features

Everything you need to see, protect and optimize your network

More than 70 modules across ten pillars, from raw flow to routing decision. They all ship in the same binary: your license unlocks what your plan includes.

full traffic visibility

See every flow, from the last minute to the last month

From raw flow to the executive view: see who talks to whom, over which path and what it costs you. Collects NetFlow v5/v9, IPFIX and sFlow v5, with no dependency on DPI.

  • Real-time dashboard Starter

    Live KPIs, mirrored In/Out traffic, traffic by service, protocols, an attack heat map and overall network status. Click the chart to inspect that exact moment.

  • My Dashboards (Meus Dashboards) Professional New

    Build boards by dragging and resizing 16 widgets, or start from 4 ready-made templates: Security/DDoS, Transit and Peering, Capacity/95th, Services and CDN.

  • Point-in-time Analysis (Análise do instante) Starter New

    Answers “what exactly was going through at that minute”: services, IPs, interfaces, flow versus SNMP and why it did (or didn’t) become a violation. One click builds a pre-filled FlowSpec filter.

  • Flows Starter

    Collected flows in near real time, with filters and export. The raw view for audits and troubleshooting.

  • Statistics and 95th percentile (Estatísticas) Starter

    Inbound and outbound, protocols, 95th percentile and top IPs: your billing and capacity numbers in one place.

  • Interfaces Starter

    Traffic per router port, utilization and a per-interface summary. See which link is filling up.

  • Flow Explorer Professional

    Multi-dimensional Sankey diagram: source AS, ingress and egress interfaces, destination AS and a conversation map. See how it works.

  • Network Query Builder (Analisador de Rede) Starter New

    Visual query builder, no SQL required: dimensions, metrics, filters, drill-down, real time, saved queries and CSV.

  • Network Analysis (Análise de Rede) Starter New

    Applications, protocols, QoS/DSCP and top talkers, with an hour-of-day baseline that flags anomalies.

  • VRF Visibility Starter New

    Traffic broken out per VRF, with a time series for each instance. Built for L3VPN and enterprise customers.

  • IP Zones (Zonas de IP) Starter

    Traffic segmented by registered block (your prefixes and your customers’), with import by ASN and /24 suggestions.

  • Packet Sensor Starter New

    Capture over SPAN, TAP or GRE with libpcap or AF_PACKET, VLAN/QinQ/GRE/MPLS decapsulation and DPI of HTTP Host, TLS SNI, DNS and QUIC.

  • Tunnel classification Starter New

    Recognizes VxLAN, GENEVE, GRE, L2TP, IP-in-IP and MPLS-in-UDP inside the flow.

flow explorer

Who talks to whom, and over which path

A multi-dimensional Sankey diagram shows the full traffic path: source AS, ingress interface, egress interface and destination AS. Spot imbalances, plan capacity and make peering decisions from visual data.

Flow Explorer · last 6 h

Swipe sideways to see the whole path.

Google 32% Meta 18% Akamai 11% Amazon 9% Others 30% et-0/0/2 IX et-0/0/1 TRANSITO-A ae0 CLIENTES ae1 CORPORATIVO AS65000 Source AS Ingress interface Egress interface Destination
Hover or tap a band to see its share.Illustrative data
  • The big pictureGrouped by ASN: you see “Google 32%”, not a pile of loose IPs.
  • The full pathKnow which interface traffic comes in on and which one it leaves through.
  • No starting point neededExplore all your traffic without having a specific IP in mind.
content and CDN intelligence

Know how much of each CDN enters your edge, and where

EdgeWarden automatically identifies more than 40 content providers (Google, Netflix, Meta, Akamai, Cloudflare, TikTok, Apple, Amazon, Fastly, Valve/Steam and others), separates what is already served by caches inside your network and shows which upstream carrier delivers each CDN.

Find out what your subscribers consume and where it pays to request a cache or open a peering session.

