Skip to content
PEERYXNETWORK
Product releasePEERYX FLOW COLLECTOR · 1.1

Peeryx Flow Collector: let your network call for protection

A free collector that connects sFlow, NetStream and IPFIX measurements to Peeryx on-demand DDoS protection. Choose the thresholds and prefixes that fit your network.

Open Peeryx Flow Collector
A cyan traffic path bypasses a disturbed area while a separate instrument observes a few measurements.
Concept illustration
Linux · x86-64 / ARM64sFlow · NetStream · IPFIXIPv4 /24

An attack does not start with a support ticket. It starts with a rising graph, a filling link and then customers calling. If you run your own network, you probably already have the measurements. The missing piece is often the connection between those measurements and the decision to send traffic through external protection.

Peeryx Flow Collector makes that connection. Installed on your network, it reads your router’s exports, tracks traffic to your /24s and can trigger diversion to Peeryx under rules you choose. The software is available as a free download today.

For the people who operate the network

The collector is designed for operators, hosting providers, datacenters and businesses that manage their BGP announcements and want to retain their usual providers outside an attack. It also suits sites already exporting sFlow or NetStream without an integrated diversion mechanism.

It is optional. If your traffic already passes through Peeryx permanently, or your existing detector is integrated, you do not need to install it. The software download is free; Peeryx network service and protection remain part of your service plan.

Keep your everyday providers. Bring in Peeryx when the measurements call for it.

Measurements at your site. Filtering at Peeryx.

Your router sends measurements to the collector, which estimates bandwidth and packet rates per prefix. It sits outside the customer traffic path. An attack of tens of Gbit/s therefore does not pass through the Ethernet port of the collector VM.

After a confirmed breach, diversion proceeds in stages: announce the /24 through Peeryx, verify the announcement and clean-traffic delivery path, then withdraw the competing announcements covered by the BGP policies. Recovery restores the usual providers before withdrawing Peeryx. This sequence must be validated against your topology, including any other router originating the same prefix.

Measurements branch off a continuing traffic stream: customer traffic does not pass through the collector.
Concept illustrationMeasurements branch off a continuing traffic stream: customer traffic does not pass through the collector.

Thresholds you can explain

Set TCP, UDP, ICMP, GRE, IPIP and Other limits in packets per second or Gbit/s. A total IPv4 traffic rule, called L3, can trigger on combined traffic across all protocols. Other covers protocols outside the five named categories. Advanced TCP flag settings are also available.

Any enabled rule can trigger diversion. An exclusive total-bandwidth override for an individual prefix can replace the general thresholds. Prepare settings in the client portal, then apply the exported configuration file on the collector. Set thresholds against normal busy-hour traffic: high volume alone is not proof of an attack.

You also choose the minimum time on Peeryx: 20 minutes to 7 days after full diversion is confirmed. An ongoing attack extends protection. Recovery waits for fresh measurements showing the attack has cleared; a delivery-path or monitoring failure may require an earlier return to preserve connectivity.

A Linux VM, not a scrubbing server

The current version supports Debian 12 or 13 and Ubuntu Server 24.04 LTS with systemd, on x86-64 or ARM64. A recommended starting point is 2 CPU cores, 8 GB RAM, 20 GB free disk and a 1 Gbit/s Ethernet port. A small Xeon or comparable VM is a practical starting size; capacity depends on the exported measurement volume.

Supported formats are sFlow v5, NetFlow/NetStream v5 and v9, and IPv4 IPFIX. The guide covers ports, sampling rates and export freshness requirements. Stale measurements, or counting the same traffic on multiple interfaces, undermine reliable detection.

New prefixes follow the network

The collector discovers public IPv4 /24s advertised by your router over BGP within your service’s authorized ranges. There is no fixed ten-prefix list in the software. New allocations outside those ranges need authorization first, and router policies must also permit their protection.

This version operates at /24 granularity: it does not automatically split larger announcements or control IPv6 diversion. Discovering a prefix and validating its protection path are separate steps.

Observe first, then enable

Open Services → Peeryx Flow Collector in the client portal and select the network service. The guide walks through preparing Linux, downloading the installer, pairing the collector and configuring router exports. This section appears for accounts with an eligible network service.

The collector starts in observation mode. Check measurements, tune thresholds and work with our team to validate the Peeryx announcement, withdrawal from other providers, clean-traffic delivery and recovery to normal routing. Enable automation after those checks, with settings you understand and a protection path you have verified.

Your guide and settings, together.

Open Peeryx Flow Collector

Free software · Network service required for protection