hardware & sizing

The right server depends on its role

EdgeWarden is a single package that runs as all-in-one, analyzer or scrubber, set by one line in config.toml. Each role leans on a different resource: the box that analyzes lives on disk and memory; the box that scrubs traffic lives on the NIC and CPU cores.

Applies to every role

OS
Debian 13 (Trixie), kernel 6.12
Architecture
x86_64
Software
Same package and same binary in all three roles; the license sets the scrubbing-node quota
NIC for filtering
Native XDP in the driver: mlx5, ice, i40e or ixgbe
demand by role

Where each role puts the load

A relative scale across roles to guide purchasing. Exact numbers depend on flow volume, retention and how much traffic crosses the filter.

Relative CPU, RAM, disk and network demand by node role
Role CPU RAM Disk Network What drives it
All-in-onethe default Mediumgrows with flows/s High Highgrows with retention Lowvery high if it filters inline Collection, analysis, databases, UI and filter on the same box. In a typical install it only receives flow samples and announces FlowSpec; the router does the dropping. If it also filters inline, add the scrubber's demand.
Analyzerout of the traffic path Mediumgrows with flows/s High Highgrows with retention Low Runs ClickHouse, MariaDB, Redis, GoBGP and the UI. It only receives flow samples, so the NIC barely matters; ClickHouse wants NVMe and free memory for the page cache, and swap kills latency.
Scrubberin the diverted traffic path Very highper core, on the NIC's NUMA node Low Lowno local databases Very highnative XDP, PCIe x16 Just the core with the XDP filter: no databases, no BGP, no UI. What counts is a NIC with native XDP, physical cores on the NIC's NUMA node and a PCIe x16 slot of a recent enough generation.
Packet Sensoroptional module (SPAN/TAP) High Medium Medium High Packet capture for sub-second detection and to read SNI, DNS and HTTP Host. It isn't a role: it adds to the all-in-one or analyzer (the scrubber turns it off). Estimated order of magnitude per engine: libpcap ~1–2 Gbps and AF_PACKET v3 ~5 Gbps; AF_XDP capture and a DPDK engine are coming soon.

Low, Medium, High and Very high compare the roles with each other; they are not measurements.

On the scrubber, less is more. The scrubbing node uses the same package, but only the core runs. Don't install MariaDB, Redis, ClickHouse, Apache, PHP, Node.js, GoBGP or certbot: it reads the mitigation queue from the analyzer's ClickHouse.

Firewall with nftables only, never ufw, which would drop the clean traffic.

two nodes

One node out of the path, one in it

When you scrub traffic, the recommended mode separates the box that decides from the box that takes the attack. That's why each machine has a different shopping list.

Two nodes: the analyzer out of the traffic path and the scrubber in the diverted traffic path The edge router sends flow samples to the analyzer, which announces the victim's diversion over BGP. The router hands the diverted traffic to the scrubber through the dirty port; the scrubber filters it with XDP and returns clean traffic through the clean port, which continues to the customer network. The analyzer polls the scrubber's /health every 10 seconds, and both nodes share the mitigation queue in ClickHouse. Internet victim + attack Edge router main table + CLEAN Customer network 203.0.113.10 clean flow samples NetFlow · sFlow BGP divert /32 · /128 dirty port (diversion) clean port (CLEAN) Analyzer out of the traffic path collector · detection · GoBGP ClickHouse · MariaDB · Redis web UI and API load: NVMe disk and RAM Scrubber in the diverted traffic path core + XDP filter in driver no databases, no BGP, no UI returns clean traffic load: NIC and CPU cores GET /health · 10 s 3 failures: withdraw mitigation queue ClickHouse :8123 Two nodes: the analyzer out of the traffic path and the scrubber in the diverted traffic path The edge router sends flow samples to the analyzer, which announces the victim's diversion over BGP. The router hands the diverted traffic to the scrubber through the dirty port; the scrubber filters it with XDP and returns clean traffic through the clean port, which continues to the customer network. The analyzer polls the scrubber's /health every 10 seconds, and both nodes share the mitigation queue in ClickHouse. Internet victim + attack Customer 203.0.113.10 Edge router main + CLEAN flows BGP dirty clean Analyzer out of the path collector · detection GoBGP · ClickHouse MariaDB · Redis · UI load disk and RAM Scrubber in the diverted path core + XDP filter no databases no BGP, no UI load NIC and CPU cores GET /health · 10 s mitigation queue ClickHouse :8123
Mode B, the recommended setup for scrubbing. On Juniper MX, the dirty and clean ports share the same cable; on Huawei NE40E/NE8000 they are two separate ports.
  • AnalyzerReceives flow samples from the router, detects, and announces the victim's /32 or /128 diversion over BGP, with the scrubber as next hop.
  • Dirty portThe router hands the scrubber only the diverted victim's traffic, not the whole network.
  • Clean portWhatever passes XDP goes back to the router through the CLEAN table, which never contains the diversion. No loop.
  • Health watchdogThe analyzer polls the scrubber's /health every 10 s. Three consecutive failures withdraw the active diversions; one good response allows diversion again.
  • Mitigation queueThe two nodes talk through the analyzer's ClickHouse. Port 8123 is open only to the scrubber; 8090, for /health, only to the analyzer.
reference sizes

