Carrier-grade performance, from the NIC driver to the dashboard
A Rust engine with no garbage collector, eBPF/XDP filters running in the NIC driver and a columnar database built for billions of flows. It all runs on your own server, with no third-party cloud involved in detection or mitigation.
- automated tests in the core
- 1,198
- attack vectors decoded
- 50
- analytical tables in ClickHouse
- 125
- materialized views
- 20
- reflectors blocked in XDP
- 13
- REST API v1 endpoints
- 46
How the data flows
Telemetry comes in on the left, the engine decides every 10 s, and the response goes back to the edge over BGP or through the scrubber. Everything is stored in ClickHouse: flows, attacks, decisions and the audit trail.
Swipe sideways to see the whole diagram.
- Edge routersJuniper, Huawei, MikroTik, Cisco and any device that exports flow data.
- CollectorNetFlow, IPFIX and sFlow on
UDP 2055/6343, BMP onTCP 11019, SNMP and packet capture. - EnrichmentASN, GeoIP, rDNS, TLS probe, passive DNS, tunnel decoder and port → provider map.
- Analysis engine10 s cycle, configurable down to 1 s: decoders, thresholds, baseline, burst, carpet bombing, spoofing, RPKI/IRR and threat intel.
- DecisionDeterministic cascade with a CGNAT lock and a ceiling of 80% of the scrubber's measured capacity.
- ActionGoBGP or ExaBGP announce to the routers; the XDP/nftables scrubber cleans; the mitigation provider takes whatever doesn't fit.
- Dashboard and integrationsWeb UI, REST API v1, email, Telegram, webhook, Syslog and SNMP Trap.
Chosen so it doesn't choke in the middle of an attack
Each piece does one job, in the place where it pays off most. None of them needs an external service to work.
Rust + TokioThe engine
Collection, analysis, decision and mitigation in a single async binary, with no garbage collector and no pauses mid-attack. The release build uses LTO and jemalloc and is hardened against reverse engineering.
eBPF/XDP with ayaThe data plane
Filter and scrubber run in the NIC driver, before the Linux network stack. A destination that isn't under mitigation passes with a single hash lookup.
ClickHouseFlows and history
Columnar database for billions of flows, with millisecond queries and roughly 10:1 compression. It also holds the mitigation queue, the decisions and the audit trail.
MariaDB / MySQLUsers and configuration
Users and roles, dashboards, Managed Objects, API keys and scheduled reports.
RedisHot state
Statistical baselines and real-time alerts. After a restart, the engine restores baselines from Redis instead of relearning the network from scratch.
GoBGP v3 / ExaBGPBGP sessions
GoBGP over native gRPC, or ExaBGP. The configuration generated by the UI shows a diff before it is applied and can be rolled back.
Next.js 16 + React 19User interface
More than 60 screens in Brazilian Portuguese, light and dark themes, an in-browser SSH terminal, drag-and-drop dashboards and built-in Swagger UI.
Keep the decision-maker away from the box that takes the hit
The same installation package runs in three roles, selected by one line in config.toml. Nodes talk to each other through the mitigation queue in ClickHouse, with no proprietary protocol.
| Function | All-in-onethe default | Analyzerout of the traffic path | Scrubberin the path of diverted traffic |
|---|---|---|---|
| Receives flows and detects | Yes | Yes | No, the collector binds to loopback only |
| Decides and announces over BGP | Yes | Yes | No |
| Filters with XDP and nftables | Yes | Never touches the local filter | Yes, reading the mitigation queue |
| Web UI and API | Yes | Yes | No, it runs lean |
| When to use it | Single network, one server for everything | Separate the intelligence from the box that receives the attack | Dedicated scrubbing appliance, with a node quota in the license |
Health watchdog: a diversion never turns into a black hole
The analyzer polls the scrubber's /health every 10 s. After 3 consecutive failures, active diversions are withdrawn and no new ones are announced. On the first good response, everything comes back. The scrubber returns 503 if the filter failed to load or if the node is outside the license quota.
- responds
- responds
- 1st failure
- 2nd failure
- 3rd failure
- diversions withdrawn
- diverting again
Filtering in the NIC driver
The EdgeWarden XDP program runs before the Linux network stack. With an empty map, the machine behaves as if the filter weren't there, so it is safe to install. Any failure lets the packet through; it never causes a drop. Included in the Enterprise plan.
L3/L4 sanity
Drops martian addresses, fragments and impossible flag combinations.
Amplification
Blocks 13 well-known reflectors by source port and minimum packet size.
