Flow Collector
- Role
- Flow detection and diversion coordination
- Where it runs
- A VM or server in your network
PEERYX FLOW COLLECTOR
Use your router’s measurements to detect unusual traffic to your IPv4 prefixes. After your routing is validated, Flow Collector can request diversion to Peeryx and coordinate the return to your usual providers.
Free softwarePeeryx network service is separate.
The collector receives telemetry. Customer traffic follows the routing path validated for your service.
Your router exports measurements to a dedicated Linux VM or server. Check sampling, incoming interfaces and export freshness before setting thresholds.
Compare traffic for each authorized /24 with your protocol and total-traffic rules. Observation mode lets you tune thresholds against your actual busy hours.
Announce through Peeryx, verify the announcement and clean delivery, then withdraw the competing routes covered by your policy. Every announcing router must be accounted for.
Restore your usual providers before withdrawing Peeryx. An ongoing attack extends protection; missing measurements or a failed delivery path require explicit recovery handling.
Set limits for TCP, UDP, ICMP, GRE, IPIP and Other in pps or Gbit/s, plus a Total L3 rule. TCP-flag estimates use pps. An exclusive per-prefix bandwidth override can replace the general rules.
You also choose the minimum time on Peeryx: 20 minutes to 7 days after full diversion is confirmed. An ongoing attack extends protection. Recovery waits for fresh measurements showing the attack has cleared; a delivery-path or monitoring failure may require an earlier return to preserve connectivity.
Starting recommendation for one router. Actual capacity depends on export rate, sampling and the number of interfaces; verify with the diagnostic before activation.
Customer traffic does not pass through this server. Allow the configured UDP export port from your router, TCP 179 only between router and collector, and outbound HTTPS 443. A 1 Gbps collector port is not a 1 Gbps limit on protected traffic.
Use a dedicated host. The installer checks the operating system, verifies the signed package, and installs isolated services. It does not change your router.
Detection, local filtering and upstream protection have different jobs. They can be combined after the routing design is validated.
Use it for on-demand protection when traffic normally arrives through your own providers. It is not required for always-on Peeryx protection, a standard tunnel, or an existing compatible detection system.
LINUX · 1.1.0
Inspect the installer before running it. The signed release is available for Linux amd64 and arm64. Installation starts in observation mode; it does not enable production diversion.
Have your router and collector addresses, ASN, authorized prefixes, exporter settings and clean-traffic path ready. The client guide is available for an eligible Peeryx network service. Commissioning must verify diversion and recovery before automatic mode is armed.