40+

CDNs detected automatically

3

Ways to find caches in your network: SNI, reverse DNS and TLS certificate

CDN ranking (6h)
AS65000
Total CDN15.9 Gbps
Providers30
Served by caches38%
  1. GoogleCloud3.4 G
  2. Meta/WhatsAppSocial2.6 G
  3. NetflixStreaming2.1 G
  4. TikTokSocial1.5 G
  5. AkamaiCDN1.2 G
  6. AWSCloud0.9 G
  7. CloudflareCDN0.8 G
  8. ValveGaming0.6 G
  9. AppleCloud0.5 G
  10. FastlyCDN0.4 G
Served by a cache inside the networkArrives via transit or IX
Illustrative data. The names are public providers that EdgeWarden recognizes.
  • CDN Traffic (Tráfego CDN) Professional

    How much traffic comes from each CDN (Google, Netflix, Meta, Cloudflare and 40+ providers), with rankings, categories and trends.

  • CDN by Carrier (CDN por Operadora) Professional New

    Which purchased link each CDN comes in on, with latency to the cache. Shows where to request a GGC, OCA or FNA, or open peering at the IX.

  • On-net Caches (Caches na Rede) Professional New

    How much of each CDN is already served by appliances inside your network, identified by SNI, reverse DNS or TLS certificate.

  • Applications (Aplicações, DPI) Starter New

    Applications and domains by TLS SNI, HTTP Host and DNS, plus passive DNS, with categories and top domains.

DDoS detection

Catch the attack early without burying the NOC in false alarms

Four methods work together: per-zone thresholds, an hour-of-day baseline, burst detection in 100 ms windows and decoders you write yourself. Every violation comes with its vector, target, sources and the rule that fired.

Attack card with illustrative data.
7,287 → 79

Carpet-bomb alerts over 11 days and 2.4 billion flows at a customer ISP, after the new detector shipped. The real attacks, from 0.6 to 15 Gbps, were still detected.

  • 50 attack vectors Starter

    SYN, ACK, RST, UDP, ICMP and HTTP/HTTPS floods, plus DNS, NTP, SSDP, memcached, LDAP/CLDAP, CharGEN, SNMP, QUIC, SIP, STUN, WS-Discovery amplification and more.

  • Per-zone thresholds and templates Starter

    Thresholds in bits/s and packets/s per zone and per IP, with IPv4 and IPv6 longest-prefix match, a minimum duration to prevent flapping and eight possible responses.

  • Statistical baseline Starter

    A 24-hour baseline by hour of day, with a z-score that rates severity as low, medium, high or critical.

  • Sub-second bursts Starter New

    A 1-second window in 100 ms buckets per destination, using sFlow or Packet Sensor.

  • Carpet bombing Starter New

    Attacks spread across a prefix (/24 IPv4, /48 IPv6), with a 7-day profile and botnet heuristics. At a real customer: from 7,287 down to 79 alerts.

  • QUIC detection Starter New

    Floods and amplification on UDP/443 with dedicated criteria: sources, volume, packet size and pps.

  • DNS abuse Starter New

    Entropy-based DGA detection, NXDOMAIN/water torture and exfiltration.

  • Spoofing and threat intel Starter New

    SAV/BCP38 anti-spoofing against your own prefixes, bogons and the RIB, plus Spamhaus DROP/EDROP, Team Cymru fullbogons and AbuseIPDB.

  • Custom Decoders Starter New

    Write your own vectors in BPF/Wanguard or C/Wireshark syntax, and mix them. Example: proto 17 and dst port 53.

  • Violations (Violações) and forensics Starter

    The incident hub: severity, vector, interfaces, ports and destinations, one-click mitigation, per-attack forensics and CSV/PDF export. It also flags IPs in your own network acting as reflectors.

  • IP Investigation (Investigação) Professional

    Type an IP and see everything it talked to: sources, destinations, protocols and ports. Incident forensics in seconds.

  • WANGuard import Starter New

    Bring in IP Zones from .wan and .csv files, including files over 29 MB.

How long detection takes

The engine runs an analysis cycle every 10 s, configurable down to 1 s, and the burst detector looks at 100 ms buckets in a 1-second window per destination. What changes the total time is when the data arrives, and that depends on the source.

