Content Selection

Preview

Update

Update & Close

Loading...
OcNOS & IP Maestro VM Download
FREE Software Demos
  • Products
      • OcNOS®
        • – Service Provider
        • – Data Center
      • IP Maestro
      • OcNOS Flex
      • OcNOS CP
      • Broadcom Development Collaborator
  • Solutions
      • Access
        • CSR
        • Unified Access
      • Aggregation
        • Segment Routing
        • Broadband Aggregation
        • Cloud and SP WAN
      • Data Center
        • Data Center Fabric
        • AI Networking
        • Data Center Interconnect
      • IPoDWDM Transport
      • DDoS Protection and Network Security
  • Partners
  • Resources
      • Press Releases
      • News Coverage
      • Webinars
      • Events
      • Whitepapers
      • Blogs
      • Newletters
      • Videos
      • Customer Stories
      • Training Videos
      • Competitive Campaigns
        • Juniper Replacement
        • Open Networking Alternative to Vendor-Locked Solutions
        • Top Alternative to Enterprise SONiC
        • Open Networking for Broadcast and Post Production
        • Data Center with OcNOS
  • Documentation
      • OcNOS Feature Matrix
      • Hardware Compatibility List
      • Coherent Transceiver Bundles
      • Product Collateral Library
      • Application Notes
      • Product Documentation
        • OcNOS for Service Providers Documentation
        • OcNOS for Data Centers Documentation
        • OcNOS for Routed Optical Networks Documentation
        • IP Maestro Documentation
      • Supported Hardware Datasheets
      • Product Life Cycle
        • EoS/EoL Listings
        • EoS/EoL Process
  • Company
      • About
      • Global Locations
      • Leadership Team
      • Industry Associations
      • Careers
      • Customer Stories
  • Support
      • Technical Assistance
      • Resources
      • EULA
      • Partners
      • Contact
  • How to Buy

IP Infusion

Transform your network with our expertise in network disaggregation

  • Products
      • OcNOS®
        • – Service Provider
        • – Data Center
      • IP Maestro
      • OcNOS Flex
      • OcNOS CP
      • Broadcom Development Collaborator
  • Solutions
      • Access
        • CSR
        • Unified Access
      • Aggregation
        • Segment Routing
        • Broadband Aggregation
        • Cloud and SP WAN
      • Data Center
        • Data Center Fabric
        • AI Networking
        • Data Center Interconnect
      • IPoDWDM Transport
      • DDoS Protection and Network Security
  • Partners
  • Resources
      • Press Releases
      • News Coverage
      • Webinars
      • Events
      • Whitepapers
      • Blogs
      • Newletters
      • Videos
      • Customer Stories
      • Training Videos
      • Competitive Campaigns
        • Juniper Replacement
        • Open Networking Alternative to Vendor-Locked Solutions
        • Top Alternative to Enterprise SONiC
        • Open Networking for Broadcast and Post Production
        • Data Center with OcNOS
  • Documentation
      • OcNOS Feature Matrix
      • Hardware Compatibility List
      • Coherent Transceiver Bundles
      • Product Collateral Library
      • Application Notes
      • Product Documentation
        • OcNOS for Service Providers Documentation
        • OcNOS for Data Centers Documentation
        • OcNOS for Routed Optical Networks Documentation
        • IP Maestro Documentation
      • Supported Hardware Datasheets
      • Product Life Cycle
        • EoS/EoL Listings
        • EoS/EoL Process
  • Company
      • About
      • Global Locations
      • Leadership Team
      • Industry Associations
      • Careers
      • Customer Stories
  • Support
      • Technical Assistance
      • Resources
      • EULA
      • Partners
      • Contact
  • How to Buy

Logo

DDoS Protection and Network Security

Detect and mitigate attacks within 2 seconds with OcNOS and FastNetMon.

Discover Key Advantages in Solution Brief

DDoS ATTACKS ARE EVOLVING

+358% Surge in Attack Frequency

DDoS attacks surged 358% in 2025 versus 2024, showing the rapid rise in frequency and sophistication of modern threats.

6 Tbps+ Peak Attacks

Volumetric floods have now reached over 6 Tbps, exceeding both the capacity and economics of legacy scrubbing appliances.

2 Seconds Required Response Time

Manual mitigation is no longer viable. Only real-time automated protection can stop threats before major damage occurs.

The Solution: OcNOS + FastNetMon

The IP Infusion OcNOS + FastNetMon solution delivers fully automated, carrier-grade DDoS defense using a modern disaggregated architecture.
It combines two core components: OcNOS (carrier-grade NOS on cost-effective whitebox routers) and FastNetMon (intelligent software detection and mitigation platform).
OcNOS + FastNetMon disaggregated DDoS defense architecture

Operational Simplicity

Fully automated closed-loop protection with zero manual intervention and seamless integration into existing networks.

Agile Scalability

Independently scale detection or enforcement as your network grows – without hardware rip-and-replace.

Lower Total Cost

Up to 75% TCO reduction by replacing proprietary appliances with open whitebox hardware and software.

