Skip to content
PEERYXNETWORK

Deployment and purchasing guide

Defense Fabric vs NETSCOUT Arbor Sightline and TMS

Sightline supplies visibility and detection; TMS performs packet mitigation. Sentinel and other components can extend orchestration. Compare the full proposed deployment rather than Sightline alone against a filtering engine.

Where each approach fits

Defense Fabric is an option for teams qualifying filtering on their own servers with a visible port-based software tariff. Local capacity and failure recovery still need measurement.

An Arbor deployment can combine network-wide intelligence, multiple TMS devices and existing operator workflows. The value and cost depend on the selected Sightline, TMS, Sentinel and service scope.

Technical and commercial comparison

Deployment and traffic path
Deployment and traffic path — Defense Fabric vs NETSCOUT Arbor Sightline and TMS
What to comparePeeryx Defense FabricNETSCOUT Arbor Sightline + TMS
Product scope

Local detection, packet filtering and policy control on your servers.

[1]

Sightline visibility/detection plus TMS packet mitigation; Sentinel adds orchestration capabilities.

[4] [5]
Appliance or software

Licensed Linux software; server and network supplied by the operator.

[1]

Physical and virtual deployment options are documented.

[4]
Hardware ownership

Compatible standard servers and qualified NICs; TPM 2.0 required.

[1]

Appliance or qualified virtual platform; obtain model and resource requirements.

[4]
On-premises installation

Distributed installer: Debian 12, x86-64, VPP 25.10-release.

[1]

On-premises/edge deployments and cloud integration options.

[4]
Inline filtering

Inline forwarding is supported; physical bypass must be designed separately.

[1]

Confirm the supported inline topology for the selected TMS model and release.

[4]
Traffic diversion

BGP diversion to a validated filtering next hop with a separate clean return.

[1]

TMS scrubbing is coordinated with Sightline; verify diversion and clean-return integration.

[4] [5]
Detection and protection
Detection and protection — Defense Fabric vs NETSCOUT Arbor Sightline and TMS
What to comparePeeryx Defense FabricNETSCOUT Arbor Sightline + TMS
NetFlow / sFlow / IPFIX

sFlow, NetFlow and IPFIX collection; validate sampling and export delay.

[1]

Network telemetry is collected by Sightline; verify exporters and licensed integrations.

[6]
Packet inspection

Local VPP-based packet filtering; sampled evidence is not a full attack capture.

[1]

TMS removes attack packets; Sightline visibility is a separate component.

[4]
L3/L4 filtering

Protocol thresholds, TCP validation, source quotas and post-filter firewall policies.

[1]

Volumetric and protocol/state-exhaustion mitigation is documented.

[4]
Application-layer scope

Protocol-specific modules require qualification; no blanket WAF or arbitrary L7 coverage claim.

[1]

Application-attack protections are advertised; verify protocols, model and subscriptions.

[4]
Generated attack signatures

Adaptive signatures can be observed or applied; validate collateral effects.

[1]

Adaptive countermeasures are described; inspect the required attack signatures in a proof of concept.

[4]
BGP FlowSpec

Dry-run and active export; compatible router/BGP family required; panel limit 50 rules.

[1]

Sightline/Sentinel provide router FlowSpec orchestration and per-rule visibility.

[5]
BGP steering

Agent-managed sessions and diversion; verify FIB installation and withdrawal.

[1]

Network orchestration and upstream signalling; qualify the routing design.

[5]
RTBH blackholing

Available as last-resort destination blackholing; legitimate traffic is also discarded.

[1]

Sightline documents blackholing alongside FlowSpec and ACL actions.

[6]
Gaming-specific protection

Optional Game module; qualify each protocol and architecture before ordering.

[3]

Confirm specific games and deployment tests; a gaming customer story is not protocol certification.

[4]
Operations and resilience
Operations and resilience — Defense Fabric vs NETSCOUT Arbor Sightline and TMS
What to comparePeeryx Defense FabricNETSCOUT Arbor Sightline + TMS
Reports and evidence

Panel history and available PCAP, ZIP and PDF evidence; sampling and retention apply.