Three sizes, by flow volume

These sizes are for the box that collects and analyzes (all-in-one or analyzer). The scrubber is sized by its NIC, covered in the next sections.

Small

Regional ISP

Up to 20K flows/snetworks up to ~5 Gbps

CPU
8 cores (Xeon / EPYC)
RAM
32 GB DDR4
Disk
500 GB NVMe SSD
Network
1 Gbps
OS
Debian 13+ (Trixie)

Medium

recommended

ISP / mid-size DC

Up to 50K flows/snetworks up to ~20 Gbps

CPU
16 cores (Xeon Scalable / EPYC)
RAM
64 GB DDR4 ECC
Disk
2 TB NVMe SSD
Network
10 Gbps
OS
Debian 13+ (Trixie)

Enterprise

Tier-1 / large DC

100K+ flows/snetworks of 40 Gbps+

CPU
32+ cores (EPYC / Xeon Platinum)
RAM
128+ GB DDR4/DDR5 ECC
Disk
4+ TB NVMe (RAID 10)
Network
25 / 40 / 100 Gbps
OS
Debian 13+ (Trixie)
  • eBPF/XDP: Debian 13 already ships kernel 6.x; use a NIC with native XDP (Mellanox or Intel recommended).
  • ClickHouse: from the Medium size up, move it to a dedicated server.
  • Retention: size the disk for the retention period you need (compression is around 10:1).
  • High availability: for Enterprise, a cluster of 2 or more nodes is recommended.
scrubbing center

Reference scrubbing center: Dell PowerEdge R760

The build documented in detail for scrubbing traffic at 100G. An equivalent server follows the same logic: one NIC per CPU, an x16 slot and native XDP.

NICs
2 × NVIDIA/Mellanox ConnectX-6 Dx (MCX623106A) with two 100G ports each: 4 × 100G. ConnectX-5 Ex, ConnectX-6 and ConnectX-7 also work.
Slots
One NIC per CPU: slots 2 + 7 (PCIe Gen5 x16) or 3 + 6 (Gen4 x16).
Cabling
Today, one router per scrubber: a single 100G port, or LACP with one port from each NIC (200G), which stays up even if an entire NIC fails. The other routers divert through that one over a clean VLAN. Direct cabling to several routers (up to 4 Juniper or 2 Huawei): coming soon.
OS
Debian 13, kernel 6.12 LTS with BTF, intel_iommu=on iommu=pt, no irqbalance, and the kernel's own mlx5 driver (no MLNX_OFED).
BIOS
Performance profile, Sub-NUMA Cluster off, SR-IOV off.
NIC tuning
One queue per physical core on the NIC's NUMA node, 4096-entry rings, LRO and hardware GRO off, mq qdisc and pinned IRQ affinity, reapplied at boot by a systemd unit.
Management
Out-of-band iDRAC; host management goes over the data port.

Two deployment modes

Scrubbing center deployment modes
ItemMode A: everything on the R760Mode B: separate analyzer recommended
On the R760Collector, ClickHouse, MariaDB, UI, GoBGP and XDPOnly the core with XDP
BGP with the edgeThe R760 itselfThe analyzer
Health watchdogNot neededRequired

Edge routers with a clean-path template

Juniper MXValidated in production

One port per router, dirty and clean on the same cable; an input filter sends clean traffic to the CLEAN routing instance. IPv4 and IPv6.