Discover Key Advantages in Solution Brief
See Full Config in Application Note

HOW IT WORKS

OcNOS + FastNetMon provides the complete fix: A closed-loop automated defense that detects threats via real-time telemetry and stops attacks with BGP signaling directly at the edge in under 2 seconds.

OcNOS + FastNetMon disaggregated DDoS defense

Closed-Loop DDoS Defense with OcNOS and FastNetMon

1. Detect

OcNOS routers sample traffic at line rate using ASIC-accelerated sFlow/IPFIX telemetry (out-of-band, no performance impact).

2. Analyze

FastNetMon ingests the telemetry, correlates flows in real time, and identifies anomalies using behavioral thresholds.

3. Mitigate

FastNetMon automatically pushes standards-based BGP FlowSpec (surgical filtering) or RTBH (instant null-route) rules to all OcNOS routers for line-rate hardware enforcement.

4. Recover

Rules auto-withdraw when the attack ends. The system logs the event, restores normal traffic, and continuously improves detection accuracy.

 

See Full Config in Application Note
Get the Architecture Review

How it Compares to Legacy Solutions

 

Feature OcNOS + FastNetMon (Disaggregated) Traditional (Monolithic) Appliances
Architecture  OcNOS on whitebox routers + FastNetMon software (VM) Single proprietary “black box” appliance
Telemetry & Enforcement OcNOS exports ASIC-accelerated sFlow/IPFIX telemetry and enforces BGP rules at line rate while FastNetMon performs real-time analysis Bundled inline “scrubber” appliance
Control Plane Decoupled: FastNetMon software (VM) performs detection, analysis, and policy generation Bundled inside the appliance
Traffic Path Out-of-band telemetry + direct edge mitigation (no rerouting, zero added latency) Requires inline processing or diversion to central scrubbing center
Scalability True scale-out: Add detection VMs or routers independently Limited scale-up: Must replace entire expensive chassis
Standards 100% open standards (BGP FlowSpec, RTBH, sFlow, IPFIX) – full interoperability Often proprietary methods and vendor lock-in
Cost Model Cost-efficient whitebox hardware + flexible software (up to 75% TCO savings) High-cost proprietary hardware with vendor lock-in

Get the Architecture Review

Frequently Asked Questions

Does this replace appliances like Arbor or Radware?

Yes. By moving detection to FastNetMon software and mitigation to the OcNOS router ASIC, you achieve equal or better performance for volumetric and L3/L4 attacks at up to 75% lower cost.

Do I need inline hardware for this to work?

No. The solution uses a pure out-of-band architecture. Only metadata (sFlow/IPFIX) is sent to FastNetMon – there is no inline bottleneck or single point of failure.

What are the deployment options for FastNetMon?

FastNetMon can be deployed as a VM (VMware, KVM, Proxmox, Hyper-V) or on bare-metal x86 servers. For terabit-scale networks, it supports a clustered architecture.

How many FlowSpec rules can the hardware support?

This depends on the ASIC in your whitebox router. Typical TCAM capacity ranges from 1,000 to 10,000 concurrent rules – enough for most production DDoS events.

Does this support multi-homing and multi-AS deployments?

Yes. Because mitigation uses standard BGP signaling, the solution integrates seamlessly with complex peering edges, multi-homed environments, and multi-AS architectures.

Does this handle multi-tenant or customer-specific attacks?

Yes. You can define per-prefix, per-ASN, or per-customer thresholds, enabling targeted detection and mitigation without affecting unrelated traffic.

Does this help protect peering and transit links?

Yes. It is commonly used on peering, IX, and upstream links to detect abnormal patterns and apply early mitigation before congestion impacts other services.

Does this support encrypted traffic analysis?

Yes. The solution works on flow metadata and behavioral patterns. It does not decrypt payloads, which is sufficient and effective for volumetric and protocol-level attacks.

What visibility does the solution provide during an attack?

Real-time dashboards, traffic graphs (PPS/BPS/flows), top talkers, target prefixes, attack timelines, and full forensic logs for post-incident analysis.

What happens if the FastNetMon VM fails?

The BGP session times out (default 90 seconds) and OcNOS automatically withdraws all mitigation rules, restoring normal traffic flow with no manual intervention required.

What about IPv6 support?

FastNetMon can analyze IPv6 traffic and apply RTBH mitigation. Selective FlowSpec filtering for IPv6 is not yet supported on OcNOS (as of 7.0).

OcNOS® Virtual Machine

Free Download

Get Started Today!