13 reflectorsPer-source rate limit
Token bucket per source address, for botnets and reflectors using real IPs.
up to 65,536 sourcesSYN protection New
Drops the first SYN and lets through clients that retransmit, without turning the scrubber into a reflector the way SYN cookies would.
Per-destination limit
Traffic ceiling per victim, adjustable per customer in the Managed Object.
up to 16,384 victimsContent signatures New
4- or 8-byte UDP signatures plus port, defined by the operator, with a counter per signature.
up to 1,024 signaturesThe 13 reflectors blocked in the driver
UDP source port. QUIC on UDP/443 is left out on purpose: it is handled by the QUIC detector and by FlowSpec.
- QOTD17
- chargen19
- DNS53
- portmap111
- NTP123
- NetBIOS137
- SNMP161
- CLDAP389
- RIPv1520
- SSDP1900
- WS-Discovery3702
- mDNS5353
- memcached11211
Observe mode. With a heuristic switched off, the filter counts what it would drop without dropping anything, and the Data plane (Plano de dados) panel shows hits per heuristic every minute. Carpet bombing over IPv4 and IPv6 is handled per prefix, with the victim looked up in an LPM trie.
100G reference scrubbing center
The reference deployment uses a Dell PowerEdge R760 with two NVIDIA/Mellanox ConnectX-6 Dx cards (4 × 100G ports), Debian 13 and kernel 6.12 LTS. Each router gets one 100G port, or 200G over LACP using one port from each card, which keeps the service up even if an entire card fails.
- 100G/200G architecture per router, with capacity validated in each deployment
- Drops in the tens of Mpps per port with a native-XDP NIC
- Loop-free path by design:
/32or/128diversion with a community andNO_EXPORT; clean traffic returns through a table that never contains the diversion - Stock kernel
mlx5driver, no vendor package to install - Recommended NICs: Mellanox ConnectX-5/6 and Intel E810 at the high end; X710, X520/X540 and ConnectX-4 for best value
Two deployment modes
| Item | Mode A: everything on the R760 | Mode B: separate analyzer recommended |
|---|---|---|
| On the R760 | Collector, ClickHouse, MariaDB, UI, GoBGP and XDP | Only the core with XDP |
| BGP with the edge | The R760 itself | The analyzer |
| Health watchdog | Not needed | Required |
Edge routers with a clean-path template
One port per router, dirty and clean traffic on the same cable; an input filter sends clean traffic to the CLEAN routing-instance. IPv4 and IPv6.
VRP8 template written from the official documentation, with one dirty port and one clean port. It still needs lab validation.
Measured capacity, not promised capacity. Clean forwarding capacity is measured in each deployment and recorded in the system. EdgeWarden only diverts up to 80% of the measured value; above that, the decision falls through to external scrubbing, then FlowSpec on the vector and, as a last resort, RTBH.
Open protocols, real-world vendors
Any router that exports flow data and speaks BGP FlowSpec or RTBH is covered by the standard features. Vendor-specific features are listed below, with no overstatement.
Collection and telemetry
- NetFlow v5
- NetFlow v9RFC 3954
- IPFIXRFC 7011
- sFlow v5
- SNMP v1/v2c/v3
- BMPRFC 7854
- libpcap · AF_PACKET v3
- AF_XDP · DPDKcoming soon
Mitigation
- BGP FlowSpecRFC 5575/8955
- RTBH
- GoBGPgRPC
- ExaBGP
- eBPF/XDP
- nftables
Route validation
- RPKI/RTR
- IRRRIPE · RADb
Decoded tunnels
- VxLAN
- GENEVE
- GRE
- L2TP
- IP-in-IP
- MPLS-in-UDP
| Vendor | Standard flow and BGP | Vendor-specific features |
|---|---|---|
| JuniperJunOS, MX | Yes | FlowSpec and RTBH in production, IPv4/IPv6 scrubbing templates, firewall counters (JUNIPER-FIREWALL-MIB), static filter hardening, PBR via prefix-list, SSH terminal |
| HuaweiVRP8, NE40E/NE8000 | Yes | PBR via ACL and SSH terminal. Scrubbing template written, awaiting lab validation |
| MikroTikRouterOS | Yes | PBR via address-list and SSH terminal |
| CiscoIOS, IOS-XR | Yes | In-browser SSH terminal. No automatic PBR |
| Nokia, Arista and others | Yes | No vendor-specific integration: they work through NetFlow/IPFIX/sFlow and BGP FlowSpec/RTBH |
Plug it into your NOC, Zabbix, SIEM or customer portal
REST API v1 documented in OpenAPI/Swagger: 46 endpoints, scoped keys, per-IP and per-customer restrictions, rate limiting and webhooks.
