Deployment and purchasing guide
Defense Fabric vs FastNetMon Advanced
FastNetMon Advanced is widely used for telemetry and network-action automation. Its documentation now also describes FastACL, a VPP inline filtering plugin. The comparison must name the actual components being deployed.
Where each approach fits
Defense Fabric provides a local filtering and policy workflow with server enrolment, a shared licensed port pool and the Peeryx portal. Its installed release and network path must be qualified.
FastNetMon Advanced can automate existing routers or scrubbing services. Where inline filtering is required, assess FastACL separately; do not infer its availability, support or price from a collector subscription.
Technical and commercial comparison
Deployment and traffic path
| What to compare | Peeryx Defense Fabric | FastNetMon Advanced / FastACL |
|---|---|---|
| Product scope | Local detection, packet filtering and policy control on your servers. [1] |
Advanced detects and automates network actions; FastACL is a documented VPP filtering component. [4] [5] |
| Appliance or software | Licensed Linux software; server and network supplied by the operator. [1] |
Software on operator infrastructure; distinguish core collector, XDP experiment and FastACL. [4] [6] [5] |
| Hardware ownership | Compatible standard servers and qualified NICs; TPM 2.0 required. [1] |
Standard servers or VMs for collection; inline NIC/dataplane requirements need separate qualification. [4] [5] |
| On-premises installation | Distributed installer: Debian 12, x86-64, VPP 25.10-release. [1] |
Local collector deployment; inline FastACL runs within VPP. [4] [5] |
| Inline filtering | Inline forwarding is supported; physical bypass must be designed separately. [1] |
FastACL supports bridge/routed filtering. The separate host XDP feature is marked experimental. [5] [6] |
| Traffic diversion | BGP diversion to a validated filtering next hop with a separate clean return. [1] |
Advanced automates BGP diversion to an external scrubbing destination. [7] |
Detection and protection
| What to compare | Peeryx Defense Fabric | FastNetMon Advanced / FastACL |
|---|---|---|
| NetFlow / sFlow / IPFIX | sFlow, NetFlow and IPFIX collection; validate sampling and export delay. [1] |
sFlow, NetFlow, IPFIX and mirrored-packet inputs are documented. [4] |
| Packet inspection | Local VPP-based packet filtering; sampled evidence is not a full attack capture. [1] |
Mirrored packet analysis and separate inline enforcement; confirm which engine is deployed. [4] [5] |
| L3/L4 filtering | Protocol thresholds, TCP validation, source quotas and post-filter firewall policies. [1] |
FlowSpec rules are enforced by routers or the selected inline component. [7] [5] |
| Application-layer scope | Protocol-specific modules require qualification; no blanket WAF or arbitrary L7 coverage claim. [1] |
The documented FlowSpec generator analyses L3/L4, not application payload. [7] |
| Generated attack signatures | Adaptive signatures can be observed or applied; validate collateral effects. [1] |
Traffic samples drive statistical attack-rule generation. [7] |
| BGP FlowSpec | Dry-run and active export; compatible router/BGP family required; panel limit 50 rules. [1] |
Advanced generates BGP FlowSpec; FastACL matches IPv4/IPv6 FlowSpec-style rules. [7] [5] |
| BGP steering | Agent-managed sessions and diversion; verify FIB installation and withdrawal. [1] |
BGP route actions and scrubbing diversion; validate installed next hops and withdrawal. [7] |
| RTBH blackholing | Available as last-resort destination blackholing; legitimate traffic is also discarded. [1] |
Automatic BGP blackhole announcements are supported. [7] |
| Gaming-specific protection | Optional Game module; qualify each protocol and architecture before ordering. [3] |
Qualify game traffic separately; L3/L4 detection is not a game-session validation guarantee. [7] |
Operations and resilience
| What to compare | Peeryx Defense Fabric | FastNetMon Advanced / FastACL |
|---|---|---|
| Reports and evidence | Panel history and available PCAP, ZIP and PDF evidence; sampling and retention apply. [1] |
Metrics and attack history; LiveView is an optional paid web interface. [4] [8] |
| API and automation interface | Published authenticated OpenAPI; revisioned policy writes remain pending until node application. [2] |
Advanced API and callbacks are documented; FastACL has a VPP CLI reference. [9] [5] |
