyber-disruption/) - On 1 April, Russia’s state-owned railway RZD was hit by a DDoS attack that knocked its website and mobile app offline. No tickets, no timetables, just timeout errors The disruption began Tuesday evening and affected users nationwide, many of whom were unable to check train schedules or purchase tickets online. Although station offices remained open, - [OnlyFangs disbands after WoW intense DDoS attacks — what it says about gaming security in 2025](https://fastnetmon.com/2025/04/03/onlyfangs-disbands-after-wow-intense-ddos-attacks-what-it-says-about-gaming-security-in-2025/) - One of World of Warcraft Hardcore’s most watched guilds, OnlyFangs, has officially disbanded — not because of in-game failure, but due to repeated DDoS attacks. The group, made up of streamers and creators like Sodapoppin, Tyler1, and Zizaran, decided to call it quits after players repeatedly lost characters and raid progress because of connection issues - [Event Wrap - CloudFest 2025](https://fastnetmon.com/2025/03/28/event-wrap-cloudfest-2025/) - CloudFest 2025, hosted from March 17-20 at Europa Park in Rust, Germany, brought together over 11,000 cloud industry professionals from across the globe. This year's event was the largest to date, with an expanded exhibition area to accommodate the growing number of companies eager to showcase their innovations. The atmosphere was buzzing with a sense - [CO.ZA domains disrupted by a DDoS attack](https://fastnetmon.com/2025/03/24/co-za-domains-disrupted-by-a-ddos-attack/) - A major DDoS attack hit South Africa’s CO.ZA domain services, leaving businesses and users unable to access websites linked to the country’s most widely used domain. The ZA Registry Consortium confirmed that the issue was triggered by an unprecedented system load that impacted secondary domains under their management. Some industry stakeholders questioned whether this was - [Event Recap: CLNOG 2025](https://fastnetmon.com/2025/03/21/event-recap-clnog-2025/) - On 21 March 2025, we had the pleasure of attending CLNOG 2025, held in Santiago, Chile. This event brought together network operators and industry experts from across the region, highlighting Chile's role as a key hub of network connectivity in Latin America. It was a fantastic opportunity to be part of this vibrant community. The - [Event Recap: Red Button DDoS Day 2025](https://fastnetmon.com/2025/03/24/event-recap-red-button-ddos-day-2025/) - Last Thursday, March 20th, we had the privilege of attending Red Button’s DDoS Day 2025, an exclusive event hosted at the iconic House of Lords in the United Kingdom. As DDoS attacks grow in number and complexity, this gathering brought together cybersecurity professionals to discuss the latest developments and explore strategies for maximising protection. This - [Azerbaijan state and media infrastructure faces massive DDoS attacks](https://fastnetmon.com/2025/03/10/azerbaijan-state-and-media-infrastructure-faces-massive-ddos-attacks/) - Azerbaijan has faced a series of massive DDoS attacks targeting state information resources. The country’s digital infrastructure is challenged as the attacks have been disrupting the services and overwhelming systems with a flood of traffic. The Special Communication and Information Security State Service of the Republic of Azerbaijan has been actively working to neutralise these - [A new powerful botnet Eleven11bot discovered](https://fastnetmon.com/2025/03/04/a-new-powerful-botnet-eleven11bot-discovered/) - A newly identified botnet, Eleven11bot, has emerged as a significant cyber threat, compromising over 80,000 internet-connected devices globally. Nokia Deepfield’s Emergency Response Team (ERT) has reported that this botnet primarily targets security cameras and network video recorders (NVRs), utilising them to launch distributed denial of service (DDoS) attacks. These attacks have notably impacted telecom providers - [Prop trading platform E8 Markets hit by DDoS attack](https://fastnetmon.com/2025/02/26/prop-trading-platform-e8-markets-hit-by-ddos-attack/) - What happened? E8 Markets, a well-known name in prop trading, faced a significant DDoS attack over the weekend, leaving traders locked out of their accounts for two days. Even as markets reopened on Monday, some users continued to report access issues, adding to their frustration. Although E8 Markets managed to restore its systems, the impact - [DDoS Attacks disrupt Italian infrastructure](https://fastnetmon.com/2025/02/20/ddos-attacks-disrupt-italian-infrastructure/) - Italy recently faced a wave of DDoS attacks that targeted critical sectors, including government institutions, transport networks, and financial services. These attacks, attributed to the Russian hacker collective NoName057(16), caused temporary disruptions but were swiftly mitigated through early detection and response. The offensive began with attacks on local and air transport services, as well as - [The impact of the speculated PlayStation DDoS attack](https://fastnetmon.com/2025/02/13/the-impact-of-the-speculated-playstation-ddos-attack/) - The recent PlayStation Network outage has left many gamers frustrated and seeking answers. The disruption, which began late on February 7 and lasted nearly 24 hours, rendered online gaming services inaccessible for popular titles such as Fortnite, Call of Duty, and Grand Theft Auto. Offline single-player games also faced issues with license verification, adding to - [DeepSeek DDoS Attacks Explained - what really happened?](https://fastnetmon.com/2025/02/05/deepseek-ddos-attacks-explained-what-really-happened/) - DeepSeek, a rising name in artificial intelligence, has faced large-scale DDoS attacks since its reasoning model was released on January 20th. The attack came just as the company was experiencing a surge in popularity, overtaking OpenAI’s ChatGPT as the most downloaded free app on Apple’s App Store. While DeepSeek has since restored access to its - [Large Scale Carpet-Bombing DDoS Attacks Targeted Critical Infrastructure in Japan](https://fastnetmon.com/2025/02/05/large-scale-carpet-bombing-ddos-attacks-targeted-critical-infrastructure-in-japan/) - Recent large-scale carpet-bomb DDoS attacks in Japan have showed the evolving risks facing critical infrastructure. Unlike traditional DDoS attacks that overwhelm specific servers, carpet-bombing targets multiple devices across a network, significantly increasing disruption. The year-end and New Year period saw widespread outages affecting Japan Airlines, major banks like MUFG, Resona, and Mizuho, as well as - [Aquabot Botnet Exploits Mitel Phone Vulnerability for DDoS Attacks](https://fastnetmon.com/2025/02/04/aquabot-botnet-exploits-mitel-phone-vulnerability-for-ddos-attacks/) - A new Mirai botnet variant, Aquabot, is making the rounds, exploiting a flaw in Mitel phones to launch DDoS attacks. The vulnerability, CVE-2024-41710, impacts Mitel’s 6800, 6900, and 6900w Series SIP Phones, along with the 6970 Conference Unit, putting affected devices at risk. Although Mitel addressed this issue in July 2024, a proof-of-concept exploit became - [Event Recap - TRNOG 2025](https://fastnetmon.com/2025/01/28/event-recap-trnog-2025/) - On January 28, 2025, FastNetMon had the privilege of attending the inaugural TRNOG event in Ankara, a significant gathering for the Turkish Network Operators Group. This non-profit community of network engineers is dedicated to advancing the internet in Turkey, providing a platform for sharing knowledge and fostering collaboration. The event was a one-day intensive program - [Cybercriminals Leverage Zero-Day Vulnerability to Launch AIRASHI DDoS Botnet](https://fastnetmon.com/2025/01/24/cybercriminals-leverage-zero-day-vulnerability-to-launch-airashi-ddos-botnet/) - Recent reports have revealed a serious network security issue: hackers exploiting a zero-day vulnerability in Cambium Networks cnPilot routers to deploy the AIRASHI variant of the AISURU botnet. This botnet is being used to conduct large-scale DDoS attacks, leveraging a variety of vulnerabilities, including those in AVTECH IP cameras and LILIN DVRs. According to the - [NoName057(16) target Swiss institutions amid World Economic Forum](https://fastnetmon.com/2025/01/24/noname05716-target-swiss-institutions-amid-world-economic-forum/) - Swiss institutions have recently been targeted by a series of DDoS attacks orchestrated by the pro-Russian hacker group "NoName057(16)." This collective is known for its strategic overload attacks, aiming to make target servers inaccessible by flooding them with network requests. Since Tuesday, the group has focused its efforts on Swiss institutions, coinciding with the World - [Institutions in The Netherlands affected by DDoS attacks: Several universities and government login service impacted](https://fastnetmon.com/2025/01/20/institutions-in-the-netherlands-affected-by-ddos-attacks-several-universities-and-government-login-service-impacted/) - Several Dutch universities and the government login service DigiD have recently been targeted with DDoS attacks. The connection between the incidents is not clear nor the culprit of the attacks have been published. Last Friday, January 17th 2025, a major DDoS attack disrupted the joint network of Dutch universities, applied sciences universities, university hospitals, and - [FastNetMon Advanced 2.0.352](https://fastnetmon.com/2023/10/26/fastnetmon-advanced-2-0-352/) - Our latest release includes several updates to enhance your DDoS cover. We’ve added options for future TLS support for FastNetMon Flow, improved debugging with more detailed logs, and added logic to reconnect TCP flow forwarding sockets. We’ve also enabled IPv6 for Web_api_host and Web_api_ssl_host, and added a per hostgroup dashboard for Clickhouse. Full release notes - [FastNetMon Advanced 2.0.353](https://fastnetmon.com/2023/10/31/fastnetmon-advanced-2-0-353/) - FastNetMon's latest release brings several product enhancements to improve your DDoS detection and mitigation. We've added TLS support for FastNetMon Flow TLS agent and server, reworked capnp serialization logic, and improved debug logging for IPFIX. We've also enabled netflow_sampling_cache for Netflow v9 and IPFIX by default to avoid traffic gaps after tool restart. For a - [FastNetMon Advanced 2.0.354](https://fastnetmon.com/2023/11/01/fastnetmon-advanced-2-0-354/) - FastNetMon's latest release brings several improvements to our IPFIX and Netflow v9 logic. We've migrated away from be_copy_function in IPFIX logic, reworked IPFIX sampling logic, and addressed a bug with 2 byte sampling rate decoder in Netflow v9 for Cisco specific encoding format. See below the full list. Changes: Migrated away from be_copy_function in IPFIX - [FastNetMon Advanced 2.0.355](https://fastnetmon.com/2023/11/14/fastnetmon-advanced-2-0-355/) - FastNetMon's latest release brings several enhancements to your DDoS protection. We've added logic to store source and destination MAC addresses in Clickhouse, reworked our sFlow counters logic, and added IPv6 support for Clickhouse access. We've also introduced a new dashboard to show top talkersper network and added new fields for API and fcli command hostgroup_counters_total. - [FastNetMon Advanced 2.0.356](https://fastnetmon.com/2023/11/19/fastnetmon-advanced-2-0-356/) - FastNetMon's latest update brings significant improvements to our top hosts dashboard, now using a pre-calculated top hosts table for faster performance. We've also added a new flag to export top hosts to Clickhouse tables, improved our Clickhouse table creation logic, and reduced excessive logging in our Netflow and IPFIX plugin. Changes: Upgraded top hosts dashboard - [FastNetMon Advanced 2.0.357](https://fastnetmon.com/2023/12/28/fastnetmon-advanced-2-0-357/) - FastNetMon's latest release introduces several enhancements to improve your network security. We've added a new capability to filter traffic inline using XDP, upgraded MongoDB to 7.0 for Debian 12, and added support for multi-set TCP flags in BGP Flow Spec mode. We've also incorporated scrubbing_services_integration into our official packages and added logic to upgrade Grafana. - [FastNetMon Advanced 2.0.358](https://fastnetmon.com/2024/01/15/fastnetmon-advanced-2-0-358/) - FastNetMon's