Skip to content
PEERYXNETWORK

Deployment and purchasing guide

Compare the complete DDoS deployment

Start with where packets are filtered, then compare the equipment, licences and operating work required. A collector, a router rule and a scrubbing server perform different jobs.

Choose a solution to compare

Choose the enforcement point first

Keep filtering on your servers

Include the packet-processing engine, NICs, server resources, a clean return path and a tested failure design. Owning the server does not remove the need for upstream capacity.

Enforce rules on your routers

Check FlowSpec matching and action support, hardware rule limits, validation and withdrawal. A detector that sends rules is distinct from the router that applies them.

Move large attacks upstream

Include the scrubbing provider, prefix authorisation, diversion, clean delivery and billing. A local software licence does not add upstream bandwidth.

Ask every supplier to demonstrate the same workload

  1. Record exact versions, hardware, packet sizes, rules and legitimate traffic. Compare the whole path, not port labels.
  2. Test new and established connections during mitigation. Measure packet loss and application latency as well as attack throughput.
  3. Test exporter loss, BGP loss, node failure, withdrawal and recovery separately. Record what happens to customer traffic.
  4. Price the full deployment: required instances, ports, modules, support, hardware, rack space, power and network services.

How this comparison is prepared

Prepared by Peeryx from the public vendor documentation linked below and the distributed Defense Fabric release. It describes product scope, not a jointly run performance test. Unconfirmed items are questions for the proposed configuration, not claims that a feature is absent.

Sources reviewed:

Sources and scope
  1. Deployment documentation ↗
  2. Defense Fabric public OpenAPI ↗
  3. Defense Fabric and pricing ↗
  4. Corero on-premises deployment ↗
  5. Corero SmartWall ONE FAQ ↗
  6. Andrisoft Wanguard 9.0 overview ↗
  7. Wanguard mitigation methods ↗
  8. Wanguard Filter Cluster ↗
  9. Wanguard Sensor licensing ↗
  10. Wanguard Filter licensing ↗
  11. Wanguard DPDK Engine licensing ↗
  12. Wanguard evaluation licence ↗
  13. FastNetMon Advanced overview ↗
  14. FastACL operator reference ↗
  15. FastNetMon experimental XDP filter ↗
  16. FastNetMon BGP mitigation modes ↗
  17. FastNetMon pricing and licensing basis ↗
  18. FastNetMon Advanced API ↗
  19. FastNetMon HA deployment ↗
  20. NETSCOUT Arbor TMS ↗
  21. Arbor Sightline with Sentinel ↗
  22. Arbor Sightline data sheet (2021) ↗
  23. Arbor Sightline API cookbook ↗
  24. DefensePro X data sheet (2023) ↗
  25. Radware Cyber Controller ↗
  26. Radware DefensePro X models ↗
  27. DefenseFlow integration and connectivity ↗

Validate Defense Fabric against your network

Bring your server models, interface speeds, topology and normal traffic profile. Use the trial to establish the behaviour and capacity of the configuration you would actually deploy.