| High availability | Network failover must be engineered; second server is not automatic state replication. [1] |
Documented HA setup; licence must cover the extra instances. [10] [8] |
| Multiple servers or sites | Shared port pool across up to 128 managed servers; qualified second-link ECMP. [1] |
Multiple collectors/sites supported; instance count and aggregate licensing scope apply. [8] |
| Automatic operation | Monitor, automatic and permanent policy modes; hold and exit thresholds control recovery. [1] |
Threshold-driven actions and return to normal; configuration determines the response. [7] |
Licensing, costs and validation
| What to compare | Peeryx Defense Fabric | FastNetMon Advanced / FastACL |
|---|---|---|
| Licensing unit | Base licence with one 10G port; extra port speeds/counts share a fleet pool. [3] |
Advanced uses monitored traffic and instance counts; confirm FastACL commercial terms separately. [8] [5] |
| Evaluation terms | 14-day trial; adding servers does not restart it. Physical and activation limits still apply. [1] |
One-month Advanced trial; confirm whether the proposed inline scope is included. [8] |
| Public price basis | €350.00 per month excluding tax; server, network and optional modules are separate. [3] |
Advanced starts at $115/month for 10G observed traffic and one instance, plus a one-time $85 activation fee for monthly subscriptions. [8] |
| Support scope | Peeryx technical support; confirm deployment responsibilities and contractual response commitments. [3] |
Plan-specific ticket allowances; enterprise terms and inline-component support need confirmation. [8] |
| Deployment constraints | TPM, compatible NICs, management HTTPS, tested routing; SYN proxy requires symmetry. [1] |
Current licence basis is average combined ingress/egress for the network, not P95 or filter throughput. [8] |
| Performance evidence | No published reproducible benchmark for the reference servers; measure your workload. [1] |
Observed bandwidth and inline throughput are different measures; no common benchmark was run. [8] [5] |
| Upstream saturation | Local filtering cannot clear an already saturated upstream link; transit is a separate service. [1] |
Upstream router enforcement or a contracted scrubbing service is still needed for link saturation. [4] |
Prices use the published currency and billing period. Monitored bandwidth, licensed ports and filtering capacity are different quantities; these figures are not equivalent quotes. Hardware, taxes and optional services may add to the total.
What to verify before a decision
- FastACL supports VPP bridge and routed modes. The older experimental host XDP filter has different limits; they are not the same implementation.
- Advanced pricing uses monitored network traffic and instance counts. Those quantities do not represent guaranteed scrubbing capacity.
- Include any LiveView users, extra instances, activation fees and inline-component terms in the proposal before comparing totals.
Ask every supplier to demonstrate the same workload
- Record exact versions, hardware, packet sizes, rules and legitimate traffic. Compare the whole path, not port labels.
- Test new and established connections during mitigation. Measure packet loss and application latency as well as attack throughput.
- Test exporter loss, BGP loss, node failure, withdrawal and recovery separately. Record what happens to customer traffic.
- Price the full deployment: required instances, ports, modules, support, hardware, rack space, power and network services.
How this comparison is prepared
Prepared by Peeryx from the public vendor documentation linked below and the distributed Defense Fabric release. It describes product scope, not a jointly run performance test. Unconfirmed items are questions for the proposed configuration, not claims that a feature is absent.
Sources reviewed:
Sources and scope
- Deployment documentation ↗
- Defense Fabric public OpenAPI ↗
- Defense Fabric and pricing ↗
- FastNetMon Advanced overview ↗
- FastACL operator reference ↗
- FastNetMon experimental XDP filter ↗
- FastNetMon BGP mitigation modes ↗
- FastNetMon pricing and licensing basis ↗
- FastNetMon Advanced API ↗
- FastNetMon HA deployment ↗
Validate Defense Fabric against your network
Bring your server models, interface speeds, topology and normal traffic profile. Use the trial to establish the behaviour and capacity of the configuration you would actually deploy.