latest release brings several enhancements to improve your network security. We've added logic to export flexible counters for hostgroups and individual hosts to Clickhouse, and enabled per protocol metrics for InfluxDB and Clickhouse by default. We've also updated our traffic dashboards to the latest version and added documentation for the IPFIX_FRAGMENT_IDENTIFICATION IPFIX field. For - [FastNetMon Advanced 2.0.371](https://fastnetmon.com/2025/01/13/fastnetmon-advanced-2-0-371/) - FastNetMon Advanced 2.0.371 has been released with significant updates. We've added logic to handle padding in IPFIX plugin, improved checks in IPFIX and Netflow v9 logic, and added support for IPFIX enterprise fields used by Arista. We've also implemented multiple options templates reading in IPFIX packets, added detailed logging for data templates parsing, and ensured - [Case Study: A leading mobile carrier enhancing network security with FastNetMon blocklist-based filtering](https://fastnetmon.com/2025/01/13/case-study-a-leading-mobile-carrier-enhancing-mobile-network-security-with-fastnetmon-blocklist-based-filtering/) - Case study - FastNetMon block list based filtering in telecommunicationsDownload Background A leading global telecommunications company, with a significant presence in Ireland, faced increasing challenges in managing threats across its expansive mobile network. The company required a robust solution to effectively block malicious traffic and protect its network and customers. Challenge The telecommunications industry is - [New Mirai botnet targeting industrial routers with zero-day exploits](https://fastnetmon.com/2025/01/13/new-mirai-botnet-targeting-industrial-routers-with-zero-day-exploits/) - A new Mirai-based botnet that targets industrial routers has emerged. This botnet, discovered in February last year, has been growing in sophistication and now leverages previously unknown vulnerabilities, according to researchers at Chainxin X Lab. One of the key security issues is CVE-2024-12856, a vulnerability in Four-Faith industrial routers. This flaw was discovered in late - [Mobile operator NTT Docomo affected by a DDoS attack](https://fastnetmon.com/2025/01/06/mobile-operator-ntt-docomo-affected-by-a-ddos-attack/) - NTT Docomo, Japan's largest mobile operator was recently hit by a DDoS attack. On January 2nd, 2025 the company experienced significant network congestion from 05:27 to 16:10, impacting key services like the "goo" web portal, Lemino video streaming, dpay billing service, and "Golf me" golf-round service. This disruption affected nearly 90 million subscribers and highlights - [Surge in FICORA and CAPSAICIN botnet activity: Old D-Link vulnerabilities exploited in global attacks](https://fastnetmon.com/2024/12/28/surge-in-ficora-and-capsaicin-botnet-activity-old-d-link-vulnerabilities-exploited-in-global-attacks/) - Cybersecurity researchers have reported a surge in malicious activity involving the exploitation of old D-Link router vulnerabilities by two different botnets, FICORA and CAPSAICIN. These botnets spread through documented D-Link vulnerabilities that allow remote attackers to execute malicious commands via the Home Network Administration Protocol (HNAP) interface. The FICORA botnet attacks have targeted various countries - [Delays and cancellations as JAL suffers a DDoS attack](https://fastnetmon.com/2024/12/27/delays-and-cancellations-as-jal-suffers-a-ddos-attack/) - Japan Airlines, Japan's flag carrier, recently fell victim to a cyber attack that led to the cancellation or delay of dozens of flights. The attack, which targeted the airline's network infrastructure, also caused the temporary suspension of ticket sales for both domestic and international flights. The attack began on December 26th at 7:24 a.m. local - [Juniper Networks alerts: Mirai botnet scans and exploits SSR devices for DDoS](https://fastnetmon.com/2024/12/26/juniper-networks-alerts-mirai-botnet-scans-and-exploits-ssr-devices-for-ddos/) - ​​Juniper Networks has issued a critical alert regarding a Mirai botnet that is actively scanning the internet for Session Smart routers (SSR) using default credentials. The Mirai malware, notorious for its role in large-scale DDoS attacks, exploits devices with default login credentials to execute commands remotely, thereby enabling a range of malicious activities. The campaign - [New DDoS Malware cShell Targets Poorly Managed Linux SSH Servers](https://fastnetmon.com/2024/12/25/new-ddos-malware-cshell-targets-poorly-managed-linux-ssh-servers/) - The AhnLab Security Intelligence Center (ASEC) has recently discovered a new strain of DDoS malware, called cShell, that is specifically targeting poorly managed Linux SSH servers. This malware exploits weak SSH credentials and leverages Linux tools to execute sophisticated DDoS attacks. The initial access and infection process involves scanning publicly exposed SSH services and employing - [FastNetMon Advanced 2.0.368](https://fastnetmon.com/2024/11/26/fastnetmon-advanced-2-0-368/) - This release includes a new option for AF_PACKET to unpack GTPv1 tunnels: af_packet_extract_gtp_v1_tunnels, support for new forwardingStatus 4 byte encoding which is used by Cisco ASR9006 with IOS XR 6.4.2, a complete multi-user support for API via users_configuration and roles_configuration sections, see the full list of changes below!Changes: Complete multi user support for API via - [FastNetMon Addresses Critical Vulnerabilities in Netflow and sFlow Plugins](https://fastnetmon.com/2024/12/20/fastnetmon-addresses-critical-vulnerabilities-in-netflow-and-sflow-plugins/) - FastNetMon has successfully resolved two critical vulnerabilities in the Netflow and sFlow plugins of its product. The vulnerabilities were identified by an independent security researcher on December 12th 2024, and have since been patched. The vulnerabilities, discovered through a methodology known as fuzzing, had the potential to allow remote attackers to cause crashes of the - [FastNetMon Advanced 2.0.360](https://fastnetmon.com/2024/02/20/fastnetmon-advanced-2-0-360/) - In our recent update, we've introduced the ability to calculate speed in parallel and added precise profiling for each part of the speed calculation process. We've also reworked the logic for top k speed counters and remote IP speed retrieval. We've merged data and speed counters for a speed calculation process that's approximately 1.74 times - [27 DDoS-for-hire platforms shut down](https://fastnetmon.com/2024/12/11/27-ddos-for-hire-platforms-shut-down-major-breakthrough-from-operation-poweroff/) - Major breakthrough from Operation PowerOFF In a sweeping international effort, law enforcement agencies from 15 countries have successfully dismantled 27 DDoS-for-hire services, commonly referred to as "booters" or "stressers." These platforms, which utilize botnets on compromised devices, enable paying customers to launch disruptive DDoS attacks against selected online targets. This operation, known as 'Operation PowerOFF,' - [Danish Municipality Websites Down with a DDoS attack](https://fastnetmon.com/2024/12/11/danish-municipality-websites-down-with-a-ddos-attack/) - Several Danish municipalities recently fell victim to Distributed Denial of Service (DDoS) attacks, disrupting the websites of cities including Vejle, Albertslund, Dragør, Esbjerg, Frederiksberg, and Frederikshavn. The director of the Danish Cybersecurity Centre (CFCS), Mark Fidel, reported that such attacks are often carried out by pro-Russian cyber-activists, who regularly target Denmark. The purpose of these - [FastNetMon Advanced 2.0.362](https://fastnetmon.com/2024/03/13/fastnetmon-advanced-2-0-362/) - Our latest release includes a complete logic to reload per host hostgroups without a FastNetMon restart. We've improved IPv6 hostgroup lookup performance and added explicit logic to avoid complex JSON crafting operations. We've also added several counters to measure time required for various procedures. We've made significant improvements in our threshold checking logic and extracted - [FastNetMon Advanced 2.0.364](https://fastnetmon.com/2024/04/04/fastnetmon-advanced-2-0-364/) - Our latest update introduces new BGP peering configuration options, allowing for more control over add path logic. We've also added the ability to override default values in hostgroup configurations. Additionally, we've introduced new controls for IPv6 Flow Spec redirect. See all updates below! Changes: Added warning message to log when capacity of traffic buffer is - [FastNetMon Advanced 2.0.365](https://fastnetmon.com/2024/04/26/fastnetmon-advanced-2-0-365/) - Changes: Multiple improvements for licensing logic - [FastNetMon Advanced 2.0.369](https://fastnetmon.com/2024/11/27/fastnetmon-advanced-2-0-369/) - Changes: Fixed bug with endpoints total_traffic_counters_v4 and total_traffic_counters_v6 which did not work and required not needed parameters - [BGP Blackhole Automation for DDoS mitigation](https://fastnetmon.com/2026/01/06/bgp-blackhole-automation-for-ddos-mitigation/) - In this article, we will discuss how the routing infrastructure, more specifically the BGP routing technique called “blackholing”, can provide efficient mitigation for DDoS attacks. We will go through some key concepts, and explain how to set up and manage a RTBH (Remotely Triggered Black Hole), and highlight the advantages and disadvantages of the technique. - [Evolution of Network Layer DDoS attacks](https://fastnetmon.com/2024/12/06/evolution-of-network-layer-ddos-attacks/) - Despite being one of the oldest types of cyberattacks, Distributed Denial of Service attacks still remain the most common cyber threat for organisations. Over the course of years, the attackers' aim has not changed: to overwhelm and disrupt online services, rendering them inaccessible to legitimate users. However, over the past decade, DDoS attacks have evolved - [DDoS capabilities installed in 240 000 satellite receivers by manufacturer](https://fastnetmon.com/2024/12/04/ddos-capabilities-installed-in-240-000-satellite-receivers-by-manufacturer/) - The Korean National Police Agency has arrested the CEO and five employees of a South Korean company for a peculiar cybercrime. The company has been manufacturing and exporting a large number of satellite receivers with embedded Distributed Denial of Service (DDoS) attack capabilities. The arrest followed a tip-off from Interpol in July, when the case - [FastNetMon Advanced 2.0.367](https://fastnetmon.com/2024/10/10/fastnetmon-advanced-2-0-367/) - FastNetMon has released a new update with several enhancements and bug fixes. The update includes added logic for storing unban actions in MongoDB, a fix for a bug in the Graphite plugin, and changes in BGP Flow Spec mitigation logic. We've also deprecated certain fields and improved the logic for crafting IPv4 BGP attributes. Please - [“Matrix Botnet” Exploiting IoT Devices for DDoS Campaign](https://fastnetmon.com/2024/11/27/matrix-botnet-exploiting-iot-devices-for-ddos-campaign/) - The Matrix Botnet, a threat actor linked to a widespread DDoS campaign has been uncovered by security researchers. The botnet is exploiting vulnerabilities and misconfigurations in Internet of Things (IoT) devices. This operation seems to be a comprehensive one-stop shop for scanning, exploiting vulnerabilities, deploying malware, and setting up shop kits, which makes it an - [Event Recap - UK IPv6 Council Annual Meeting](https://fastnetmon.com/2024/11/20/event-recap-uk-ipv6-council-annual-meeting/) - FastNetMon had the privilege of participating in the UK IPv6 Council Annual Meeting held last Tuesday, November 19th, 2024 at Cisco Meraki in London. The event was a melting pot of knowledge and expertise, with very interesting talks from industry leaders in the Internet, telco, and networking fields. Here’s our recap of the highlights! From - [Fastnetmon at HKNOG13](https://fastnetmon.com/2024/11/08/fastnetmon-at-hknog13/) - How was it at HKNOG13? Here’s our conference recap Last Friday, November 1st 2024, we had the absolute pleasure of attending the annual Hong Kong Network Operators Group conference #13 - AKA HKNOG13. Flying in all the way from UK on a short notice was bt of a task, but it was