Huawei NE40E / NE8000Validation pending

VRP8 template written from the official documentation, with one dirty and one clean port. It still needs lab validation.

Capacity: what we can claim

148.8Mpps

Line rate of one 100G port with 64-byte frames: the worst case the filter has to face.

~24Mpps

XDP drop rate per core in the literature (XDP paper, CoNEXT 2018, ConnectX-5 Ex). reference, not an EdgeWarden benchmark

80%

Diversion ceiling over the capacity measured in your deployment. Above that, the decision falls through to external scrubbing, FlowSpec on the vector and, as a last resort, RTBH.

100G/200G architecture per router, with capacity validated in each deployment. Dropping is cheap; clean traffic that gets forwarded costs an order of magnitude more and has no published figure. That's why capacity is measured at install time and recorded in the system, and the 80% ceiling applies to that number.

network cards

Native XDP is what counts

The filter runs in the NIC driver. Without native support, EdgeWarden falls back to generic mode (SKB): it works, but packets only get filtered after the kernel has already spent cycles on them.

Recommended NICs for eBPF/XDP
NICDriverSpeedXDPNotes
Top tier
Mellanox ConnectX-5 / 6mlx525G / 100GNativeThe best native XDP support. For two 100G ports at once, use ConnectX-5 Ex, ConnectX-6 Dx or ConnectX-7.
Intel E810ice25G / 100GNativeIntel's current generation, with full XDP.
Best value (production)
Intel X710i40e10G / 40GNativeExcellent XDP support, widely tested.
Intel X520 / X540ixgbe10GNativeOlder, but solid XDP and easy to find used.
Mellanox ConnectX-4mlx510G / 25GNativeGreat price on the used market.
Lab
Intel I350 / I210igb1GBasicGood for testing.
virtio-netvirtioVMTestingFor testing in KVM VMs.

To take real attack traffic, the minimum is an Intel X520 (10G); ideally, a Mellanox ConnectX-5 (25G).

200 Gbps requires PCIe 4.0 x16. The plain ConnectX-5 (MCX516A-CCAT, PCIe Gen3) can't sustain two 100G ports at once, and in an x8 slot no NIC delivers its rated throughput.

In a VM with vmxnet3, native XDP needs kernel 6.3 or newer; below that, generic mode only. Expect something in the 1–2 Gbps range.

Identify the NIC by its driver, never by MAC address: we've seen a Mellanox OUI on an Intel card.

verification

How to check the server

Read-only commands: they change nothing on the NIC or the system. The actual tuning (rings, queues, IRQs) is in step 11 of the installation guide and needs a maintenance window.

bash · read-only
IF=eth0   # data plane interface (the one receiving dirty traffic)

# NIC driver: decides whether XDP can run natively
ethtool -i $IF | grep driver

# NIC's NUMA node (0 or 1; -1 = BIOS without SLIT)
cat /sys/class/net/$IF/device/numa_node

# Which mode did XDP come up in? (with the core running)
ip -d link show $IF | grep -i xdp
#    "xdp"        = native, in the driver — required at this scale
#    "xdpgeneric" = SKB fallback, runs AFTER GRO

# Check whether the NIC is dropping packets (everything should stay at zero)
ethtool -S $IF | grep -iE "drop|discard|miss|nobuf|error" | grep -v ": 0$"

# PCIe slot width and generation
lspci -vv -s $(basename $(readlink /sys/class/net/$IF/device)) | grep -i "LnkSta:"

What to expect

  • Driver mlx5_core, ice, i40e or ixgbe: native XDP available.
  • xdp in the ip link output: the filter is in the driver. If you see xdpgeneric, sort out the NIC or driver before sending real traffic.
  • Counters: no lines from ethtool -S, meaning nothing is being dropped on the NIC.
  • LnkSta: Width x16 and Speed 16GT/s (Gen4) or 32GT/s (Gen5). x8 or Gen3 means the wrong slot or riser, at half the bandwidth.
  • NUMA: use only cores on the NIC's node; 16 queues on the right node beat 64 spread across both.

Need help with sizing?

Tell us your flow volume, the retention you want to keep and how many routers will divert to scrubbing. The team will recommend the server and NIC for each role. Assistance is provided in Portuguese.