- Swagger UI built in at
/api-docs, which works even on an appliance with no internet access - The key is shown only once; the server stores only its SHA-256 hash
- Scopes for traffic, flows, attacks, violations, mitigations, Managed Objects, reports and system
- Apply FlowSpec, RTBH, diversion or external scrubbing with a
POST, under the same safeguards as the UI - Default limit of 120 requests per minute per key, answered with
429andRetry-After - Zabbix-ready health check at
/api/v1/system/health
# example key: create yours under Configurações → Chaves de API (Settings → API Keys) export EW=https://edgewarden.example.net export FSK=fsk_a1b2c3d4e5f60718_YOUR_SECRET curl -s -H "Authorization: Bearer $FSK" \ "$EW/api/v1/attacks?status=active&hours=1" { "data": [{ "target_ip": "203.0.113.9", "attack_type": "udp_flood", "severity": "high", "status": "active", "bytes_per_sec": 3750000000, "source_count": 18422, "zone_group": "AS65000-CUSTOMERS", "zone_cidr": "203.0.113.0/24" }], "pagination": { "page": 1, "total": 1 } }
The response above is abbreviated. Mitigations requested through the API are queued as pending, and the core applies them on the next cycle, in about 10 s.
Alerts arrive without anyone having to ask
Each Managed Object can have its own channels. Use the API to enrich the event, not to find out about the attack.
- Syslog and SIEMEvents in
CEF,JSONorRFC 5424, over UDP or TCP. - SNMP Trap v2cFor Zabbix, PRTG, LibreNMS and SolarWinds, with encoding that holds up under bursts.
- TelegramTarget, vector and action taken, straight to the NOC group.
- EmailThrough your own SMTP server, with scheduled reports and Attack Analyst (Analista de Ataques) bulletins.
- Webhook
attack_detectedevent in JSON, posted to your system. - Slack and TeamsThrough the channel's incoming webhook.
Your network doesn't stop because a license server went down
Licensing
- License signed with Ed25519 and verified offline
- Heartbeat every 24 h, plus a 30-day grace period with no contact with the server
- Hardware fingerprint that survives bonding, LACP and VLANs
- The binary is the same on every plan; the license unlocks the features and the quota of routers and scrubbing nodes
The server itself
- Services run as
www-data, without sudo, with only the capabilities they need:CAP_NET_RAWCAP_NET_BIND_SERVICECAP_BPFCAP_NET_ADMIN - Router credentials encrypted with AES-256-GCM; SSH to the edge is implemented in pure Rust
- A unique session secret generated on each installation
- Host firewall in nftables, editable from the UI
- Updates verified with
sha256sum, keeping configuration and logs, with rollback
Recommended sizing
Pick the tier based on your network's flow volume. The installation guide has the commands for every step, from sysctl to HTTPS.
| Resource | SmallRegional ISP | Medium recommendedISP / mid-size DC | EnterpriseTier-1 / large DC |
|---|---|---|---|
| Volume | Up to 20K flows/s, networks up to ~5 Gbps | Up to 50K flows/s, networks up to ~20 Gbps | 100K+ flows/s, networks of 40 Gbps+ |
| CPU | 8 cores (Xeon / EPYC) | 16 cores (Xeon Scalable / EPYC) | 32+ cores (EPYC / Xeon Platinum) |
| RAM | 32 GB DDR4 | 64 GB DDR4 ECC | 128+ GB DDR4/DDR5 ECC |
| Disk | 500 GB NVMe SSD | 2 TB NVMe SSD | 4+ TB NVMe (RAID 10) |
| Network | 1 Gbps | 10 Gbps | 25 / 40 / 100 Gbps |
| OS | Debian 13+ (Trixie) | Debian 13+ (Trixie) | Debian 13+ (Trixie) |
- eBPF/XDP: Debian 13 already ships kernel 6.x; use a NIC with native XDP (Mellanox or Intel recommended).
- ClickHouse: from the Medium tier up, move it to a dedicated server.
- Retention: size the disk for the retention period you need (compression is around 10:1).
- High availability: for Enterprise, a cluster of 2 or more nodes is recommended.
The architecture checks out. Ready to see it on your network?
We'll show you EdgeWarden running on flows from your own routers, and you get a demo license with every Enterprise feature for 7 days. The demo and support are in Portuguese.