more than worth - [British Councils Fend Off a Series of DDoS Attacks](https://fastnetmon.com/2024/11/06/british-councils-fend-off-a-series-of-ddos-attacks/) - Last week several UK councils experienced outages on their websites, with some even knocked offline or rendered inaccessible to users, due to a series of DDoS attacks. The cyber onslaught targeted various local authorities and other organisations, including small banks and the Premier League football club Tottenham Hotspur. The attack is claimed to be work - [German Police Shuts Down DDoS Service](https://fastnetmon.com/2024/11/05/german-police-shuts-down-ddos-service/) - German police have announced the disruption of a DDoS-for-hire platform dstat[.]cc. The platform has been playing a significant role in facilitating distributed denial-of-service (DDoS) attacks, and the crackdown is a big victory for cybercrime defense. German law enforcement describes dstat[.]cc as a platform that was provided evaluations of stressor services, which are used to conduct - [CUPS vulnerability explained ](https://fastnetmon.com/2024/10/23/cups-vulnerability-explained/) - How compromised CUPS servers can be a DDoS threat? A newly discovered vulnerability (CVE-2024-47850) in the Common Unix Printing System (CUPS) can be exploited to stage DDoS attacks. Starting an attack is surprisingly simple. It only requires sending a single packet to a vulnerable CUPS service, triggering an amplified, partially attacker-controlled IPP/HTTP request flood.There are ## Pages - [FastNetMon - Comprehensive Solutions for DDos Security](https://fastnetmon.com/) - High-performance DDoS Security, Detection & Visibility. Support BGP FlowSpec, RTBH & sFlow for real-time security without extra hardware. Deploy on any cloud. - [What is average_calculation_time?](https://fastnetmon.com/docs-fnm-advanced/what-is-average_calculation_time/) - Concept of average_calculation_time is exceptionally important in FastNetMon as correct bandwidth calculation relies on correct setting of this value. Internally, FastNetMon uses algorithm called exponential moving average to approximate speed. This algorithm allows us to react on new traffic information way faster in compare with simple average which can provide traffic speed only after getting - [Automatic baseline calculation for FastNetMon](https://fastnetmon.com/docs-fnm-advanced/automatic-baseline-calculation-for-fastnetmon/) - Automatic threshold generation from historical data for FastNetMon Advanced - [FastNetMon Advanced per host threshold configuration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-per-host-threshold-configuration/) - FastNetMon is a baseline / threshold based DDoS detection engine and it means that you need to set level of traffic which will be considered as attack by FastNetMon. By default, FastNetMon has global hostgroup which keeps thresholds for all hosts in your network. To set level of traffic which FastNetMon will consider as an - [FastNetMon Advanced threshold types](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-threshold-types/) - In this guide you can find detailed description for all threshold types - [Huawei router configuration with FastNetMon Advanced](https://fastnetmon.com/docs-fnm-advanced/huawei-routers-configuration-with-fastnetmon-advanced/) - This guide tells you about required configuration steps for Huawei. - [FastNetMon NetFlow v9 configuration for Cisco ASR 9000](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-netflow-v9-configuration-for-cisco-asr-9000/) - In this guide you will find detailed information about Netflow v9 configuration for Cisco ASR 9000 - [FastNetMon Partner Ecosystem](https://fastnetmon.com/partners/) - Our partners play an important role in helping customers successfully deploy and operate FastNetMon across diverse network environments. This page brings together our Solution Partners, Technology Partners, cloud-based DDoS scrubbing providers, recent partnership announcements, and information on joining our growing ecosystem. Partner Highlights & News FastNetMon and IP Infusion introduce automated DDoS protection with - [Become a FastNetMon Partner](https://fastnetmon.com/partner-register/) - Partner with FastNetMon to bring advanced DDoS detection and mitigation to more networks. The FastNetMon Partner Program is built for companies that help network operators, enterprises, and digital infrastructure providers strengthen their network security. Whether you want to introduce FastNetMon to your customers, deliver FastNetMon as part of your solutions, or build our technology into - [FastNetMon Partner Onboarding Enquiry](https://fastnetmon.com/fastnetmon-partner-onboarding-enquiry/) - [FastNetMon Careers](https://fastnetmon.com/careers/) - FastNetMon is a fast-growing technology company building cutting-edge DDoS detection and mitigation tools used by network operators and enterprises in over 130 countries. As we scale globally, we’re looking for curious, technically minded people to help us protect the world’s internet infrastructure. We’re a remote-first team based in London, UK, with deep roots in the - [FastNetMon Advanced API](https://fastnetmon.com/docs-fnm-advanced/advanced-api/) - This page described API capability of FastNetMon Advanced - [BGP announces for total hostgroups](https://fastnetmon.com/docs-fnm-advanced/bgp-announces-for-total-hostgroups/) - This guide covers FastNetMon's ability to run BGP announces when total amount of traffic for a group of hosts or networks exceeds a specified threshold. This capability is called total hostgroups and is well covered in this guide. To use this guide, you will need to have attack detection enabled for total hostgroups using this - [FastNetMon and BGP traffic diversion](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-and-bgp-traffic-diversion/) - In addition to the option to announce /32 or /128 hosts which are under attack, FastNetMon can announce whole networks where the attacked host is located. It may be useful for DDoS scrubbing centre diversion or internal network policy changes (i.e. to move the prefix under attack to in-house scrubbing or move it to another - [FastNetMon Advanced install on Hyper-V](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-install-on-hyper-v/) - This guide was tested with Windows 2022 Server Standard. To start with, you'll need to download our VHD image for Hyper-V here. We do automated image builds on the next day from stable release. Feel free to change the file name of the image if you prefer to use the latest release. As a first - [FastNetMon Advanced installation on Proxmox VM](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-installation-on-proxmox-vm/) - We offer official QCOW2 images which can be used with a variety of KVM-based hypervisors. To start, please download the latest image. We do automated image builds on the next day from the stable release. Feel free to change the file name of the image if you prefer to use the latest release. This guide - [FastNetMon and Juniper JunOS integration in IPFIX mode](https://fastnetmon.com/docs-fnm-advanced/junos_integration/) - Documentation to integrate FastNetMon with inline jFlow using Juniper MX Series routers. - [FastNetMon Advanced per-network hostgroups](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-per-network-hostgroups/) - FastNetMon Advanced provides an option to implement attack detection for all networks in FastNetMon configuration (as defined in networks_list) on per network basis. In this mode FastNetMon counts all traffic for particular prefix and sends alerts when total traffic for particular network exceeds defined value. Current implementation does not allow to set thresholds for particular - [FastNetMon Advanced licensing logic](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-licensing-server/) - This guide tells you details about FastNetMon’s license server implementation. - [FastNetMon ASN peering reports](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-asn-peering-reports/) - We offer ASN analytics reports capability for FastNetMon Advanced, which implements native support for per ASN bandwidth calculation and stores it into InfluxDB or Clickhouse in pre-calculated format. It is implemented in the following way for outgoing traffic: sudo fcli show asn_counters_v4 outgoing 28026 4810 pps 38 mbps 52374 3028 pps 25 mbps 52376 2345 - [FastNetMon VM Vmware Esxi image install](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-vm-image-install/) - In this guide we will offer step-by-step instructions to deploy FastNetMon from image on hypervisor - [FastNetMon VM image install in vmware vCenter](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-vm-image-install-in-vmware-vcenter/) - You can find detailed step by step guide about deployment of FastNetMon on vmware - [Flexible thresholds](https://fastnetmon.com/docs-fnm-advanced/flexible-thresholds/) - In addition to a wide range of static thresholds, FastNetMon offers the capability to create completely custom thresholds using almost all fields available in L3 and L4 OSI model layers. Flexible thresholds can be used for both per_host and total hostgroups. To enable this logic, you will need to set the following flag: sudo fcli - [Case Studies & User Stories](https://fastnetmon.com/client-testimonials/) - Many companies use our DDoS detection tool. Read their testimonials about experience. - [FastNetMon LiveView installation](https://fastnetmon.com/docs-fnm-advanced/web-user-interface-for-fastnetmon-advanced/) - To configure and manage FastNetMon Advanced, you can use the official web user interface FastNetMon LiveView (chargeable per user, as an addon). LiveView is available for free during trial period To use LiveView, please ensure that you run at least FastNetMon Advanced 2.0.378, and that your FastNetMon installation use MongoDB and Clickhouse. FerretDB and InfluxDB - [Enabling BGP BMP monitoring on JunOS Juniper platforms](https://fastnetmon.com/docs-fnm-advanced/enabling-bgp-bmp-monitoring-on-junos-juniper-patforms/) - To enable BMP monitoring on Juniper platforms you need to apply following configuration: routing-options { bmp { station BMPServerFastNetMon { initiation-message "FastNetMon"; local-address XXX; connection-mode active; monitor enable; route-monitoring { pre-policy; } station-address XXX; station-port XXX; statistics-timeout 300; } } Unfortunately it explicitly does not support hostnames and you have to use IP addresses in - [Automatic blocks for remote attackers](https://fastnetmon.com/docs-fnm-advanced/automatic-blocks-for-remote-attackers/) - In this article you will find all information to detect remote attackers. - [FastNetMon Advanced Install guide](https://fastnetmon.com/docs-fnm-advanced/advanced-install-guide/) - Here you could find information how you could install FastNetMon Advanced. - [Clean attack records from MongoDB](https://fastnetmon.com/docs-fnm-advanced/clean-attack-records-from-mongodb/) - By default, when we install MongoDB usually you can connect with command mongosh from root (without args). Or with stored for FastNetMon password with mongosh --username administrator --password $(cat /etc/fastnetmon/keychain/.mongo_admin) command or with mongosh --username fastnetmon_user --password $(cat /etc/fastnetmon/keychain/.mongo_fastnetmon_password) After you connected to MongoDB, to clean all attack records run use fastnetmon db.attacks.drop() To find and delete - [FastNetMon Advanced upgrade procedure](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-upgrade-procedure/) - For all supported Linux distributions, we offer official repositories which simplify the installation of upgrades. For Ubuntu, Debian and RedHat family of distributions, if you use the standard way to upgrade all system packages, FastNetMon will be upgraded too. You will find detailed information about latest versions of FastNetMon at GitHub. We strongly recommend doing - [FastNetMon Advanced APT repositories](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-apt-repositories/) - FastNetMon Advanced packages are distributed through separate APT repository domains for each supported Debian and Ubuntu release. Supported repository domains: The repository