Speak with an IP Infusion expert to discuss your specific needs and learn how we can help you unlock the full potential of your network with open networking solutions.

ipinfusion
  • Products
    • OcNOS®
      • – Service Provider
      • – Data Center
    • IP Maestro
    • OcNOS Flex
    • OcNOS CP
    • Broadcom Development Collaborator
  • Solutions
    • Access
    • CSR
    • Aggregation
    • Data Center
  • Resources
    • Press Releases
    • Webinars
    • Events
    • Whitepapers
    • Blog
    • Newsletters
    • Videos
    • Case Studies
    • Competitive Campaigns
  • Documentation
    • OcNOS Feature Matrix
    • Hardware Compatibility List
    • Coherent Transceiver Bundles
    • Product Collateral Library
    • Application Notes
    • Product Documentation
    • Supported Hardware Datasheets
    • Product Life Cycle
  • Company
    • About
    • Global Locations
    • Leadership Team
    • Industry Associations
    • Our Customers
    • Careers
  • Support
    • Technical Assistance
    • Resources
    • EULA
    • Partners
    • Contact
    • Newsletter Signup
Copyright © 2026 IP Infusion. All Rights Reserved. Privacy | Terms of Use | Cookie Policy
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies. Read More
In case of sale of your personal information, you may opt out by using the link:  .
Cookie SettingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-advertisement1 yearSet by the GDPR Cookie Consent plugin, this cookie is used to record the user consent for the cookies in the "Advertisement" category .
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
CookieLawInfoConsent1 yearRecords the default button state of the corresponding category & the status of CCPA. It works only in coordination with the primary cookie.
JSESSIONIDsessionThe JSESSIONID cookie is used by New Relic to store a session identifier so that New Relic can monitor session counts for an application.
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
wordpress_test_cookiesessionThis cookie is used to check if the cookies are enabled on the users' browser.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
CookieDurationDescription
bcookie1 yearLinkedIn sets this cookie from LinkedIn share buttons and ad tags to recognize browser ID.
bscookie1 yearLinkedIn sets this cookie to store performed actions on the website.
langsessionLinkedIn sets this cookie to remember a user's language setting.
lidc1 dayLinkedIn sets the lidc cookie to facilitate data center selection.
li_gc5 months 27 daysLinkedin set this cookie for storing visitor's consent regarding using cookies for non-essential purposes.
UserMatchHistory1 monthLinkedIn sets this cookie for LinkedIn Ads ID syncing.
visitorId1 yearZoomInfo sets this cookie to identify a user.
__cf_bm30 minutesThis cookie, set by Cloudflare, is used to support Cloudflare Bot Management.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
CookieDurationDescription
_gat1 minuteThis cookie is installed by Google Universal Analytics to restrain request rate and thus limit the collection of data on high traffic sites.
__utma2 yearsThis cookie is set by Google Analytics and is used to distinguish users and sessions. The cookie is created when the JavaScript library executes and there are no existing __utma cookies. The cookie is updated every time data is sent to Google Analytics.
__utmb30 minutesGoogle Analytics sets this cookie, to determine new sessions/visits. __utmb cookie is created when the JavaScript library executes and there are no existing __utma cookies. It is updated every time data is sent to Google Analytics.
__utmcsessionThe cookie is set by Google Analytics and is deleted when the user closes the browser. It is used to enable interoperability with urchin.js, which is an older version of Google Analytics and is used in conjunction with the __utmb cookie to determine new sessions/visits.
__utmz6 monthsGoogle Analytics sets this cookie to store the traffic source or campaign by which the visitor reached the site.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
CookieDurationDescription
AnalyticsSyncHistory1 monthLinkedin set this cookie to store information about the time a sync took place with the lms_analytics cookie.
CONSENT2 yearsYouTube sets this cookie via embedded youtube-videos and registers anonymous statistical data.
pardotpastThe pardot cookie is set while the visitor is logged in as a Pardot user. The cookie indicates an active session and is not used for tracking.
vuid2 yearsVimeo installs this cookie to collect tracking information by setting a unique ID to embed videos to the website.
_ga2 yearsThe _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors.
_gat_gtag_UA_144639687_11 minuteSet by Google to distinguish users.
_ga_VZ8HYV5ELY2 yearsThis cookie is installed by Google Analytics.
_gid1 dayInstalled by Google Analytics, _gid cookie stores information on how visitors use a website, while also creating an analytics report of the website's performance. Some of the data that are collected include the number of visitors, their source, and the pages they visit anonymously.
__utmt_sfga10 minutesSet by Google Analytics and Google Tag Manager to enable website owners to track visitor behaviour and measure site performance.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
CookieDurationDescription
VISITOR_INFO1_LIVE5 months 27 daysA cookie set by YouTube to measure bandwidth that determines whether the user gets the new or old player interface.
YSCsessionYSC cookie is set by Youtube and is used to track the views of embedded videos on Youtube pages.
yt-remote-connected-devicesneverYouTube sets this cookie to store the video preferences of the user using embedded YouTube video.
yt-remote-device-idneverYouTube sets this cookie to store the video preferences of the user using embedded YouTube video.
_fbp3 monthsThis cookie is set by Facebook to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising, after visiting the website.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
CookieDurationDescription
AWSALBAPP-07 daysNo description
AWSALBAPP-17 daysNo description
AWSALBAPP-27 daysNo description
AWSALBAPP-37 daysNo description
DEVICE_INFO5 months 27 daysNo description
guestidcsessionNo description
ln_or1 dayNo description
lpv90027130 minutesNo description
visitor_id90027110 yearsNo description
visitor_id900271-hash10 yearsNo description
_cfuvidsessionNo description
Save & Accept