Skip to content
PEERYXNETWORK
Peeryx Defense Fabric · software for your infrastructure

DDoS mitigation software for your network.

You provide the servers and bandwidth. Defense Fabric provides detection, packet filtering and policy management, operated from your Peeryx panel.

14 days · Free trial, no port quota€350.00 · excl. tax / month

Local filtering uses your hardware and network capacity. Peeryx upstream capacity belongs to the separate protected transit service.

An aisle between server racks in a data center.
Illustrative photograph · Brett Sayles / Pexels
On your infrastructure
  1. Incoming traffic
  2. Your filtering servers
  3. Your services
How it works

Rules and telemetry in your client area

Incoming traffic
Your upstream links and routing
Your filtering servers
Defense Fabric applies your protection policies
Your services
Delivery of filtered traffic

Filtering path used continuously or after diversion. Deployment and return routing depend on your network.

DEFENSE FABRIC

Built for network operations

Detection and mitigation capacity deployed on your infrastructure.

Adaptive L3/L4 defense

Detect host attacks and distributed carpet bombing. Generate local BPF/JIT rules automatically, inspect them and exclude unsuitable signatures.

TCP validation and source limits

SYN proxy for a validated symmetric return path; SYN challenge for asymmetric routing. Configure UDP and SYN/SYNACK limits per source IP.

Protection by prefix and host

PPS detection thresholds, predefined profiles and /32 exceptions. Up to 20 post-filter firewall rules per protected prefix; larger allocations are managed as /24 blocks.

Routing under your control

iBGP diversion communities, optional BGP FlowSpec and last-resort RTBH. GRE/VXLAN routing designs require deployment validation.

Evidence you can use

Attack history, time-zone selection and private PCAP, ZIP and PDF exports. Inspect TTL, packet length, countries, ASNs and recorded mitigation rules.

Integrate and operate

Scoped API access, five-second live statistics and signed software updates from the panel. Available API operations are listed in the customer documentation.

Your infrastructure

One platform. Three ways to deploy.

Choose where traffic is filtered, then validate the forwarding path, failure behaviour and return route before carrying production traffic.

01

Permanent mitigation

Place the filtering server in the traffic path. Check the required interfaces, legitimate traffic and return routing. SYN proxy requires a validated symmetric path.

02

Automatic diversion

Your router sends selected attacked destinations to the filtering server through a validated BGP policy. Flow export, detection, convergence and the clean return path determine the response time.

03

Hybrid defense

Combine local filtering with protected Peeryx transit when upstream mitigation is needed. Transit delivery and routing policies require separate activation and validation.

Peeryx protected transit →

Conceptual diagram. Traffic paths and BGP policies must be validated for each deployment.

Your infrastructure

Automatic mitigation targets less than 5 seconds; FlowSpec generation targets less than 1 second after detection. Export timeouts, sampling, BGP convergence, hardware and the validated clean return path determine actual response time. These are qualification targets, not an unconditional SLA.

03 / AMD × MELLANOX

Size your filtering server

Reference platforms for qualification, from 10G to two 400G ports. Open a configuration to check its processor, memory and expansion requirements. A port speed does not establish filtering performance.

1 × 10G / 2 × 10G / 1 × 40GAMD Ryzen 9 5950X Theoretical ingress at 64 bytes14.88 / 29.76 / 59.52 Mpps Configuration details
Cores / threads
16 / 32
Memory
64 GB · 2 × 32 GB DDR4
Memory channels
2
Platform / CPU PCIe generation
AM4 · PCIe 4.0
Network adapter
ConnectX-4 / ConnectX-5
SSD / NVMe
450 GB
Measured filtering
No published result

Check the motherboard lane map: a physical ×16 slot may be wired at ×8 or share lanes. Keep packet workers and their memory close to the network adapter; qualify DDR5-6000 overclocking separately from the stock memory profile.