configuration is stored in: /etc/apt/sources.list.d/fastnetmon.list For example, on Ubuntu 22.04 Jammy, the file contains: deb [arch=amd64 signed-by=/usr/share/keyrings/fastnetmon_dearmor.gpg] https://jammy.ubuntu.repo.fastnetmon.com stable main Public gpg key fastnetmon_dearmor.gpg, that should be putted in /usr/share/keyrings/fastnetmon_dearmor.gpg, you can download - [FastNetMon Advanced configuration with Huawei sFlow v5](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-configuration-with-huawei-sflow-v5/) - In thus guide you will learn how to configure sFlow v5 on Huawei switches or routers with FastNetMon Advanced First of all you need to enable sFlow v5 globally: sflow enable Then you need to configure IP for sFlow v5 agent, it will use this IP to send data to FastNetMon: sflow agent ip 10.1.10.1 - [FastNetMon Advanced Proxy support](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-proxy-support/) - FastNetMon, fcli, and the FastNetMon installer support HTTP and HTTPS proxies through standard environment variables: export https_proxy="http://proxy.example.com:3128" export http_proxy="http://username:password@proxy-with-auth.example.com:3128" Uppercase variants HTTP_PROXY and HTTPS_PROXY also supported by installer and fcli. FastNetMon systemd service To configure proxy access for FastNetMon running as a systemd service, create a service override: sudo systemctl edit fastnetmon Add the required - [FastNetMon Advanced: navigating all available telemetry protocols for different vendors](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-navigating-all-available-telemetry-protocols-for-different-vendors/) - FastNetMon Advanced has comprehensive support for variety of telemetry protocols and it may not be easy to find out protocol which is the best in your particular case You can find full table with all vendors and telemetry protocols supported by FastNetMon, recommended protocols highlighted by star: According to this page we can make conslusions: - [FastNetMon Community edition Terms and Conditions](https://fastnetmon.com/fastnetmon-community-edition-terms-and-conditions/) - fastnetmon-community-edition-terms-and-conditions-10-aug-2023Download Looking for something else? See the full list of FastNetMon Policies and Terms. - [Software Licensing Terms and Conditions](https://fastnetmon.com/terms-conditions/) - Our terms and conditions for FastNetMon Advanced. Read it if you want to use FastNetMon DDoS detection tool. - [FastNetMon Privacy Policy](https://fastnetmon.com/privacy-policy/) - We keep our up to date privacy policy here - [Website Terms of Use](https://fastnetmon.com/website-terms-of-use/) - Looking for something else? See the full list of FastNetMon Policies and Terms. - [Website Accessibility Statement](https://fastnetmon.com/website-accessibility-statement/) - Looking for something else? See the full list of FastNetMon Policies and Terms. - [FastNetMon Advanced: Network-Level DDoS Defence and Monitoring](https://fastnetmon.com/product-overview/) - FastNetMon Advanced Key Features. We have a lot of improvements here in different subsystems. - [Hostgroup Max Talkers capability](https://fastnetmon.com/docs-fnm-advanced/hostgroup-max-talkers-capability/) - Please note that this capability is a part of the partner-only integration feature set, and we strongly advise against using it unless you have discussed it with our engineering team. This logic can be changed or removed without any further notice, and it is not a part of FastNetMon's backward compatibility guarantee. To enable the - [FastNetMon Advanced web callbacks](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-web-callbacks/) - FastNetMon Advanced has capability to send attack information in JSON format to remote URL when it detects attack against IP or identifies malicious pattern (BGP Flow Spec mode). In addition it can report information ongoing attacks using attack status capability To send information it uses POST request with JSON encoded document inside and content-type is - [Legal](https://fastnetmon.com/legal/) - FastNetMon policies and terms Find FastNetMon’s legal policies and terms, including website usage, privacy, accessibility, and software licensing information, via the links below. Website accessibility statement Website Terms of Use Privacy policy Software Licensing Terms and Conditions Website Cookie Policy FastNetMon Community Edition Terms and Conditions FastNetMon Community Edition Privacy Notice FastNetMon uses several external - [FastNetMon Advanced XDP filter](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-xdp-filter/) - Starting from release 2.0.357, we offer an experimental capability which allows you to filter traffic in line using FastNetMon. We leverage the XDP capability of the Linux Kernel for lightning-fast traffic filtering. You can use this capability to defend a Linux server from attacks from the outside. To enable logic which automatically creates filtering rules - [FastNetMon Advanced installation on ARM 64 edition](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-arm-64-edition/) - You can find all details about required step to install FastNetMon on ARM64 platform - [Press & Newsroom](https://fastnetmon.com/news-and-pr/) - Press & Newsroom Home ‣ Press & Newsroom Information for the press About FastNetMon FastNetMon develops DDoS detection and network traffic visibility solutions for telecommunications providers, Internet Service Providers, hosting companies, and organisations operating large-scale networks. The platform enables network operators to monitor traffic in real time, detect DDoS attacks, and automate mitigation - [Events](https://fastnetmon.com/events/) - Events Home ‣ Events Upcoming events We regularly attend industry conferences, network operator group meetings, and cybersecurity events around the world. See below where you can catch up with FastNetMon next. See you at NONOG-8 / NIX-2026Upcoming EventsFastNetMon will be attending NONOG-8 / NIX-2026 on September 9, 2026, in Oslo, Norway, and we’re looking forward - [FastNetMon Advanced cli reference guide](https://fastnetmon.com/docs-fnm-advanced/advanced-cli-reference/) - FastNetMon Advanced - cli reference guide. Full information about settings. - [FastNetMon Advanced Traffic Persistence](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-traffic-persistency/) - This page describes ability to store all sFlow/Netflow/IPFIX traffic using FastNetMon and Clickhouse - [Subnet collection from BGP peering session](https://fastnetmon.com/docs-fnm-advanced/subnet-collection-from-bgp-peering-session/) - In this guide we will provide detailed explanation how you can automatically collect networks list from BGP peering session - [FastNetMon Advanced manual deployment on Docker platform](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-manual-deployment-on-docker-platform/) - To store state data and configuration, FastNetMon uses MongoDB, and we will need to install it first. You can deploy FastNetMon on Docker using our official Docker images. To keep MongoDB data and FastNetMon configuration and state, we will use folders from the host, and we need to create them in the following way: sudo - [FastNetMon Advanced Docker installation](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-docker-installation/) - In this guide we will guide you through installation process on Docker platform - [FastNetMon Pricing Plan](https://fastnetmon.com/pricing/) - FastNetMon offers volume-based pricing with no limits on the number of network devices. Choose a plan that fits your traffic and scale effortlessly. - [Data retention for Clickhouse persistent data storage](https://fastnetmon.com/docs-fnm-advanced/data-retention-for-clickhouse-persistent-data-storage/) - If you would like to use Clickhouse for FastNetMon read this manual how to setup it. - [Important note for upgrades from older FastNetMon Advanced releases before 2.0.375](https://fastnetmon.com/docs-fnm-advanced/important-note-for-upgrades-from-older-fastnetmon-advanced-releases-before-2-0-375/) - Starting from FastNetMon Advanced 2.0.375, the old ClickHouse metrics database schema is no longer supported. If you upgraded FastNetMon Advanced from an older release and ClickHouse metrics export was enabled before the upgrade, we recommend checking that all FastNetMon metrics tables use the current schema documented below. FastNetMon can create all required ClickHouse metrics tables - [Videos and presentations from FastNetMon](https://fastnetmon.com/video/) - Watch videos about FastNetMon with conferences. You can find a lot of interesting and useful information about tool from users who use it. - [FastNetMon presentation Slides](https://fastnetmon.com/presentation/) - Watch presentations from conference about FastNetMon. You can find a lot of useful advises and testimonials from our partners. - [FastNetMon Netflow and IPFIX sampling configuration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-netflow-and-ipfix-sampling-configuration/) - This guide will describe all steps required to configure sampling rate - [FastNetMon JSON formats](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-json-formats/) - FastNetMon uses number of different documents represented in JSON format - [FastNetMon Advanced integration with F5 DDoS scrubbing centre](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-integration-with-f5-silverline-ddos-scrubbing-centre/) - FastNetMon Advanced offers complete production-ready integration with cloud DDoS scrubbing service provided by F5 XC and F5 Silverline (legacy). You can find the official press release of this capability on the F5 website here. How does FastNetMon scrubbing centre diversion integration work? When FastNetMon detects an attack against an IP address, it determines /24 prefix - [Discarded traffic monitoring in FastNetMon Advanced](https://fastnetmon.com/docs-fnm-advanced/discarded-traffic-monitoring-in-fastnetmon-advanced/) - In addition to the capability which calculates bandwidth and packet rate of specific types of packets, FastNetMon Advanced provides a very special counter which counts bandwidth and packet rate for discarded packets. The main application of this logic is to understand the amount of traffic filtered by BGP Flow Spec when FastNetMon works in BGP - [BGP Flow spec configuration on Cisco ASR1000](https://fastnetmon.com/bgp-flow-spec-configuration-on-cisco-asr1000/) - In this guide we will provide all commands required to configure BGP Flow spec. - [FastNetMon BGP Flow spec based DDoS mitigation](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-bgp-flow-spec-configuration/) - In this guide you will find all details about BGP Flow spec mode configuration - [sFlow on Juniper MX FastNetMon Advanced](https://fastnetmon.com/docs-fnm-advanced/sflow-on-juniper-mx-fastnetmon-advanced/) - We recommend using this official guide to configure sFlow on the MX platform. Unfortunately, MX on Juniper has several quirks and may not work well. We recommend using inline monitoring services instead. To address one of the well-known sFlow protocol implementation issues on Juniper MX, you may use this flag: sudo fcli set sflow_read_packet_length_from_ip_header true - [FastNetMon Advanced visual traffic with Grafana](https://fastnetmon.com/docs-fnm-advanced/advanced-visual-traffic/) - FastNetMon Advanced visual traffic. Full information about settings. - [FastNetMon Advanced Technical Documentation](https://fastnetmon.com/docs-fnm-advanced/) - All required information about FastNetMon Advanced. - [FastNetMon and DDoS Scrubbing centers integration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-and-ddos-scrubbing-centers-integration/) - In addition to solid support for BGP Unicast protocol which can be used to move traffic for affected prefix to cloud based DDS scrubbing center FastNetMon Advanced features multiple API based integrations with variety of DDoS scrubbing centers. You can use FastNetMon Advanced with following scrubbing centers: GCore Global DDoS Protection F5 Cloudflare Magic Transit - [Using FastNetMon Advanced with FerretDB and SQLite backend instead of MongoDB](https://fastnetmon.com/docs-fnm-advanced/using-fastnetmon-advanced-with-ferretdb-and-sqlite-backend-instead-of-mongodb/) - We