sales@as203446.net

BGP FlowSpec

Use your own router to tell our network which traffic to drop or rate limit. FlowSpec carries those instructions over BGP, so filtering can take place before the traffic reaches your connection.

You control the match conditions and can announce or withdraw rules as your requirements change.

Match conditions and actions

Choose the traffic you want the rule to match, then set whether matching packets should be dropped or rate limited.

Match conditions

IP addresses
Source and destination prefixes
Protocol
IP protocol, such as TCP or UDP
Ports
Source and destination ports
Packet properties
Packet length and TCP flags

Actions

Discard

Drop packets that match the rule.

Rate-limit

Limit the rate of matching traffic.

Supported matches and actions depend on the router platform. Our NOC can confirm the options for your connection.

How the rules reach our routers

Your router sends the match conditions and action as a FlowSpec route. Once SMARTNET accepts the rule, our routers apply it to matching packets.

BGP can distribute that rule to several routers, saving a separate ACL change on each device.

Read the FlowSpec technical reference

FlowSpec and SmartMitigate

FlowSpec works well when an attack has a pattern you can describe with addresses, ports or packet properties.

Use SmartMitigate for the additional connection and protocol checks, including TCP and UDP authentication and validation of game and voice traffic.

SmartMitigate DDoS protection

Set up FlowSpec

Contact SMARTNET

Contact

Contact sales