Manufacturer specifications · AMD ↗AM4 · DDR4 ↗
1 × 100GAMD Ryzen 9 7950X Theoretical ingress at 64 bytes148.81 Mpps Configuration details
Cores / threads
16 / 32
Memory
64 GB · 2 × 32 GB DDR5-6000
Memory channels
2
Platform / CPU PCIe generation
AM5 · PCIe 5.0
Network adapter
ConnectX-5 / ConnectX-6
SSD / NVMe
450 GB
Measured filtering
No published result

Check the motherboard lane map: a physical ×16 slot may be wired at ×8 or share lanes. Keep packet workers and their memory close to the network adapter; qualify DDR5-6000 overclocking separately from the stock memory profile.

Manufacturer specifications · AMD ↗
2 × 100GAMD Ryzen 9 9950X Theoretical ingress at 64 bytes297.62 Mpps Configuration details
Cores / threads
16 / 32
Memory
64 GB · 2 × 32 GB DDR5-6000
Memory channels
2
Platform / CPU PCIe generation
AM5 · PCIe 5.0
Network adapter
ConnectX-6 · 2 × 100G
SSD / NVMe
450 GB
Measured filtering
No published result

Check the motherboard lane map: a physical ×16 slot may be wired at ×8 or share lanes. Keep packet workers and their memory close to the network adapter; qualify DDR5-6000 overclocking separately from the stock memory profile.

Manufacturer specifications · AMD ↗
1 × 400GAMD Ryzen Threadripper 9970X Theoretical ingress at 64 bytes595.24 Mpps Configuration details
Cores / threads
32 / 64
Memory
128 GB · 4 × 32 GB DDR5 ECC RDIMM
Memory channels
4
Platform / CPU PCIe generation
TRX50 · PCIe 5.0
Network adapter
ConnectX-7 · 400GbE
SSD / NVMe
450 GB
Measured filtering
No published result

Populate all four memory channels and use a CPU-connected PCIe 5.0 ×16 slot for the 400G adapter. Verify card power, cooling and firmware. Core count alone does not establish a packet rate.

Manufacturer specifications · AMD ↗ NVIDIA ConnectX-7 ↗
2 × 400GAMD Ryzen Threadripper PRO 9995WX Theoretical ingress at 64 bytes1,190.48 Mpps Configuration details
Cores / threads
96 / 192
Memory
256 GB · 8 × 32 GB DDR5 ECC RDIMM
Memory channels
8
Platform / CPU PCIe generation
WRX90 · PCIe 5.0
Network adapter
2 × ConnectX-7 · 400GbE
SSD / NVMe
450 GB
Measured filtering
No published result

WRX90, all eight memory channels populated, and two separate CPU-connected PCIe 5.0 ×16 slots. Use two qualified 400GbE adapters. Check NUMA placement and traffic distribution; two ports do not guarantee 800G of filtered traffic.

Manufacturer specifications · AMD ↗ NVIDIA ConnectX-7 ↗

Ethernet line rate, including 8 bytes of preamble/SFD and 12 bytes of inter-frame gap. Aggregate ingress is not end-to-end filtering throughput or a software benchmark.

Anti-DDoS capacity planner ↗

Gbps ↔ Mpps calculator ↗

What has been measured?

No reproducible Defense Fabric benchmark is published for these reference platforms. The rates above describe Ethernet ingress only. A useful result must identify the hardware, traffic mix, enabled protection, duration, loss and latency.

Qualification objective

Agree the required traffic profile, packet rate and acceptable loss and latency before testing. Capacity is accepted from the measured result, within the physical ingress limit.

Qualify the complete traffic path

Record the exact server, adapter part number, BIOS, firmware and software version. Test 64-byte frames and a documented traffic mix, with the intended rules and mitigation enabled. Measure offered, forwarded and dropped packets, legitimate-traffic loss and latency, CPU use, recovery and failure behaviour. Run load tests on an isolated test network.

