Deployment and purchasing guide
Defense Fabric vs Corero SmartWall ONE
Both can form part of an on-premises filtering design. The useful distinction is the qualified platform and operating model: Defense Fabric on compatible operator servers, or the selected SmartWall ONE hardware, software or virtual edition.
Where each approach fits
Defense Fabric fits teams that want to qualify their own Debian servers, allocate licensed ports across their fleet and manage local policies through the Peeryx portal.
SmartWall ONE offers purpose-built appliances as well as approved bare-metal and virtual software deployments. Existing Corero management or router integration can be a material part of the design.
Technical and commercial comparison
Deployment and traffic path
| What to compare | Peeryx Defense Fabric | Corero SmartWall ONE |
|---|---|---|
| Product scope | Local detection, packet filtering and policy control on your servers. [1] |
Packet mitigation platform with network-edge integration and central management. [4] [5] |
| Appliance or software | Licensed Linux software; server and network supplied by the operator. [1] |
Physical appliances, approved bare-metal software and virtual editions. [4] |
| Hardware ownership | Compatible standard servers and qualified NICs; TPM 2.0 required. [1] |
Corero appliances or approved Dell, HPE and Supermicro servers. [4] |
| On-premises installation | Distributed installer: Debian 12, x86-64, VPP 25.10-release. [1] |
On-premises deployments; hypervisor and bare-metal requirements vary by edition. [4] |
| Inline filtering | Inline forwarding is supported; physical bypass must be designed separately. [1] |
Inline inspection; zero-power bypass is tied to applicable hardware interfaces. [4] |
| Traffic diversion | BGP diversion to a validated filtering next hop with a separate clean return. [1] |
BGP-integrated scrubbing mode is documented. [4] |
Detection and protection
| What to compare | Peeryx Defense Fabric | Corero SmartWall ONE |
|---|---|---|
| NetFlow / sFlow / IPFIX | sFlow, NetFlow and IPFIX collection; validate sampling and export delay. [1] |
Flow telemetry and packet-sample integrations are documented; qualify the selected components. [4] [5] |
| Packet inspection | Local VPP-based packet filtering; sampled evidence is not a full attack capture. [1] |
Inline packet inspection and router packet-sample analysis. [4] [5] |
| L3/L4 filtering | Protocol thresholds, TCP validation, source quotas and post-filter firewall policies. [1] |
Network and protocol mitigation are part of SmartWall ONE. [4] |
| Application-layer scope | Protocol-specific modules require qualification; no blanket WAF or arbitrary L7 coverage claim. [1] |
Vendor describes application and encrypted-traffic protections; confirm licensed features and traffic path. [4] |
| Generated attack signatures | Adaptive signatures can be observed or applied; validate collateral effects. [1] |
Behavioural detection and updated protections; exact generated-rule controls need edition review. [4] [5] |
| BGP FlowSpec | Dry-run and active export; compatible router/BGP family required; panel limit 50 rules. [1] |
Network-edge integration can use FlowSpec and NETCONF. [5] |
| BGP steering | Agent-managed sessions and diversion; verify FIB installation and withdrawal. [1] |
BGP scrubbing integration; validate router support and clean delivery design. [4] |
| RTBH blackholing | Available as last-resort destination blackholing; legitimate traffic is also discarded. [1] |
Confirm blackholing workflow and supported communities for the quoted solution. [5] |
| Gaming-specific protection | Optional Game module; qualify each protocol and architecture before ordering. [3] |
Obtain protocol-specific evidence for your games; generic L7 claims are not game certification. [4] |
Operations and resilience
| What to compare | Peeryx Defense Fabric | Corero SmartWall ONE |
|---|---|---|
| Reports and evidence | Panel history and available PCAP, ZIP and PDF evidence; sampling and retention apply. [1] |
Central analytics, events and PCAP exports are advertised. [4] |
| API and automation interface | Published authenticated OpenAPI; revisioned policy writes remain pending until node application. [2] |
JSON REST API and integration interfaces are advertised. [4] |
| High availability | Network failover must be engineered; second server is not automatic state replication. [1] |
Vendor documents multi-site and active-active options; validate the purchased topology. [4] |
| Multiple servers or sites | Shared port pool across up to 128 managed servers; qualified second-link ECMP. [1] |
Central management of multiple deployments and modular expansion. [4] |
| Automatic operation | Monitor, automatic and permanent policy modes; hold and exit thresholds control recovery. [1] |
Automated behavioural mitigation; validate application behaviour during a proof of concept. [4] |
Licensing, costs and validation
| What to compare | Peeryx Defense Fabric | Corero SmartWall ONE |
|---|---|---|
| Licensing unit | Base licence with one 10G port; extra port speeds/counts share a fleet pool. [3] |
Edition, capacity, appliance/software and service scope must be included in the quote. [4] |
| Evaluation terms | 14-day trial; adding servers does not restart it. Physical and activation limits still apply. [1] |
Demonstration offered; evaluation duration and equipment terms require confirmation. [4] |
| Public price basis | €350.00 per month excluding tax; server, network and optional modules are separate. [3] |
No comparable configured public price verified in the reviewed sources; request a quote. [4] |
| Support scope | Peeryx technical support; confirm deployment responsibilities and contractual response commitments. [3] |
Vendor services available; obtain the exact support, replacement and response terms. [4] |
| Deployment constraints | TPM, compatible NICs, management HTTPS, tested routing; SYN proxy requires symmetry. [1] |
Approved hardware or hypervisor and selected router integration; validate bypass and failure modes. [4] |
| Performance evidence | No published reproducible benchmark for the reference servers; measure your workload. [1] |
Vendor model specifications exist; no common Peeryx-versus-Corero benchmark was run. [4] |
| Upstream saturation | Local filtering cannot clear an already saturated upstream link; transit is a separate service. [1] |
Hybrid upstream scrubbing is a separate architectural and commercial component. [4] |
Prices use the published currency and billing period. Monitored bandwidth, licensed ports and filtering capacity are different quantities; these figures are not equivalent quotes. Hardware, taxes and optional services may add to the total.
What to verify before a decision
- Do not base the decision on “software versus appliance”: Corero offers both. Obtain the exact supported server or appliance reference.
- For inline operation, identify the physical bypass and test power loss. Software availability and packet-path continuity are separate properties.
- Compare the same packet mix, rule set and legitimate application load. Published port speeds or latency claims are not a shared benchmark.
Ask every supplier to demonstrate the same workload
- Record exact versions, hardware, packet sizes, rules and legitimate traffic. Compare the whole path, not port labels.
- Test new and established connections during mitigation. Measure packet loss and application latency as well as attack throughput.
- Test exporter loss, BGP loss, node failure, withdrawal and recovery separately. Record what happens to customer traffic.
- Price the full deployment: required instances, ports, modules, support, hardware, rack space, power and network services.
How this comparison is prepared
Prepared by Peeryx from the public vendor documentation linked below and the distributed Defense Fabric release. It describes product scope, not a jointly run performance test. Unconfirmed items are questions for the proposed configuration, not claims that a feature is absent.
Sources reviewed:
Validate Defense Fabric against your network
Bring your server models, interface speeds, topology and normal traffic profile. Use the trial to establish the behaviour and capacity of the configuration you would actually deploy.