BGP FlowSpec
Use your own router to tell our network which traffic to drop or rate limit. FlowSpec carries those instructions over BGP, so filtering can take place before the traffic reaches your connection.
You control the match conditions and can announce or withdraw rules as your requirements change.
Match conditions and actions
Choose the traffic you want the rule to match, then set whether matching packets should be dropped or rate limited.
Match conditions
- IP addresses
- Source and destination prefixes
- Protocol
- IP protocol, such as TCP or UDP
- Ports
- Source and destination ports
- Packet properties
- Packet length and TCP flags
Actions
Discard
Drop packets that match the rule.
Rate-limit
Limit the rate of matching traffic.
Supported matches and actions depend on the router platform. Our NOC can confirm the options for your connection.
How the rules reach our routers
Your router sends the match conditions and action as a FlowSpec route. Once SMARTNET accepts the rule, our routers apply it to matching packets.
BGP can distribute that rule to several routers, saving a separate ACL change on each device.
Read the FlowSpec technical referenceFlowSpec and SmartMitigate
FlowSpec works well when an attack has a pattern you can describe with addresses, ports or packet properties.
Use SmartMitigate for the additional connection and protocol checks, including TCP and UDP authentication and validation of game and voice traffic.
SmartMitigate DDoS protection