Adaptive L3/L4 defense
Detect host attacks and distributed carpet bombing. Generate local BPF/JIT rules automatically, inspect them and exclude unsuitable signatures.
You provide the servers and bandwidth. Defense Fabric provides detection, packet filtering and policy management, operated from your Peeryx panel.
Local filtering uses your hardware and network capacity. Peeryx upstream capacity belongs to the separate protected transit service.

Rules and telemetry in your client area
Filtering path used continuously or after diversion. Deployment and return routing depend on your network.
Detection and mitigation capacity deployed on your infrastructure.
Detect host attacks and distributed carpet bombing. Generate local BPF/JIT rules automatically, inspect them and exclude unsuitable signatures.
SYN proxy for a validated symmetric return path; SYN challenge for asymmetric routing. Configure UDP and SYN/SYNACK limits per source IP.
PPS detection thresholds, predefined profiles and /32 exceptions. Up to 20 post-filter firewall rules per protected prefix; larger allocations are managed as /24 blocks.
iBGP diversion communities, optional BGP FlowSpec and last-resort RTBH. GRE/VXLAN routing designs require deployment validation.
Attack history, time-zone selection and private PCAP, ZIP and PDF exports. Inspect TTL, packet length, countries, ASNs and recorded mitigation rules.
Scoped API access, five-second live statistics and signed software updates from the panel. Available API operations are listed in the customer documentation.
Choose where traffic is filtered, then validate the forwarding path, failure behaviour and return route before carrying production traffic.
Place the filtering server in the traffic path. Check the required interfaces, legitimate traffic and return routing. SYN proxy requires a validated symmetric path.
Your router sends selected attacked destinations to the filtering server through a validated BGP policy. Flow export, detection, convergence and the clean return path determine the response time.
Combine local filtering with protected Peeryx transit when upstream mitigation is needed. Transit delivery and routing policies require separate activation and validation.
Peeryx protected transit →Conceptual diagram. Traffic paths and BGP policies must be validated for each deployment.
Automatic mitigation targets less than 5 seconds; FlowSpec generation targets less than 1 second after detection. Export timeouts, sampling, BGP convergence, hardware and the validated clean return path determine actual response time. These are qualification targets, not an unconditional SLA.
Reference platforms for qualification, from 10G to two 400G ports. Open a configuration to check its processor, memory and expansion requirements. A port speed does not establish filtering performance.
Check the motherboard lane map: a physical ×16 slot may be wired at ×8 or share lanes. Keep packet workers and their memory close to the network adapter; qualify DDR5-6000 overclocking separately from the stock memory profile.
Manufacturer specifications · AMD ↗AM4 · DDR4 ↗Check the motherboard lane map: a physical ×16 slot may be wired at ×8 or share lanes. Keep packet workers and their memory close to the network adapter; qualify DDR5-6000 overclocking separately from the stock memory profile.
Manufacturer specifications · AMD ↗Check the motherboard lane map: a physical ×16 slot may be wired at ×8 or share lanes. Keep packet workers and their memory close to the network adapter; qualify DDR5-6000 overclocking separately from the stock memory profile.
Manufacturer specifications · AMD ↗Populate all four memory channels and use a CPU-connected PCIe 5.0 ×16 slot for the 400G adapter. Verify card power, cooling and firmware. Core count alone does not establish a packet rate.
Manufacturer specifications · AMD ↗ NVIDIA ConnectX-7 ↗WRX90, all eight memory channels populated, and two separate CPU-connected PCIe 5.0 ×16 slots. Use two qualified 400GbE adapters. Check NUMA placement and traffic distribution; two ports do not guarantee 800G of filtered traffic.
Manufacturer specifications · AMD ↗ NVIDIA ConnectX-7 ↗Ethernet line rate, including 8 bytes of preamble/SFD and 12 bytes of inter-frame gap. Aggregate ingress is not end-to-end filtering throughput or a software benchmark.
No reproducible Defense Fabric benchmark is published for these reference platforms. The rates above describe Ethernet ingress only. A useful result must identify the hardware, traffic mix, enabled protection, duration, loss and latency.
Agree the required traffic profile, packet rate and acceptable loss and latency before testing. Capacity is accepted from the measured result, within the physical ingress limit.
Record the exact server, adapter part number, BIOS, firmware and software version. Test 64-byte frames and a documented traffic mix, with the intended rules and mitigation enabled. Measure offered, forwarded and dropped packets, legitimate-traffic loss and latency, CPU use, recovery and failure behaviour. Run load tests on an isolated test network.
Ryzen AM5: matched 2 × 32 GB DDR5-6000, preferably CL30 or lower, EXPO only after stability validation. Ryzen 5950X: qualified DDR4 kit with compatible memory profile. Threadripper/EPYC: compatible ECC RDIMMs in every memory channel; platform specifications take precedence over EXPO or desktop timings.
Single-socket EPYC alternatives to qualify: 9355P (32 cores, 12 memory channels) for the 400G tier; 9655P (96 cores, 12 channels) for the 2 × 400G tier. Populate 12 channels, for example 12 × 16 GB or 12 × 32 GB. Equal core counts do not establish equal filtering performance.
At least 450 GB SSD/NVMe, TPM 2.0, supported x86-64 Linux, independent management access and outbound HTTPS licence renewal. Use CPU-connected PCIe slots, sufficient power and cooling. Hardware and router compatibility must be checked before purchase.
For 2 × 400G, plan two ConnectX-7 400G adapters in two CPU-connected PCIe 5.0 ×16 slots. Validate exact adapter part numbers, aggregate bandwidth, firmware and single-socket NUMA placement.
See the packet rate a link can carry. This calculation describes Ethernet line rate; it does not predict Defense Fabric performance.
Mpps = Gbit/s × 1,000 ÷ ((frame bytes + 20) × 8). One direction; no extra encapsulation is added.
Start with the included capacity and add ports or features as your infrastructure grows.
A licence includes one 10G port and detection, FlowSpec, sFlow and BGP features according to your configuration.
100 Mbps Peeryx IP transit is included, downstream allowed. Extra capacity is €1.50 excl. tax per Mbps.
Prerequisites, installation, BGP, telemetry, TCP protection, updates and recovery tests: read the guide before connecting your traffic.
Read the technical documentation → Compare DDoS solutions →One 10G port is included per licence. Purchased ports are shared across the servers; they are not duplicated for each installation.
Each server has its own identity and settings. Adding a server does not restart the trial or purchase extra ports.
Defense Fabric is separate from Peeryx protected IP transit. You may use either service or both.
During the 14-day trial, the licence has no software quota for port count or declared port speed. Your server and its physical links remain the real limit.
The panel separates licensing, telemetry and routing policy. You decide where traffic is filtered; technical validation keeps the handoff controlled before production activation.
PCAP contains up to 1,000 reconstructed sampled packets: headers and a limited payload prefix. Timestamps and missing payload bytes are reconstructed; this is not a full wire capture.
Artifacts: 30 days. History: 90 days. Per-server storage limits apply.
Create your customer account, configure the trial and choose the architecture that fits your network. The panel guides the technical handoff step by step.
Configure my trial ↗Already a customer? Sign in