have an experimental version of our installer, which installs FastNetMon Advanced with FerretDB automatically: wget https://install.fastnetmon.com/installer -Oinstaller sudo chmod +x installer sudo ./installer -ferretdb This guide is an improved version of this guide with the goal to eliminate dependency on PostgreSQL and using SQLite instead. FerretDB offers complete ARM64 support; you can use FastNetMon - [Releases](https://fastnetmon.com/releases/) - Releases Home ‣ Releases FastNetMon Advanced is actively maintained and enhanced to provide deeper traffic visibility and stronger DDoS defence capabilities. This page lists all FastNetMon Advanced version releases, including new features, improvements, and platform updates. For full technical details and historical release information, visit the FastNetMon GitHub repository. FastNetMon Advanced 2.0.383Aug 6, 2026 | ReleasesRelease date: 5 August, - [Single click install on Google Cloud Engine](https://fastnetmon.com/docs-fnm-advanced/single-click-install-on-google-cloud-engine/) - [FastNetMon Advanced IPv6 support](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-ipv6-support/) - We support IPv6 and this configuration guide tells you about settings for it. - [FastNetMon usage analytics](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-usage-analytics/) - For product usage survey purposes, FastNetMon sends the following information to the stats server multiple times per day: Instance ID random identifier allocated during installation Current incoming, outgoing, other and internal bandwidth for IPv4, IPv6 and IPv4+IPv6 traffic Total number of hosts in IPv4 network Number of active IPv4 and IPv6 hosts Number of observed - [FastNetMon Advanced components diagram](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-components-diagram/) - On this diagram, you can find all FastNetMon toolkit components - [FastNetMon Advanced installation on Hypervisors or Virtual Machines](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-installation-on-hypervisors-or-virtual-machines/) - In addition to the option of installing FastNetMon on any supported Linux, we offer VM images for multiple hypervisors, which include pre-installed FastNetMon with all the components needed: vmware ESXi vmware vCenter Proxmox Microsoft Hyper-V - [BGP BMP configuration instructions](https://fastnetmon.com/docs-fnm-advanced/bgp-bmp-configuration-instructions/) - You can find BMP configuration examples for following vendors below: Juniper - [FastNetMon Accessibility issues](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-accessibility-issues/) - In some exceptionally rare cases, you may experience issues caused by the fact that the FastNetMon daemon is not running. Usually, you notice such issues by following the error from fcli or from our API daemon: sudo fcli show log 2024/09/17 15:14:31 Cannot connect to FastNetMon API localhost:50052: rpc error: code = Unavailable desc = - [FastNetMon Advanced support policy](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-support-policy/) - As part of your subscription, you have a fixed number of support requests every month. Scope of support Our support policy is strictly limited to issues about FastNetMon Advanced itself. We can provide you with assistance only when our product is not behaving as described in the documentation. We do not provide assisted installation or - [Attack_protocol deprecation in version 2.0.368](https://fastnetmon.com/docs-fnm-advanced/attack_protocol-deprecation-in-version-2-0-368/) - In version 2.0.368 (released 23rd November 2024) of FastNetMon Advanced, we completely removed field attack_protocol from JSON script and POST callbacks. In version 2.0.367 (released October 20 2024), this flag was set to "unknown" and marked as obsoleted. We did this change as attack_protocol did not reflect attack vector and was based solely on the - [Using FastNetMon Advanced with FerretDB and PostgreSQL instead of MongoDB](https://fastnetmon.com/docs-fnm-advanced/using-fastnetmon-advanced-with-ferretdb-and-postgresql-instead-of-mongodb/) - Warning: This capability is in early experimental stages and not suitable for production deployments. Warning: This guide is not suitable for existing installations, as we will remove all configuration data. By default, FastNetMon Advanced uses MongoDB as the default database for configuration. In addition to storing configuration in MongoDB, FastNetMon may store some optional information - [Clickhouse excessive disk usage with log tables](https://fastnetmon.com/docs-fnm-advanced/clickhouse-excessive-disk-usage-with-log-tables/) - Old installations of FastNetMon (pre-2023) may consume an excessive amount of disk space as the old Clickhouse configuration had logic which logged every single query in a separate database. It may easily use tens of gigabytes of disk space. You may easily confirm that it's the root cause by running this query in clickhouse-client: SELECT - [FastNetMon Advanced segmentation fault](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-segmentation-fault/) - If you observe FastNetMon Advanced suddenly stopping to work without any error messages in /var/log/fastnetmon/fastnetmon.log, it may be a crash due to a segmentation fault (segfault) error type. You can confirm it by running this command: sudo dmesg And then checking the output for records like this: Jul 18 17:21:41 monitor kernel: fastnetmon[30157]: segfault at - [FastNetMon Advanced migration from MongoDB to FerretDB](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-migration-from-mongodb-to-ferretdb/) - In addition to MongoDB, FastNetMon Advanced has complete support for FerretDB, which has the following advantages over MongoDB: Easy upgrade (no need to upgrade to intermediate major versions) Easy maintenance (just a single binary) Truly free Apache 2 open source license instead of proprietary SSPL Transparent and community-focused development model To migrate the existing installation - [FastNetMon Advanced Release Lifecycle](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-release-lifecycle/) - On this page, you can find information about FastNetMon Advanced releases' support for old distributions. Our standard policy is to provide official releases as long as the vendor provides standard free security support for a particular Linux distribution. For Ubuntu Linux LTS, it covers "LTS standard security maintenance" and explicitly excludes "LTS Expanded Security Maintenance - [Hostgroup Traffic profile capability](https://fastnetmon.com/docs-fnm-advanced/hostgroup-traffic-profile-capability/) - Please note that this capability is part of a partner-only integration feature set, and we strongly advise against using it unless you have discussed it with our engineering team. This logic can be changed or removed without any further notice, and it is not a part of FastNetMon's backward compatibility guarantee. To enable per-hostgroup traffic - [FastNetMon Advanced blackhole and Flow Spec persistence during restart](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-blackhole-during-restart/) - This is the guide about blackhole persistency during restart FastNetMon Advanced. - [Flexible counters for traffic calculation](https://fastnetmon.com/docs-fnm-advanced/flexible-counters-for-traffic-calculation/) - This guide will help you when you monitor really big networks with FastNetMon - [Extending disk space for FastNetMon VM installs](https://fastnetmon.com/docs-fnm-advanced/extending-disk-space-for-fastnetmon-vm-installs/) - Guide will help with disk extension for VM setups - [FastNetMon backup / restore](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-backup-restore/) - In this guide you will find process to backup and restore FastNetMon's configuraion - [Monitoring FastNetMon via Prometheus](https://fastnetmon.com/docs-fnm-advanced/monitoring-fastnetmon-via-prometheus/) - You can read this article to configure metrics collection from FastNetMon via Prometheus - [Log management in FastNetMon](https://fastnetmon.com/docs-fnm-advanced/log-management-in-fastnetmon/) - In this guide you will find instructions for log management in FastNetMon - [FastNetMon Advanced complete removal](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-complete-removal/) - In case of migration or a clean re-install, you may need to remove FastNetMon Advanced with all configuration files. Instructions in this article will lead to the complete irrecoverable loss of configuration and all data from the server. These instructions will work for Debian or Ubuntu platforms. Do not continue unless you're 100% sure that - [How to keep traffic counters during restart of FastNetMon](https://fastnetmon.com/docs-fnm-advanced/how-to-keep-traffic-counters-during-restart-of-fastnetmon/) - When you issue a sudo fcli commit command, you restart FastNetMon. It leads to a complete drop of all information accumulated by FastNetMon, and you may notice a drop on graphs in Grafana when such events happen. Before using this capability, you need to have subsystems which handle such logic: sudo fcli set main keep_traffic_counters_during_restart - [Memory consumption](https://fastnetmon.com/docs/memory_consumption/) - How to calculate memory consumption. FastNetMon. - [FastNetMon Advanced configuration options](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-configuration-options/) - Complete description of all availible configuration options in FastNetMon - [FastNetMon BGP Flow Spec RFC 5575 JSON representation](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-bgp-flow-spec-rfc-5575-json-representation/) - The description of FastNetMon BGP Flow Spec RFC 5575 JSON representation. - [sFlow, Netflow or IPFIX duplication to multiple servers](https://fastnetmon.com/docs-fnm-advanced/sflow-netflow-or-ipfix-duplication-to-multiple-servers/) - This guide provides information about options to replicate sFlow, IPFIX, Netflow traffic to multiple source - [FastNetMon baseline calculation](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-naseline-calculation/) - Automatic script to configure thresholds in FastNetMon - [FastNetMon Advanced scalability](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-scalability/) - Detailed guide about scalability of FastNetMon - [Delivering traffic information to FastNetMon over the Internet](https://fastnetmon.com/docs-fnm-advanced/delivering-traffic-information-to-fastnetmon-over-the-internet/) - This guide provides details about best ways to deliver traffic information from remove locations to FastNetMon over public networks - [FastNetMon Advanced example API client to add and remove networks](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-example-api-client/) - This guide provides example of API client for FastNetMon - [FastNetMon Advanced example API client which blocks and unblocks IP](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-example-api-client-which-blocks-and-unblocks-ip/) - Example API client which blocks and unblocks hosts - [FastNetMon Flow specification](https://fastnetmon.com/docs-fnm-advanced/tera-flow-capnproto-specification/) - Tera Flow format specification to encode or decode data in FastNetMon - [FastNetMon Advanced and Slack integration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-and-slack-integration/) - FastNetMon Advanced has complete support for native Slack alerts regarding ban and unban actions for blackhole mode. It's available starting from 2.0.328. You can enable it using the following options: sudo fcli set main slack_notifications_enabled true sudo fcli set main slack_notifications_url https://hooks.slack.com/services/xxx/xxx/xxx sudo fcli set main slack_notifications_add_simple_packet_dump true sudo fcli commit Example callbacks look this - [FastNetMon Advanced and Telegram integration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-and-telegram-integration/) - FastNetMon Advanced has complete support for native Telegram alerts for ban and unban actions for blackhole mode. It’s available starting from 2.0.329. To use notifications, you need to create a bot in Telegram. To create bot, you will need to contact a special @BotFather