Detect and stop DDoS attacks inside your own network
In-network DDoS protection detects and mitigates attacks at the network edge on the router itself, instead of diverting traffic to an off-path scrubbing center. IP Infusion delivers it as one system: open switches and routers running OcNOS with BGP FlowSpec and RTBH, supported under one contract. sFlow telemetry feeds a FastNetMon detection engine, which pushes FlowSpec or RTBH rules back to the router for line-rate filtering in the ASIC.
Detection-to-mitigation in seconds.
The architecture brief and the deployment app note: the high-level picture plus the step-by-step configuration for BGP Flowspec and RTBH on OcNOS with FastNetMon.
Affordable Automated DDoS Defense: OcNOS + FastNetMon
BGP Flowspec and RTBH on OcNOS with FastNetMon integration: detection-to-mitigation in seconds, sized for regional and enterprise networks.
Get the briefAutomated DDoS Mitigation: Deployment Guide
Step-by-step configuration: BGP Flowspec policies, RTBH triggering, FastNetMon integration with OcNOS, the ready-to-deploy reference.
Get the app noteFilter attack traffic in hardware at the edge, with no traffic diversion.
The router running OcNOS drops attack traffic on the box that already carries the customer, so every packet stays on its normal path and clean traffic never leaves the forwarding plane. There is no off-path scrubbing center to route through, no per-packet detour, and no separate scrubbing capacity to buy and size.
The router running OcNOS with FastNetMon puts detection and mitigation directly at the network edge: sFlow telemetry streams from the router to FastNetMon continuously; when an attack is detected, FastNetMon pushes BGP Flowspec rules back to the router; the router installs the rules in the ASIC hardware at line rate. The entire loop completes in seconds, and clean traffic passes with no added latency.
Attack types detected and mitigated:
FastNetMon: the detection engine that triggers your mitigation
FastNetMon Advanced watches the sFlow the router exports and, the moment traffic crosses a per-host or per-subnet threshold you set, triggers mitigation automatically. It is production-grade software already running at hundreds of ISPs and hosting providers worldwide, so the detection engine on the page is the same one operators trust in production.
BGP FlowSpec: surgical filtering, pushed as a BGP route
When you need to block one attack without touching everything else, the router matches on source and destination IP, protocol, port, packet length, TCP flags, DSCP, and fragment type. The rule arrives over BGP and lands in the ASIC in milliseconds, so it drops, rate-limits, or redirects the matching traffic at line rate with zero CPU overhead. FlowSpec follows RFC 8955.
RTBH: stop a volumetric flood before it reaches you
For a large volumetric attack, the router blackholes the targeted prefix over BGP, either on operator command or automatically when FastNetMon sees traffic to that prefix cross threshold. The RTBH route propagates to your upstream peers and transit providers, so they drop the attack at their edge before it ever ingresses your network.
sFlow: the traffic feed that makes detection possible
The router exports sFlow from every edge interface using hardware-accelerated sampling at a rate you set, so detection sees the traffic without loading the CPU. The same feed goes to FastNetMon for DDoS detection and, at the same time, to Kentik, PRTG, Prometheus, or any sFlow collector you already run for traffic analytics. sFlow follows RFC 3176.
Hardware ACLs: block known bad actors once, forever
For traffic you already know is hostile, the router installs an ACL in the ASIC that permanently drops it by IP, subnet, protocol, or port, and rate-limits per interface, per VLAN, or per prefix. You configure it once and the hardware enforces it from then on, with no routing or processing overhead.
FastNetMon: the detection engine
FastNetMon Advanced is a dedicated DDoS detection engine used by hundreds of ISPs globally. It integrates natively with OcNOS via BGP Flowspec and RTBH. Consumes sFlow telemetry with configurable per-host, per-subnet, and per-protocol thresholds.
Learn about FastNetMon →In-network DDoS detection and mitigation: full topology
Here is where every protection layer sits in a live network. Attack traffic from the internet arrives at the OcNOS edge routers, which stream sFlow to FastNetMon the whole time. The moment FastNetMon sees an anomaly it pushes BGP FlowSpec or RTBH back to the edge, and the router installs the rule in the ASIC in milliseconds. Your upstream peers can take the RTBH announcement too, so they drop the attack before it ever reaches you.
From attack detection to blocked traffic in four steps
The detect-to-mitigate loop runs automatically. Once configured, the network stops an attack without operator intervention.
Collect
OcNOS exports sFlow telemetry from all edge interfaces to FastNetMon. Hardware-accelerated packet sampling: no CPU overhead, no impact on forwarding performance.
Detect
FastNetMon analyzes flow data against per-host and per-subnet thresholds. Identifies volumetric floods, SYN storms, UDP amplification, DNS floods, and NTP reflection attacks, typically in under 1 second.
Signal
FastNetMon automatically pushes BGP Flowspec rules (for surgical mitigation) or RTBH blackhole routes (for volumetric attacks) to OcNOS via BGP. Fully automated: no operator action required during the attack.
Mitigate
OcNOS installs Flowspec rules or RTBH routes directly in the ASIC hardware. Attack traffic is dropped or rate-limited at full line rate. Clean traffic continues unaffected. Rules are removed automatically when the attack subsides.
Where in-network DDoS protection fits
The same edge routers and switches carry DDoS protection whether you run a small regional ISP or a large data center, because the detection and mitigation ride on the box that is already at the edge.
ISP & SP Edge Protection
Protect peering edges and transit links from volumetric DDoS that would saturate customer-facing bandwidth. sFlow detection at the peering router with automatic BGP Flowspec mitigation stops floods before they reach downstream customers. Upstream RTBH coordination with transit providers stops attacks before they enter your network.
Data Center Perimeter
In-line DDoS filtering at the DC border, protecting hosted infrastructure and cloud workloads. Static hardware ACLs block known bad actors permanently. Dynamic Flowspec rules adapt to new attack signatures in real time. No traffic diversion to a scrubbing center means zero latency impact for clean traffic.
Managed DDoS Protection Service
Operators can offer per-customer DDoS protection as a managed service, billing by the protected prefix. FastNetMon supports per-customer threshold profiles. OcNOS enforces per-customer Flowspec rules. No shared scrubbing infrastructure: each customer's protection is dedicated and in-network.
DDoS Protection with OcNOS: FAQ
Protect your network on open hardware.
We'll walk through your topology, your threat model, and the right Flowspec and RTBH configuration for your environment.
Affordable Automated DDoS Defense: OcNOS + FastNetMon
Quick form. Your PDF will download immediately after submit.
✓ Opening your PDF in a new tab…
If it didn't open, use the link below.
solution-brief-automated-ocnos-fastnetmon-ddos-defense.pdfAutomated DDoS Mitigation: OcNOS + FastNetMon Deployment Guide
Quick form. Your PDF will download immediately after submit.
✓ Opening your PDF in a new tab…
If it didn't open, use the link below.
Application-Note-Automated-DDoS-Mitigation-with-OcNOS-and-FastNetMon.pdf