[1]

Central visibility including per-router and per-FlowSpec-rule mitigation reports.

[5]
API and automation interface

Published authenticated OpenAPI; revisioned policy writes remain pending until node application.

[2]

Sightline REST API exists; use the API guide matching the purchased release.

[7]
High availability

Network failover must be engineered; second server is not automatic state replication.

[1]

Distributed TMS deployments are described; obtain the exact failure and recovery design.

[4]
Multiple servers or sites

Shared port pool across up to 128 managed servers; qualified second-link ECMP.

[1]

Multiple mitigation devices and network-wide orchestration.

[4] [5]
Automatic operation

Monitor, automatic and permanent policy modes; hold and exit thresholds control recovery.

[1]

Detection and orchestrated mitigation across supported network components.

[5]
Licensing, costs and validation
Licensing, costs and validation — Defense Fabric vs NETSCOUT Arbor Sightline and TMS
What to comparePeeryx Defense FabricNETSCOUT Arbor Sightline + TMS
Licensing unit

Base licence with one 10G port; extra port speeds/counts share a fleet pool.

[3]

Quote the full Sightline/TMS/Sentinel, capacity and subscription scope.

[4] [5]
Evaluation terms

14-day trial; adding servers does not restart it. Physical and activation limits still apply.

[1]

Evaluation duration and equipment terms were not confirmed in reviewed public sources.

[4]
Public price basis

€350.00 per month excluding tax; server, network and optional modules are separate.

[3]

A complete comparable public price was not verified; request the configured solution quote.

[4]
Support scope

Peeryx technical support; confirm deployment responsibilities and contractual response commitments.

[3]

Vendor and managed-service options exist; contract the needed support scope and response times.

[4]
Deployment constraints

TPM, compatible NICs, management HTTPS, tested routing; SYN proxy requires symmetry.

[1]

Component integration, licences, clean delivery and qualified topology must be sized together.

[4] [5]
Performance evidence

No published reproducible benchmark for the reference servers; measure your workload.

[1]

Model-specific vendor specifications; ask for the current datasheet rather than mixing headline capacities.

[4]
Upstream saturation

Local filtering cannot clear an already saturated upstream link; transit is a separate service.

[1]

Upstream signalling and cloud options are separate from local appliance capacity.

[5] [4]

Prices use the published currency and billing period. Monitored bandwidth, licensed ports and filtering capacity are different quantities; these figures are not equivalent quotes. Hardware, taxes and optional services may add to the total.

What to verify before a decision

  1. Obtain the exact model and current capacity data sheet. Distinguish single-device performance, deployment totals and licensed capacity.
  2. Validate how detection reaches enforcement, which routers are supported and how clean traffic returns to the destination.
  3. Specify management availability, data-path recovery, API version, subscriptions and support in the same proposal.

Ask every supplier to demonstrate the same workload

  1. Record exact versions, hardware, packet sizes, rules and legitimate traffic. Compare the whole path, not port labels.
  2. Test new and established connections during mitigation. Measure packet loss and application latency as well as attack throughput.
  3. Test exporter loss, BGP loss, node failure, withdrawal and recovery separately. Record what happens to customer traffic.
  4. Price the full deployment: required instances, ports, modules, support, hardware, rack space, power and network services.

How this comparison is prepared

Prepared by Peeryx from the public vendor documentation linked below and the distributed Defense Fabric release. It describes product scope, not a jointly run performance test. Unconfirmed items are questions for the proposed configuration, not claims that a feature is absent.

Sources reviewed:

Sources and scope
  1. Deployment documentation ↗
  2. Defense Fabric public OpenAPI ↗
  3. Defense Fabric and pricing ↗
  4. NETSCOUT Arbor TMS ↗
  5. Arbor Sightline with Sentinel ↗
  6. Arbor Sightline data sheet (2021) ↗
  7. Arbor Sightline API cookbook ↗

Validate Defense Fabric against your network

Bring your server models, interface speeds, topology and normal traffic profile. Use the trial to establish the behaviour and capacity of the configuration you would actually deploy.