account in Telegram and then follow the instructions. After this, you - [FastNetMon Advanced integration with Cloudflare Magic Transit scrubbing centre](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-integration-with-cloudflare-magic-transit-scrubbing-centre/) - FastNetMon Advanced offers complete production-ready integration with a cloud DDoS scrubbing service called Magic Transit, provided by Cloudflare Inc. Cloudflare and Magic Transit are registered trademarks of Cloudflare Inc. Please check that your version of FastNetMon is 2.0.357 or newer. To use this capability, you will need to create an API key which allows you - [FastNetMon Advanced notify script in Perl](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-notify-script-in-perl/) - FastNetMon Advanced JSON version of notify script in Perl - [FastNetMon Advanced Notify Script in Bash](https://fastnetmon.com/docs-fnm-advanced/notify-script-in-bash/) - Example notify script implemented in Basg - [Example web hook receiver for FastNetMon Advanced in Python](https://fastnetmon.com/docs-fnm-advanced/example-web-hook-receiver-for-fastnetmon-advanced/) - This pages provides example code for HTTP web server implemented in python to test web_hook capability. - [FastNetMon Advanced JSON notify script in Python](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-json-notify-script-in-python/) - You can find here the example JSON notify script implemented in Python. - [FastNetMon e-mail notifications](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-e-mail-notification/) - In this guide you will find all information about configuring email for FastNetMon Advanced - [FastNetMon Radware Integration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-radware-second-generation-integration/) - We offer smooth integration between Radware products and FastNetMon - [MongoDB integration with FastNetMon Advanced](https://fastnetmon.com/docs-fnm-advanced/mongodb-integration-with-fastnetmon-advanced/) - FastNetMon Advanced relies on MongoDB for configuration storage. It does not store traffic here or metrics, but it stores every configuration option. MongoDB is crucial for FastNetMon to function properly. FastNetMon uses upstream version of MongoDB from official site. By default, both the FastNetMon daemon and the fcli command line tool connect directly to MongoDB. - [FastNetMon Advanced integration with Path.net DDoS scrubbing centre](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-integration-with-path-net-ddos-scrubbing-centre/) - FastNetMon Advanced offers complete, production-ready integration with the cloud DDoS scrubbing service provided by Path.net. To use this capability, you will need a username and a password for their API. Please check that your version of FastNetMon is 2.0.357 or newer. How does FastNetMon scrubbing centre diversion automation work? When FastNetMon detects an attack against - [FastNetMon Advanced InfluxDB integration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-influxdb-integration/) - Warning: Please note that new versions of FastNetMon Advanced do not use InfluxDB. It was replaced by Clickhouse, which is more flexible and reliable. You still can use it for existing installations, but we do not recommend using it for new installations. Introduction FastNetMon has very solid and extensive support for exporting metrics and alerts - [Per interface counters](https://fastnetmon.com/docs-fnm-advanced/per-interface-counters/) - FastNetMon Advanced (from version 2.0.350) can calculate per interface bandwidth and packet rate using Netflow, IPFIX or sFlow as a source of data without any use of SNMP technology. To enable this logic, you need to use the following option: sudo fcli set main enable_interface_counters true sudo fcli commit After that, you will be able - [Traffic Metrics in ClickHouse](https://fastnetmon.com/docs-fnm-advanced/traffic-metrics-in-clickhouse/) - In this guide we describe how you could enable traffic counters export to Clickhouse - [FastNetMon attack notification in Grafana via InfluxDB](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-attack-notification-in-grafana/) - This guide tells you how to enable attack notification in FastNetMon if you are using Grafana. - [InfluxDB data retention configuration](https://fastnetmon.com/docs-fnm-advanced/influxdb-data-retention-configuration/) - This guide tells you about configuration for InfluxDB data and FastNetMon. - [FastNetMon per protocol traffic counters in InfluxDB](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-per-protocol-traffic-counters/) - Guide about detailed traffic metrics available in FastNetMon - [Traffic export to InfluxDB using Kafka](https://fastnetmon.com/docs-fnm-advanced/traffic-export-to-influxdb-using-kafka/) - In this guide you can find all information about using Kafka queue for metrics export from FastNetMon to InfluxDB - [JunOS BGP configuration](https://fastnetmon.com/docs-fnm-advanced/junos-bgp-configuration/) - In this guide, we will provide a detailed guide which will help you establish a BGP session between FastNetMon and JunOS / Juniper network devices. To apply commands which alter the configuration of a router, you need to be in JunOS CLI, in configure mode. To switch JunOS CLI into configure mode, you need to - [FRR BGP configuration with FastNetMon](https://fastnetmon.com/docs-fnm-advanced/frr-bgp-configuration-with-fastnetmon/) - In this guide, we will provide a detailed guide which will help you establish a BGP session between FastNetMon and FRR. FRR is a network routing toolkit which includes support for many routing protocols. In this guide, we will work only with the BGP protocol, and we will use Ubuntu as the platform. The very - [FastNetMon BGP Peering session setup](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-bgp-peering-session-setup/) - In this guide, we will configure a BGP peering session between your network equipment and FastNetMon. For this manual, you need to configure a BGP peering connection from your router side, and you need to know all the following data: Peering IP for FastNetMon ASN for FastNetMon Router’s IP Router’s ASN Please do not redistribute - [Country lockdown capability](https://fastnetmon.com/docs-fnm-advanced/country-lockdown-capability/) - In addition to the capability to inject IP feeds to BGP routing table to block them, we provide the capability to block certain countries from reaching the service. Please note that this approach can be used only for compliance reasons in regulated industries where you're certain you do not have legitimate users in the blocked - [FastNetMon BGP IPv6 Blackhole unicast configuration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-ipv6-bgp-configuration/) - FastNetMon BGP IPv6 Blackhole unicast configuration - [Selective BGP blackhole or traffic diversion in FastNetMon Advanced](https://fastnetmon.com/docs-fnm-advanced/selective-bgp-blackhole-or-traffic-diversion-in-fastnetmon-advanced/) - This guide describes options to announce /32 or /24 for different host groups - [Escalation script for FastNetMon Advanced](https://fastnetmon.com/docs-fnm-advanced/escalation-script-for-fastnetmon-advanced/) - Example implementation of escalation rules for FastNetMon - [FastNetMon BGP IPv4 Blackhole unicast configuration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-bgp-unicast-configuration/) - Guide covers BGP Unicast mode configuration in details - [Automated BGP Feed injection](https://fastnetmon.com/docs-fnm-advanced/automated-bgp-feed-injection/) - We offer solution to automatically retrieve external data stream and create BGP announces from it - [Mikrotik BGP configuration](https://fastnetmon.com/docs-fnm-advanced/mikrotik-bgp-configuration/) - In this guide we will show detailed setup process for Mikrotik - [FastNetMon Advanced per-host hostgroups](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-per-host-hostgroups/) - On this page, you will learn about the options to set custom per-host thresholds for specific IPv4 or IPv6 prefixes in your networks. By default, FastNetMon uses the same thresholds for all hosts in your network. They're configured using a special hostgroup with the name "global". It's special in a way that it includes all - [FastNetMon Advanced BGP Blackhole automation](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-bgp-blackhole-automation/) - Automate your BGP Blackhole Automation with FastNetMon. Instantly detect DDoS attacks and trigger BGP announcements to block traffic or divert to scrubbing. - [Per direction hostgroup thresholds](https://fastnetmon.com/docs-fnm-advanced/per-direction-hostgroup-thresholds/) - Early versions of FastNetMon Advanced used the same thresholds for incoming and outgoing traffic, which wasn't optimal behaviour for all customers. Starting from version 2.0.313, we added an option to use different thresholds for incoming and outgoing traffic. This behaviour is controlled using the following flag, and you may check the current configuration for it - [Automated baseline calculation with FastNetMon Advanced](https://fastnetmon.com/docs-fnm-advanced/automated-baseline-calculation-with-fastnetmon-advanced/) - To configure thresholds in FastNetMon correctly, you need to know peak traffic values during peacetime for all the hosts in your network. To simplify this process, FastNetMon includes the capability to show you peak traffic levels for all types of standard fixed thresholds available in FastNetMon. To use this feature, you need to enable traffic - [FastNetMon Advanced BGP mitigation modes](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-bgp-mitigation-modes/) - This article describes differences between BGP Unicast and BGP Flow spec modes in FastNetMon - [Per hostgroup thresholds](https://fastnetmon.com/docs-fnm-advanced/per-hostgroup-thresholds/) - In this article we will show you options to calculate total traffic per hostgroup in FastNetMon - [Attack detection for per hostgroup thresholds](https://fastnetmon.com/docs-fnm-advanced/attack-detection-for-per-hostgroup-thresholds/) - In this guide we will provide detailed instructions about per hostgroup attack detection - [Traffic buffer capability to speed up attack detection](https://fastnetmon.com/docs-fnm-advanced/traffic-buffer-capability-to-speed-up-attack-detection-speed/) - We've introduced a traffic buffer, storing every single packet received by FastNetMon in a very efficient storage. When FastNetMon detects an attack (when a host crosses a threshold), we use a traffic buffer to retrieve all flows or packets arriving in the network before attack detection. This way, we can immediately trigger a blackhole or - [FastNetMon VyOS sFlow v5 configuration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-vyos-sflow-v5-configuration/) - In this guide we will help you with sFlow configuration on VyOS - [Port mirror or SPAN over GRE](https://fastnetmon.com/docs-fnm-advanced/port-mirror-or-span-over-gre/) - FastNetMon has extremely solid support for port mirror capture, but standard port mirror or SPAN are both complicated to operate without direct connectivity between FastNetMon and routers. In this case, a sampled or unsampled port mirror over GRE may be extremely helpful. You need to explicitly enable GRE unpacking when you can guarantee that your - [sFlow configuration on Cisco Nexus 9000 for FastNetMon Advanced](https://fastnetmon.com/docs-fnm-advanced/sflow-configuration-on-cisco-nexus-9000-for-fastnetmon-advanced/) - To enable sFlow on this switch, you need to make the following configuration changes: feature sflow sflow sampling-rate 4096 sflow max-sampled-size 128 sflow counter-poll-interval 20 sflow max-datagram-size 1400 sflow counter-poll-interval 30 sflow collector-ip vrf default sflow collector-port 6343 sflow agent-ip You may need to change "default" to "management" to alter VRF. Please check - [sFlow configuration for Extreme XOS](https://fastnetmon.com/docs/extreme/) - Example of sFlow configuration for Extreme - [FastNetMon sFlow v5 export from Linux](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-sflow-v5-export-from-linux/) - In this guide we provide detailed example how you can export traffic details from Linux - [FastNetMon