Skip to content
PEERYXNETWORK

PEERYX FLOW COLLECTOR

Flow monitoring for on-demand DDoS protection.

Use your router’s measurements to detect unusual traffic to your IPv4 prefixes. After your routing is validated, Flow Collector can request diversion to Peeryx and coordinate the return to your usual providers.

Free softwarePeeryx network service is separate.

FLOW COLLECTORsFlow / NetFlow / IPFIX
Your routerBGP
PEERYXTraffic cleaning
sFlow · NetFlow · IPFIX
FLOW COLLECTORDetection & BGP control
Your router sends measurements to the collector; Peeryx receives diverted traffic.

From measurements to a validated traffic path

The collector receives telemetry. Customer traffic follows the routing path validated for your service.

  1. Collect

    Your router exports measurements to a dedicated Linux VM or server. Check sampling, incoming interfaces and export freshness before setting thresholds.

  2. Detect

    Compare traffic for each authorized /24 with your protocol and total-traffic rules. Observation mode lets you tune thresholds against your actual busy hours.

  3. Divert

    Announce through Peeryx, verify the announcement and clean delivery, then withdraw the competing routes covered by your policy. Every announcing router must be accounted for.

  4. Recover

    Restore your usual providers before withdrawing Peeryx. An ongoing attack extends protection; missing measurements or a failed delivery path require explicit recovery handling.

Rules based on your traffic

Set limits for TCP, UDP, ICMP, GRE, IPIP and Other in pps or Gbit/s, plus a Total L3 rule. TCP-flag estimates use pps. An exclusive per-prefix bandwidth override can replace the general rules.

You also choose the minimum time on Peeryx: 20 minutes to 7 days after full diversion is confirmed. An ongoing attack extends protection. Recovery waits for fresh measurements showing the attack has cleared; a delivery-path or monitoring failure may require an earlier return to preserve connectivity.

Requirements

Starting recommendation for one router. Actual capacity depends on export rate, sampling and the number of interfaces; verify with the diagnostic before activation.

Customer traffic does not pass through this server. Allow the configured UDP export port from your router, TCP 179 only between router and collector, and outbound HTTPS 443. A 1 Gbps collector port is not a 1 Gbps limit on protected traffic.

Use a dedicated host. The installer checks the operating system, verifies the signed package, and installs isolated services. It does not change your router.

CPU
Small Xeon or equivalent · 2 cores minimum
Memory & disk
8 GB RAM · 20 GB free disk
Network
1 Gbps Ethernet for telemetry and control
Operating system
Debian 12/13 or Ubuntu 24.04 · x86-64 / ARM64
Measurements
sFlow v5, NetFlow/NetStream v5/v9 or IPFIX
Access
Dedicated Linux VM/server, sudo, synchronized clock

Choose the component your network needs

Detection, local filtering and upstream protection have different jobs. They can be combined after the routing design is validated.

Flow Collector

Role
Flow detection and diversion coordination
Where it runs
A VM or server in your network

Defense Fabric

Role
Packet filtering under your policies
Where it runs
Your filtering servers and bandwidth

Protected IP transit

Role
Protected transit and clean traffic delivery
Where it runs
Peeryx network; separately subscribed service

Use it for on-demand protection when traffic normally arrives through your own providers. It is not required for always-on Peeryx protection, a standard tunnel, or an existing compatible detection system.

LINUX · 1.1.0

Download Peeryx Flow Collector

Inspect the installer before running it. The signed release is available for Linux amd64 and arm64. Installation starts in observation mode; it does not enable production diversion.

Download installer

Prepare your first location

Have your router and collector addresses, ASN, authorized prefixes, exporter settings and clean-traffic path ready. The client guide is available for an eligible Peeryx network service. Commissioning must verify diversion and recovery before automatic mode is armed.