Deployment and purchasing guide
Defense Fabric vs Radware DefensePro X
DefensePro X is a family of mitigation platforms with model-specific capacity and subscription options. Cyber Controller provides central management. Compare the chosen platform and modules with a fully specified Defense Fabric server deployment.
Where each approach fits
Defense Fabric fits an operator-led deployment on qualified standard servers. The software licence, optional modules, server and network can be evaluated separately.
DefensePro X provides model-specific hardware and network/application protection options. Cyber Controller and any routing or cloud components belong in the architecture and commercial scope.
Technical and commercial comparison
Deployment and traffic path
| What to compare | Peeryx Defense Fabric | Radware DefensePro X |
|---|---|---|
| Product scope | Local detection, packet filtering and policy control on your servers. [1] |
DDoS filtering platforms with application options and Cyber Controller management. [4] [5] |
| Appliance or software | Licensed Linux software; server and network supplied by the operator. [1] |
DefensePro X appliances; virtual/cloud options have separate deployment scope. [4] |
| Hardware ownership | Compatible standard servers and qualified NICs; TPM 2.0 required. [1] |
Model-specific hardware, interfaces and optional acceleration/bypass modules. [6] |
| On-premises installation | Distributed installer: Debian 12, x86-64, VPP 25.10-release. [1] |
On-premises perimeter deployment is documented. [4] |
| Inline filtering | Inline forwarding is supported; physical bypass must be designed separately. [1] |
Inline deployment; bypass behaviour depends on the chosen hardware. [4] [6] |
| Traffic diversion | BGP diversion to a validated filtering next hop with a separate clean return. [1] |
Out-of-path deployment is documented; orchestration and routing components must be specified. [4] [5] |
Detection and protection
| What to compare | Peeryx Defense Fabric | Radware DefensePro X |
|---|---|---|
| NetFlow / sFlow / IPFIX | sFlow, NetFlow and IPFIX collection; validate sampling and export delay. [1] |
Confirm the FlowDetector/external detector and exporter formats in the selected solution. [5] [7] |
| Packet inspection | Local VPP-based packet filtering; sampled evidence is not a full attack capture. [1] |
Perimeter packet mitigation with behavioural attack analysis. [4] |
| L3/L4 filtering | Protocol thresholds, TCP validation, source quotas and post-filter firewall policies. [1] |
Network flood and protocol attack mitigation; selected subscriptions define scope. [4] |
| Application-layer scope | Protocol-specific modules require qualification; no blanket WAF or arbitrary L7 coverage claim. [1] |
Application and TLS protections vary by subscription and hardware acceleration. [4] [6] |
| Generated attack signatures | Adaptive signatures can be observed or applied; validate collateral effects. [1] |
Automatic attack signatures and challenge mechanisms are described. [4] |
| BGP FlowSpec | Dry-run and active export; compatible router/BGP family required; panel limit 50 rules. [1] |
Confirm BGP/FlowSpec orchestration in the quoted controller and deployment; not assumed from the appliance alone. [7] |
| BGP steering | Agent-managed sessions and diversion; verify FIB installation and withdrawal. [1] |
Routing integration exists in the orchestration ecosystem; validate the current component/release. [7] |
| RTBH blackholing | Available as last-resort destination blackholing; legitimate traffic is also discarded. [1] |
Confirm required blackhole actions and routing ownership in the deployment plan. [7] |
| Gaming-specific protection | Optional Game module; qualify each protocol and architecture before ordering. [3] |
Validate individual games; network/application protection is not a named-game compatibility certificate. [4] |
Operations and resilience
| What to compare | Peeryx Defense Fabric | Radware DefensePro X |
|---|---|---|
| Reports and evidence | Panel history and available PCAP, ZIP and PDF evidence; sampling and retention apply. [1] |
Cyber Controller offers traffic/attack analytics and policy management. [5] |
| API and automation interface | Published authenticated OpenAPI; revisioned policy writes remain pending until node application. [2] |
Confirm supported management APIs and licences for the chosen controller/release. [5] |
| High availability | Network failover must be engineered; second server is not automatic state replication. [1] |
Cyber Controller documents management/control HA; data-path failover is a separate test. [5] |
| Multiple servers or sites | Shared port pool across up to 128 managed servers; qualified second-link ECMP. [1] |
Central management of DefensePro deployments; size platforms and controllers together. [5] |
| Automatic operation | Monitor, automatic and permanent policy modes; hold and exit thresholds control recovery. [1] |
Behavioural mitigation and controller-triggered actions using internal or external detection. [4] [5] |
Licensing, costs and validation
| What to compare | Peeryx Defense Fabric | Radware DefensePro X |
|---|---|---|
| Licensing unit | Base licence with one 10G port; extra port speeds/counts share a fleet pool. [3] |
Platform plus Network Protection and optional Application Protection subscriptions. [4] |
| Evaluation terms | 14-day trial; adding servers does not restart it. Physical and activation limits still apply. [1] |
Demonstration offered; trial duration and equipment availability need confirmation. [6] |
| Public price basis | €350.00 per month excluding tax; server, network and optional modules are separate. [3] |
No configured public price verified; request hardware, subscriptions, controller and support together. [6] |
| Support scope | Peeryx technical support; confirm deployment responsibilities and contractual response commitments. [3] |
Support and emergency-response options depend on contract; confirm what is included. [4] |
| Deployment constraints | TPM, compatible NICs, management HTTPS, tested routing; SYN proxy requires symmetry. [1] |
Distinguish mitigation capacity, legitimate throughput, modules and network topology. [6] |
| Performance evidence | No published reproducible benchmark for the reference servers; measure your workload. [1] |
Vendor model specifications separate attack and legitimate throughput; no common Peeryx benchmark was run. [6] |
| Upstream saturation | Local filtering cannot clear an already saturated upstream link; transit is a separate service. [1] |
Hybrid cloud protection is a separate option; local appliance capacity does not add upstream bandwidth. [4] |
Prices use the published currency and billing period. Monitored bandwidth, licensed ports and filtering capacity are different quantities; these figures are not equivalent quotes. Hardware, taxes and optional services may add to the total.
What to verify before a decision
- Distinguish attack-mitigation capacity from legitimate-traffic throughput. The public model table lists them separately.
- Confirm which Network Protection, Application Protection, TLS acceleration and bypass options are included.
- Test the selected inline or out-of-path design, including controller failure and packet-path recovery. Verify current integration and API terms.
Ask every supplier to demonstrate the same workload
- Record exact versions, hardware, packet sizes, rules and legitimate traffic. Compare the whole path, not port labels.
- Test new and established connections during mitigation. Measure packet loss and application latency as well as attack throughput.
- Test exporter loss, BGP loss, node failure, withdrawal and recovery separately. Record what happens to customer traffic.
- Price the full deployment: required instances, ports, modules, support, hardware, rack space, power and network services.
How this comparison is prepared
Prepared by Peeryx from the public vendor documentation linked below and the distributed Defense Fabric release. It describes product scope, not a jointly run performance test. Unconfirmed items are questions for the proposed configuration, not claims that a feature is absent.
Sources reviewed:
Validate Defense Fabric against your network
Bring your server models, interface speeds, topology and normal traffic profile. Use the trial to establish the behaviour and capacity of the configuration you would actually deploy.