Advanced AF_XDP support](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-af_xdp-support/) - In this article you can find all information about AF_XDP support in FastNetMon - [FastNetMon Advanced sFlow configuration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-sflow-configuration/) - This guide covers sFlow configuration for FastNetMon - [FastNetMon AF_PACKET port mirror configuration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-port-mirror-configuration/) - In this guide you will find all details to capture traffic directly from port using FastNetMon - [FastNetMon Flow](https://fastnetmon.com/docs-fnm-advanced/tera-flow/) - FastNetMon Flow is our own format for very high efficient flow representation which includes many improvements over existing flow protocols with main target to improve development experience and cross language support - [FastNetMon and Amazon VPC flow logs](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-and-amazon-vpc-flow-logs/) - FastNetMon can receive and process data from Amazon AWS VPC Flow logs - [FastNetMon and Google Compute GCE VPC Flow logs](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-and-google-compute-gce-vpc-flow-logs/) - Check this guide to find best options to integrate FastNetMon and GCE - [FastNetMon Netflow v9 configuration for Cisco ASR 1000](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-netflow-v9-configuration-for-cisco-asr-1000/) - We suggest the following configuration from ASR 1000 (including 1001-X) series of Cisco routers: flow record netflow_record_v4 match ipv4 tos match ipv4 protocol match ipv4 source address match ipv4 destination address match transport source-port match transport destination-port match interface input collect interface output collect counter bytes collect counter packets collect timestamp sys-uptime first collect timestamp - [Nokia Netflow v9 and IPFIX configuration for FastNetMon Advanced](https://fastnetmon.com/docs-fnm-advanced/nokia-netflow-v9-and-ipfix-configuration-for-fastnetmon-advanced/) - FastNetMon Advanced has complete support for both Netflow v9 and IPFIX telemetry protocols provided by Nokia SR. For all new deployments, we recommend using the IPFIX protocol. If you're looking for options to detect attacks in 1-3 seconds, please check the alternative traffic capture protocol supported by Nokia. To enable IPFIX support on Nokia SR, - [FastNetMon Advanced IPFIX configuration for A-10 Networks Thunder](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-ipfix-configuration-for-a-10-networks-thunder/) - To configure A10 Networks Thunder to work with FastNetMon, apply the following changes on A10 Networks side: netflow monitor fnm protocol v10 record nat44 destination 10.0.0.100 2055 flow-timeout 1 resend-template timeout 60 source-address ip 10.0.0.1 ! Unfortunately, flow timeout uses minutes and 60 seconds; it is the best flow timeout we can get. To specify - [App Packet SR Plugin](https://fastnetmon.com/docs-fnm-advanced/app-packet-sr-plugin/) - This plugin provides the capability to decode the format used by Nokia SR routers in their layer 3 encapsulated UDP shim-enabled port mirror format. You can use this capability starting from 2.0.357. We recommend checking official guides to learn more about it. You need to enable the plugin in the following way: sudo fcli set - [FastNetMon integration with TNSR high-performance router and VPN concentrator](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-integration-with-tnsr-high-performance-router-and-vpn-concentrator/) - Netgate® TNSR® is a high-performance router and VPN concentrator. This article provides detailed information on how to configure FastNetMon Advanced with TNSR software. TNSR overview TNSR software is a high-speed (exceeding 100 Gbps) virtual router and VPN concentrator. Businesses can deploy TNSR as a Netgate hardware appliance, Bare Metal Image, KVM and ESXi, or a - [FastNetMon Advanced Mikrotik configuration](https://fastnetmon.com/docs-fnm-advanced/mikrotik/) - FastNetMon Advanced and Mikrotik configuration using ssh - [FastNetMon Advanced configuration for NetFlow and IPFIX](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-configuration-for-netflow-and-ipfix/) - In this guide you can find all information about Netflow and IPFIX configuration for FastNetMon - [Juniper: handling jFlow/IPFIX export issues](https://fastnetmon.com/docs-fnm-advanced/juniper-handling-jflow-ipfix-export-issues/) - Complex issues with Juniper jFlow export - [Aggregation free Netflow and IPFIX with packet payload](https://fastnetmon.com/docs-fnm-advanced/netflow-lite-and-ipfix-inline-monitoring-services/) - This family of protocols can be called PSAMP, and it's well described in this RFC. It works by delivering truncated raw packet headers encoded in Netflow v9 or IPFIX formats to the collector. These protocols do not implement any aggregation at all. Hardware just randomly samples a packet, wraps it into an IPFIX / Netflow - [FastNetMon Connection tracking](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-connection-tracking/) - In addition to the capability to track the number of packets or bytes per second for a variety of traffic types (pre-defined and flexible), FastNetMon can calculate the number of incoming and outgoing flows per second for each IP address. This capability is enabled by default, and you can ensure that it's enabled this way: - [FastNetMon Advanced quick start](https://fastnetmon.com/docs-fnm-advanced/advanced-quick-start/) - FastNetMon Advanced - quick start. Full information about settings. - [Screenshots FastNetMon Advanced](https://fastnetmon.com/screenshoots-fastnetmon-advanced/) - Screenshots for FastNetMon Advanced DDos detection tool - [FastNetMon Advanced high availability setup](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-high-availability-setup/) - You can setup FastNetMon in high available way and this article covers multiple approaches - [FastNetMon Advanced deployment scenarios](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-deployment-scenarios/) - This article describes possible ways of deploying FastNetMon in your network - [FastNetMon multi PoP / Data Centre deployment options](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-multi-pop-data-centre-deployment-options/) - In case of large geographically distributed networks, you may have multiple options to run FastNetMon. The simplest option to deploy a single central instance of FastNetMon in a location which is well interconnected with all your remote PoPs and send network telemetry traffic to it. In this case, we recommend using private connectivity and encrypted - [Proxmox VM configuration for FastNetMon Advanced](https://fastnetmon.com/docs-fnm-advanced/proxmox-vm-configuration-for-fastnetmon-advanced/) - To use the Clickhouse-backed dashboard, your CPU needs to support SSE 4.2. To use the latest version of MongoDB, you need to have support for AVX1. Your host CPU may have complete support for both these technologies, but it may be explicitly disabled by Proxmox configuration. For example, it may look this way from your - [FastNetMon ssh shell](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-ssh-shell/) - Please note that this capability is experimental and can be subject to significant changes. FastNetMon Advanced provides the capability to expose the command line configuration tool fcli via the SSH protocol without using the system SSH server. Such an approach offers better security as it provides access only for FastNetMon specific configuration options and does - [FastNetMon Advanced manual install process on Ubuntu LTS](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-manual-install-process/) - In this guide we will provide all steps required to run FastNetMon - [Migration from Community edition to Advanced](https://fastnetmon.com/docs-fnm-advanced/migration-from-community-edition-to-advanced/) - You can follow this guide if you need migration from community edition to advanced - [Manual installation FastNetMon Advanced on Google Compute Engine](https://fastnetmon.com/docs-fnm-advanced/installing-fastnetmon-advanced-on-google-compute-engine/) - This guide will help you with installing FastNetMon on Google Compute Engine - [Amazon AWS Network Traffic Monitoring with FastNetMon](https://fastnetmon.com/aws-network-analytics/) - Unlock powerful AWS Network Analytics with automatic internal-to-external IP rewriting. Effortlessly monitor traffic, gain deep insights, and filter threats. - [Blocklist-Based Filtering with FastNetMon](https://fastnetmon.com/blocklist-filtering/) - Filter malicious traffic and create blocklist with FastNetMon. DDoS Detection based on Blocklist Based Filtering with flexible and fast update of list of hosts. - [FastNetMon Blog: DDoS News & Network Security Insights](https://fastnetmon.com/blog/) - FastNetMon Blog delivers expert DDoS news and network security insights. Stay ahead of evolving threats with research for network engineers. - [Add-ons](https://fastnetmon.com/addons/) - Extensions for FastNetMon, we have different types of extension: notification, filtering and API integrations. - [FastNetMon subscription upgrade process](https://fastnetmon.com/fastnetmon-subscription-upgrade-process/) - FastNetMon Subscription upgrade guide - [About FastNetMon](https://fastnetmon.com/about-the-company/) - Protect your network with FastNetMon. We provide fast, accurate DDoS detection and mitigation for service providers and enterprises. Secure your data today. - [FastNetMon Advanced installer configuration options reference](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-installer-configuration-options-reference/) - This document lists all supported command-line options for the FastNetMon installer binary Installation and upgrade options upgrade_fastnetmon_advanced - upgrade FastNetMon Advanced and exit developer_version - use developer build (latest build from developer branch) for FastNetMon Advanced installation do_not_install_fastnetmon - skip FastNetMon core installation during main install flow, used for preparing testing / developer environment do_not_add_repositories - [FastNetMon API user control](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-api-user-control/) - FastNetMon offers a granular access control system which allows you to have multiple API users with different access levels. This capability is available from 2.0.368. To create a new user, you can use the following command: sudo fcli set user support Then you need to set a password for it, please use single quotes to - [FastNetMon Advanced and Bison router integration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-and-bison-router-integration/) - FastNetMon Advanced has complete support for BGP Flow Spec based mitigation mode when FastNetMon detects malicious patterns and generates filtering rules to filter them out. Bison router does not support native BGP Flow Spec protocol yet but we have an option to add / remove ACLs via SSH automatically To start you need to fully - [FastNetMon Advanced callback scripts](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-callback-scripts/) - FastNetMon Advanced has capability to run scripts implemented in different programming languages when it detects attack against IP or hostgroup or identifies malicious pattern (BGP Flow Spec mode). In addition it can report information ongoing attacks using attack status capability By default FastNetMon passes information about attack in JSON format to script's standard input (stdin). - [Customer Stories](https://fastnetmon.com/publications/) - Internet media sites are writing about us. You can find a lot of interesting information about our tool from users who use it. - [FastNetMon Advanced and Mikrotik route management integration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-and-mikrotik-route-management-integration/) - Starting from RouterOS v7.1beta4, Mikrotik has support for REST API, which can be used by FastNetMon to create or remove routes (typically blackholes) without using BGP. Before beginning this guide, please read the official Mikrotik guide and enable the www or www-ssl service on Mikrotik. To enable this capability, please upgrade