Deployment and purchasing guide
Defense Fabric vs NETSCOUT Arbor Sightline and TMS
Sightline supplies visibility and detection; TMS performs packet mitigation. Sentinel and other components can extend orchestration. Compare the full proposed deployment rather than Sightline alone against a filtering engine.
Where each approach fits
Defense Fabric is an option for teams qualifying filtering on their own servers with a visible port-based software tariff. Local capacity and failure recovery still need measurement.
An Arbor deployment can combine network-wide intelligence, multiple TMS devices and existing operator workflows. The value and cost depend on the selected Sightline, TMS, Sentinel and service scope.
Technical and commercial comparison
Deployment and traffic path
| What to compare | Peeryx Defense Fabric | NETSCOUT Arbor Sightline + TMS |
|---|---|---|
| Product scope | Local detection, packet filtering and policy control on your servers. [1] |
Sightline visibility/detection plus TMS packet mitigation; Sentinel adds orchestration capabilities. [4] [5] |
| Appliance or software | Licensed Linux software; server and network supplied by the operator. [1] |
Physical and virtual deployment options are documented. [4] |
| Hardware ownership | Compatible standard servers and qualified NICs; TPM 2.0 required. [1] |
Appliance or qualified virtual platform; obtain model and resource requirements. [4] |
| On-premises installation | Distributed installer: Debian 12, x86-64, VPP 25.10-release. [1] |
On-premises/edge deployments and cloud integration options. [4] |
| Inline filtering | Inline forwarding is supported; physical bypass must be designed separately. [1] |
Confirm the supported inline topology for the selected TMS model and release. [4] |
| Traffic diversion | BGP diversion to a validated filtering next hop with a separate clean return. [1] |
TMS scrubbing is coordinated with Sightline; verify diversion and clean-return integration. [4] [5] |
Detection and protection
| What to compare | Peeryx Defense Fabric | NETSCOUT Arbor Sightline + TMS |
|---|---|---|
| NetFlow / sFlow / IPFIX | sFlow, NetFlow and IPFIX collection; validate sampling and export delay. [1] |
Network telemetry is collected by Sightline; verify exporters and licensed integrations. [6] |
| Packet inspection | Local VPP-based packet filtering; sampled evidence is not a full attack capture. [1] |
TMS removes attack packets; Sightline visibility is a separate component. [4] |
| L3/L4 filtering | Protocol thresholds, TCP validation, source quotas and post-filter firewall policies. [1] |
Volumetric and protocol/state-exhaustion mitigation is documented. [4] |
| Application-layer scope | Protocol-specific modules require qualification; no blanket WAF or arbitrary L7 coverage claim. [1] |
Application-attack protections are advertised; verify protocols, model and subscriptions. [4] |
| Generated attack signatures | Adaptive signatures can be observed or applied; validate collateral effects. [1] |
Adaptive countermeasures are described; inspect the required attack signatures in a proof of concept. [4] |
| BGP FlowSpec | Dry-run and active export; compatible router/BGP family required; panel limit 50 rules. [1] |
Sightline/Sentinel provide router FlowSpec orchestration and per-rule visibility. [5] |
| BGP steering | Agent-managed sessions and diversion; verify FIB installation and withdrawal. [1] |
Network orchestration and upstream signalling; qualify the routing design. [5] |
| RTBH blackholing | Available as last-resort destination blackholing; legitimate traffic is also discarded. [1] |
Sightline documents blackholing alongside FlowSpec and ACL actions. [6] |
| Gaming-specific protection | Optional Game module; qualify each protocol and architecture before ordering. [3] |
Confirm specific games and deployment tests; a gaming customer story is not protocol certification. [4] |
Operations and resilience
| What to compare | Peeryx Defense Fabric | NETSCOUT Arbor Sightline + TMS |
|---|---|---|
| Reports and evidence | Panel history and available PCAP, ZIP and PDF evidence; sampling and retention apply. [1] |
Central visibility including per-router and per-FlowSpec-rule mitigation reports. [5] |
| API and automation interface | Published authenticated OpenAPI; revisioned policy writes remain pending until node application. [2] |
Sightline REST API exists; use the API guide matching the purchased release. [7] |
| High availability | Network failover must be engineered; second server is not automatic state replication. [1] |
Distributed TMS deployments are described; obtain the exact failure and recovery design. [4] |
| Multiple servers or sites | Shared port pool across up to 128 managed servers; qualified second-link ECMP. [1] |
Multiple mitigation devices and network-wide orchestration. [4] [5] |
| Automatic operation | Monitor, automatic and permanent policy modes; hold and exit thresholds control recovery. [1] |
Detection and orchestrated mitigation across supported network components. [5] |
Licensing, costs and validation
| What to compare | Peeryx Defense Fabric | NETSCOUT Arbor Sightline + TMS |
|---|---|---|
| Licensing unit | Base licence with one 10G port; extra port speeds/counts share a fleet pool. [3] |
Quote the full Sightline/TMS/Sentinel, capacity and subscription scope. [4] [5] |
| Evaluation terms | 14-day trial; adding servers does not restart it. Physical and activation limits still apply. [1] |
Evaluation duration and equipment terms were not confirmed in reviewed public sources. [4] |
| Public price basis | €350.00 per month excluding tax; server, network and optional modules are separate. [3] |
A complete comparable public price was not verified; request the configured solution quote. [4] |
| Support scope | Peeryx technical support; confirm deployment responsibilities and contractual response commitments. [3] |
Vendor and managed-service options exist; contract the needed support scope and response times. [4] |
| Deployment constraints | TPM, compatible NICs, management HTTPS, tested routing; SYN proxy requires symmetry. [1] |
Component integration, licences, clean delivery and qualified topology must be sized together. [4] [5] |
| Performance evidence | No published reproducible benchmark for the reference servers; measure your workload. [1] |
Model-specific vendor specifications; ask for the current datasheet rather than mixing headline capacities. [4] |
| Upstream saturation | Local filtering cannot clear an already saturated upstream link; transit is a separate service. [1] |
Upstream signalling and cloud options are separate from local appliance capacity. [5] [4] |
Prices use the published currency and billing period. Monitored bandwidth, licensed ports and filtering capacity are different quantities; these figures are not equivalent quotes. Hardware, taxes and optional services may add to the total.
What to verify before a decision
- Obtain the exact model and current capacity data sheet. Distinguish single-device performance, deployment totals and licensed capacity.
- Validate how detection reaches enforcement, which routers are supported and how clean traffic returns to the destination.
- Specify management availability, data-path recovery, API version, subscriptions and support in the same proposal.
Ask every supplier to demonstrate the same workload
- Record exact versions, hardware, packet sizes, rules and legitimate traffic. Compare the whole path, not port labels.
- Test new and established connections during mitigation. Measure packet loss and application latency as well as attack throughput.
- Test exporter loss, BGP loss, node failure, withdrawal and recovery separately. Record what happens to customer traffic.
- Price the full deployment: required instances, ports, modules, support, hardware, rack space, power and network services.
How this comparison is prepared
Prepared by Peeryx from the public vendor documentation linked below and the distributed Defense Fabric release. It describes product scope, not a jointly run performance test. Unconfirmed items are questions for the proposed configuration, not claims that a feature is absent.
Sources reviewed:
Validate Defense Fabric against your network
Bring your server models, interface speeds, topology and normal traffic profile. Use the trial to establish the behaviour and capacity of the configuration you would actually deploy.