Keep filtering on your servers
Include the packet-processing engine, NICs, server resources, a clean return path and a tested failure design. Owning the server does not remove the need for upstream capacity.
Deployment and purchasing guide
Start with where packets are filtered, then compare the equipment, licences and operating work required. A collector, a router rule and a scrubbing server perform different jobs.
Appliances and software editions, with inline filtering and router integration.
View the comparisonSensor and Filter software, local packet enforcement and router-based mitigation.
View the comparisonTelemetry and BGP automation, with separate documented inline filtering options.
View the comparisonSightline visibility, TMS packet mitigation and network-wide orchestration.
View the comparisonMitigation appliances, application options and Cyber Controller management.
View the comparisonInclude the packet-processing engine, NICs, server resources, a clean return path and a tested failure design. Owning the server does not remove the need for upstream capacity.
Check FlowSpec matching and action support, hardware rule limits, validation and withdrawal. A detector that sends rules is distinct from the router that applies them.
Include the scrubbing provider, prefix authorisation, diversion, clean delivery and billing. A local software licence does not add upstream bandwidth.
Prepared by Peeryx from the public vendor documentation linked below and the distributed Defense Fabric release. It describes product scope, not a jointly run performance test. Unconfirmed items are questions for the proposed configuration, not claims that a feature is absent.
Sources reviewed:
Bring your server models, interface speeds, topology and normal traffic profile. Use the trial to establish the behaviour and capacity of the configuration you would actually deploy.