FastNetMon to version 2.0.359 - [FastNetMon Advanced and VyOS route management integration](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-and-vyos-route-management-integration/) - You can integrate FastNetMon Advanced with VyOS using their official API (available starting version 1.2.x). This integration allows FastNetMon to create or remove routes (blackholes) without using BGP. To enable this capability, please upgrade FastNetMon to version 2.0.359 or more recent. To start, you need to create an API Key on VyOS: set service https - [Network Traffic Visibility with FastNetMon](https://fastnetmon.com/traffic-visibility/) - Network traffic visibility is essential to protect your business operations and defend against cyber threats. Learn why it's important, the benefits it provides, and how to improve it with FastNetMon's DDoS detection. - [Compare Community and Advanced editions](https://fastnetmon.com/compare-community-and-advanced/) - Compare Community and Advanced editions. Discover why Advanced is the production-ready choice for large networks, while Community is best for labs and tests. - [FastNetMon Newsletter: Network Engineering Community News](https://fastnetmon.com/newsletter/) - FastNetMon Newsletter: Network Engineering Community News Home ‣ FastNetMon Newsletter: Network Engineering Community News Welcome to the archive of the FastNetMon Network Engineering Community News: a monthly newsletter covering notable network incidents, DDoS trends, industry developments, and updates from the FastNetMon team, including product news and events we attend. Stay up to date: Subscribe via - [DDoS Scrubbing Centre Diversion Automation](https://fastnetmon.com/ddos-scrubbing-centre-diversion/) - Streamline your defense with DDoS scrubbing automation. FastNetMon uses BGP diversion to instantly reroute malicious traffic, ensuring rapid protection. - [BGP Flow Spec DDoS Mitigation with FastNetMon](https://fastnetmon.com/bgp-flow-spec-ddos-mitigation/) - Automate your defense with BGP Flow Spec DDoS Mitigation. FastNetMon's real-time detection applies filtering rules, stopping DDoS attacks without blackholing. - [FastNetMon Advanced](https://fastnetmon.com/fastnetmon-advanced/) - It has big number of improvements, options and could detect DDoS with great attention to each packet - [Cookie Policy](https://fastnetmon.com/cookie-policy/) - The rules link with cookie policy. - [FastNetMon Brand Kit](https://fastnetmon.com/fastnetmon-brand-kit/) - Here you’ll find FastNetMon’s official logos, colours, and visual assets for use in media, partner materials and collaborations. Please use these resources to represent our brand consistently.For any questions about usage or additional formats, please contact media@fastnetmon.com. FastNetMon logos Web (raster) Full colour logo (PNG) Symbol - bolt (PNG) Vector (scalable) Full colour logo (vector - [BGP Blackhole (RTBH) DDoS Mitigation with FastNetMon](https://fastnetmon.com/bgp-blackhole-automation/) - Protect your network using BGP BlackHole Automation. Flexible configuration of traffic blocking, easy set up on your network, fast detection of attacks, integration with Cloud DDoS Scrubbing Centre. - [IP Infusion OcNOS sFlow v5 configuration with FastNetMon Advanced](https://fastnetmon.com/docs-fnm-advanced/ip-infusion-ocnos-sflow-v5-configuration-with-fastnetmon-advanced/) - To configure sFlow v5 on IP Infusion OcNOS you need to apply following options First of all you need to enable sFlow v5 globally: feature sflow sflow agent-ip [Local IP of router to send sFlow from] sflow collector [FastNetMon IP] port 6393 receiver-time-out 100 max-datagram-size 1400 vrf default Then you need to enable it for - [Cisco ASR 9000 sFlow configuration for FastNetMon Advanced](https://fastnetmon.com/docs-fnm-advanced/cisco-asr-9000-sflow-configuration-for-fastnetmon-advanced/) - To configure sFlow v5 on Cisco ASR 9000 platform please apply following configuration: flow exporter-map SFLOW-EXP-MAP version sflow v5 ! transport udp 6343 source Loopback0 destination [FastNetMon IP] ! flow monitor-map SFLOW-MON-MAP record sflow exporter SFLOW-EXP-MAP ! sampler-map SFLOW-SAMP-MAP random 1 out-of 1000 Then enable it for all upstream facing interfaces: interface TenGigE0/X/X/X flow datalinkframesection - [FastNetMon Engineer Community](https://fastnetmon.com/fastnetmon-engineer-community/) - A space for operator-to-operator DDoS knowledge exchange The FastNetMon Engineer Community is a space for network engineers and security practitioners to discuss DDoS detection, mitigation, and day-to-day operational challenges. The focus is practical: peer-to-peer support, sharing real-world experience, and helping each other solve problems faster. Many members use it as a place to ask quick - [Contact us](https://fastnetmon.com/contact/) - Information about our company - FastNetMon: our contacts and address. - [FastNetMon Advanced free trial](https://fastnetmon.com/trial/) - Order your trial now After submitting the trial order form, you will receivethe instructions to install via email. By submitting thisform, you accept our privacy policy and terms and conditions. FastNetMon Advanced 30-day free trial Join thousands of network professionals protecting their networks with FastNetMon! No credit card required. With your trial you get: Ultra-fast - [Juniper EX and QFX sFlow v5 configuration for FastNetMon Advanced](https://fastnetmon.com/docs-fnm-advanced/juniper-ex-and-qfx-sflow-v5-configuration-for-fastnetmon-advanced/) - To enable sFlow v5 on Juniper EX or QFX you need to apply initial configuration for sFlow v5 agent on switch: set protocols sflow polling-interval 30 set protocols sflow sample-rate ingress 1000 set protocols sflow sample-rate egress 1000 set protocols sflow source-ip [Local IP to send sFlow from your switch] set protocols sflow collector [FastNetMon - [FastNetMon Automated DDoS Detection](https://fastnetmon.com/ddos-detection-and-mitigation/) - Reliable and automated DDoS Detection and Prevention helps you to keep your network safe from attacks. The tool's integrated quick and easy with any vendors. - [FastNetMon - Flexible and Powerful Embeddable Solutions for Your DDoS Detection Systems](https://fastnetmon.com/embeddable-solutions/) - Reliable DDoS Detection and Mitigation with deploying on SBCs, Raspberry Pi, ROCK Pi, ESPRESSObin, MACCHIATObin, etc. Get Full Free trial to try it! - [Payment Methods](https://fastnetmon.com/payment/) - The ways which you can use for pay. - [FastNetMon for Google Cloud](https://fastnetmon.com/google-cloud-network/) - Try FastNetMon for detecting DDoS attack and analytics on Google Cloud. Optimize your traffic on the cloud and filter it to stop suspicious activity. Flexible set up on your network. - [Resources](https://fastnetmon.com/resources/) - Read different media sources about project. You can find a lot of useful advises and testimonials from our partners. - [FastNetMon Advanced integration with GCore Global DDoS protection scrubbing centre](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-integration-with-gcore-global-ddos-protection-scrubbing-centre/) - FastNetMon Advanced offers a complete, production-ready integration with GCore Global DDoS protection service. Please check that your version of FastNetMon is 2.0.373 or newer. To use this capability, please create an API access key in your portal this way: How FastNetMon scrubbing centre diversion work? When FastNetMon detects an attack against an IP address, it - [FastNetMon Community and ExaBGP without socat](https://fastnetmon.com/docs/fastnetmon-community-and-exabgp-without-socat/) - This guide describes experimental integration between FastNetMon and ExaBGP without socat tool - [FastNetMon community CLI and API](https://fastnetmon.com/docs/fastnetmon-community-api/) - FastNetMon community API. Full information about settings. - [FastNetMon Community edition Privacy Notice](https://fastnetmon.com/fastnetmon-community-edition-privacy-notice/) - fastnetmon-community-edition-privacy-notice-10-aug-2023Download - [Controlling ExaBGP from external tool](https://fastnetmon.com/docs/how-to-control-exabgp-from-external-tool/) - Full instruction how to control ExaBGP from external tool. How to configure it in your network. - [Graphite integration](https://fastnetmon.com/docs/graphite_integration/) - Graphite is a mature time series database. It could store very huge amount of data and retrieve it in a timely manner. - [Redis backend support](https://fastnetmon.com/docs/redis/) - Documentation: FastNetMaon and Redis backend - [FastNetMon Community GoBGP integration](https://fastnetmon.com/docs/gobgp-integration/) - GoBGP is an awesome implementation of BGP protocol in shiny Go language. It's very fast and has a lot of great options. - [Quagga BGP and exabgp: work together for BGP blackhole implementation](https://fastnetmon.com/docs/quagga-bgp-and-exabgp/) - Full instruction how you can setting your network for BGP blackhole implementation. - [Protocol names supported by FastNetMon Advanced](https://fastnetmon.com/docs-fnm-advanced/protocol-names-supported-by-fastnetmon-advanced/) - In all systems where a protocol name is needed in FastNetMon Advanced, we use the following protocol names based on up-to-date IANA documentation: hopopt 0 icmp 1 igmp 2 ggp 3 ipv4 4 st 5 tcp 6 cbt 7 egp 8 igp 9 bbn_rcc_mon 10 nvp_ii 11 pup 12 argus_deprecated 13 emcon 14 xnet 15 - [sFlow v5 configuration on Arista](https://fastnetmon.com/docs-fnm-advanced/sflow-v5-configuration-on-arista/) - To configure sFlow v5 on the Arista platform, we recommend usingthe following guide: show run section sflow sflow sample 1024 sflow polling-interval 60 sflow destination 10.0.0.70 sflow source 10.0.0.10 sflow sample input subinterface sflow sample output subinterface sflow run After this, you need to enable sFlow v5 monitoring for each interface: interface Port-Channel10 sflow enable - [FastNetMon Advanced simple average traffic calculation mode](https://fastnetmon.com/docs-fnm-advanced/fastnetmon-advanced-simple-average-traffic-calculation-mode/) - By default, FastNetMon Advanced uses exponential moving average algorithm to calculate bandwidth. In some cases, when routers send traffic telemetry in bursts or a stream of telemetry is not even, it may not provide the best accuracy, and you may notice 20-30% deviation from real traffic. Usually, it happens only with Netflow / IPFIX-based protocols. - [Requirements for integration with cloud-based DDoS scrubbing centers](https://fastnetmon.com/docs-fnm-advanced/requirements-for-integration-with-new-cloud-based-ddos-scrubbing-centers/) - FastNetMon has solid integrations with multiple leading DDoS mitigation cloud providers, and we are constantly working to add more providers. Our preferred integration method is API based integration where FastNetMon connects to the scrubbing centre API endpoint to announce/withdraw prefix under attack. API based integration eliminates the need to make adjustments to BGP policy configuration - [Podcast](https://fastnetmon.com/podcast/) - Listen to podcast with our team about FastNetMon DDoS Detection tool. Learn more about the story behind of the tool and the main secrets of using it. - [FastNetMon LTD subprocessors and subcontractors](https://fastnetmon.com/fastnetmon-ltd-subprocessors-and-subcontractors/) - We keep up to date list of all our subcontractors to be transparent about personal data processing ## Document Categories - [Deployment](https://fastnetmon.com/doc_category/deployment/) - [Introduction](https://fastnetmon.com/doc_category/introduction/) - [Capture engines](https://fastnetmon.com/doc_category/capture-engines/) - [Netflow and IPFIX](https://fastnetmon.com/doc_category/netflow-and-ipfix/) - [sFlow v5](https://fastnetmon.com/doc_category/sflow-v5/) - [Mitigation modes](https://fastnetmon.com/doc_category/mitigation-modes/) - [BGP](https://fastnetmon.com/doc_category/bgp/) - [Traffic reports](https://fastnetmon.com/doc_category/traffic-reports/) - [Attack actions](https://fastnetmon.com/doc_category/attack-actions/) - [Developer guides](https://fastnetmon.com/doc_category/developer-guides/) - [Maintenance operations](https://fastnetmon.com/doc_category/maintenance-operations/)