Memory

Ryzen AM5: matched 2 × 32 GB DDR5-6000, preferably CL30 or lower, EXPO only after stability validation. Ryzen 5950X: qualified DDR4 kit with compatible memory profile. Threadripper/EPYC: compatible ECC RDIMMs in every memory channel; platform specifications take precedence over EXPO or desktop timings.

Single-socket EPYC alternatives to qualify: 9355P (32 cores, 12 memory channels) for the 400G tier; 9655P (96 cores, 12 channels) for the 2 × 400G tier. Populate 12 channels, for example 12 × 16 GB or 12 × 32 GB. Equal core counts do not establish equal filtering performance.

Your infrastructure

At least 450 GB SSD/NVMe, TPM 2.0, supported x86-64 Linux, independent management access and outbound HTTPS licence renewal. Use CPU-connected PCIe slots, sufficient power and cooling. Hardware and router compatibility must be checked before purchase.

For 2 × 400G, plan two ConnectX-7 400G adapters in two CPU-connected PCIe 5.0 ×16 slots. Validate exact adapter part numbers, aggregate bandwidth, firmware and single-socket NUMA placement.

Convert Gbit/s to Mpps

See the packet rate a link can carry. This calculation describes Ethernet line rate; it does not predict Defense Fabric performance.

Theoretical packet rate148.81 Mpps

Mpps = Gbit/s × 1,000 ÷ ((frame bytes + 20) × 8). One direction; no extra encapsulation is added.

Monthly licence

Build your monthly licence

Start with the included capacity and add ports or features as your infrastructure grows.

DEFENSE FABRIC

Software licence

€350.00excl. tax / month

A licence includes one 10G port and detection, FlowSpec, sFlow and BGP features according to your configuration.

✓ 1 included 10G port✓ BPF / JIT · sFlow · FlowSpec · BGP✓ Peeryx technical support✓ 14 days · Free trial, no port quota

100 Mbps Peeryx IP transit is included, downstream allowed. Extra capacity is €1.50 excl. tax per Mbps.

Additional ports and options

Build your monthly licence

One licence shares its purchased ports across up to 128 managed servers. Each server needs its own port allocation; adding servers does not multiply the included 10G port.

Discount on additional ports: −10% from 5, −20% from 10 and −40% from 20.

Additional Peeryx transit

100 Mbps is included after network activation. Additional commit is €1.50 excl. tax per Mbps/month. This is the Fabric offer, separate from the protected transit price bands.

Configure my trial

The trial button carries your port and Game choices to the customer area. Extra transit is configured separately after the routing review.

Request a technical review →

Send your estimate with the server models, network adapters, available bandwidth and intended deployment mode.

Prepare your deployment

Prerequisites, installation, BGP, telemetry, TCP protection, updates and recovery tests: read the guide before connecting your traffic.

Read the technical documentation → Compare DDoS solutions →
FAQ

Clear answers, before deployment.

Servers

One 10G port is included per licence. Purchased ports are shared across the servers; they are not duplicated for each installation.

Each server has its own identity and settings. Adding a server does not restart the trial or purchase extra ports.

Do I need Peeryx transit?

Defense Fabric is separate from Peeryx protected IP transit. You may use either service or both.

Does the trial limit my ports?

During the 14-day trial, the licence has no software quota for port count or declared port speed. Your server and its physical links remain the real limit.

How do I start deployment?

The panel separates licensing, telemetry and routing policy. You decide where traffic is filtered; technical validation keeps the handoff controlled before production activation.

Evidence you can use

PCAP contains up to 1,000 reconstructed sampled packets: headers and a limited payload prefix. Timestamps and missing payload bytes are reconstructed; this is not a full wire capture.

Artifacts: 30 days. History: 90 days. Per-server storage limits apply.

Keep control of your infrastructure. Add Peeryx capacity when you need it.

Create your customer account, configure the trial and choose the architecture that fits your network. The panel guides the technical handoff step by step.

Configure my trial ↗