SourceWhat arrivesTime to detectGood to know
sFlow v5Packet samples, sent as soon as the router takes them, plus per-interface countersUnder 1 s, with the burst detectorAccuracy depends on the sampling rate set on the router.
NetFlow v9 / IPFIXFlows aggregated on the router, exported at each active timeoutThe exporter’s active timeout (usually 15 to 60 s) plus the analysis cycleThe shorter the router’s active timeout, the sooner the attack shows up. Carries IPv6; IPFIX also carries DPI fields.
NetFlow v5Aggregated flows in a fixed formatSame as v9: active timeout plus the cycleIPv4 only. A good fit for older routers.
Packet SensorlibpcapPacket copies over SPAN, TAP or GREUnder 1 sAround 1 to 2 Gbps. Works with any NIC.
Packet SensorAF_PACKET v3Packet copies over SPAN, TAP or GREUnder 1 sAround 5 Gbps per interface.
SNMPcountersBytes and packets per interfaceThe configured polling intervalVolume only: it shows the link filled up, not the vector or the target. Useful to cross-check flow data.

Coming soonAF_XDP and DPDK capture in the Packet Sensor, for higher-throughput links. The throughputs above are per-engine estimates; the real limit depends on the server.

automatic mitigation

Seven ways to stop the attack

Each path has its moment. The engine picks one on its own, in a cascade, and logs the reason for every decision; you can also apply any of them by hand.

When to use each path

From what acts without BGP to the most destructive. The badge shows each path’s minimum plan.

PathWhat it doesUse it whenWatch out for
Local packet filternftables / eBPF-XDPEnterpriseDrops, rate-limits or filters by signature in the server’s own kernel, with XDP in the NIC driver. Announces nothing over BGP.Traffic already flows through the server: it is the scrubber receiving the diversion, or it sits inline with the link.It only filters what reaches the server, so it can’t relieve a link that is already full upstream. Start in observe-only mode. On a scrubbing appliance, use nftables only, never ufw.
Diversion to your own scrubberEnterpriseAnnounces the target’s /32 or /128 with the scrubber as next hop, a community and NO_EXPORT. The scrubber cleans the traffic and hands the good part back.The attack fits in your scrubber and the target has to keep serving. It is the first step of the cascade.Automatic diversion only kicks in up to 80% of measured capacity, counting what is already diverted. Above that, the engine moves to the next step.
Mitigation providerexternal scrubbingEnterprise NewAnnounces the prefix covering the target (the /24, for example) to your contracted provider, with upload PBR pushed over SSH (Huawei, Juniper, MikroTik) and failover between providers.The attack is larger than your scrubber or your transit links.It only announces with the provider enabled, the BGP session up, the right address family, a prefix of at least the minimum size and an anti-hijack check. Scrubbing usually has a cost under the contract.
Vector-only FlowSpecProfessionalDrops only the protocol and port of the attack that fired the alert. The rest of the target’s traffic flows normally.The vector is known and there is nowhere to divert, or the target is a CGNAT IP, where this is the mandatory response.Without a known vector, EdgeWarden refuses and logs it instead of dropping the whole destination. Your edge routers must accept FlowSpec.
FlowSpec rate-limitProfessionalCaps the bandwidth of traffic matching the rule (100 Mbps by default) instead of dropping it.Attack and legitimate traffic can’t be told apart safely, as in a SYN flood with random sources.Legitimate traffic competes for the same cap. Tune the value to the service the target provides.
FlowSpec discardProfessionalDrops all traffic matching the rule: the destination and, if you want, protocol and port.The matched traffic has no legitimate use for the target, such as amplification on a port it doesn’t use.A rule that’s too broad turns into a blackhole. To narrow it down, use the ready-made filter wizard.
RTBHProfessionalAnnounces the /32 or /128 with the blackhole community (65000:666 by default), destination- or source-based, and the network drops everything for that IP.Nothing else works and the attack threatens the whole link. It is the last step of the cascade.It takes the target offline. It is never used on a CGNAT IP, where it would cut off dozens of subscribers: EdgeWarden switches to vector-only FlowSpec instead.

Every BGP announcement goes out within 10 s with a TTL and withdraws itself on expiry (5 min by default, up to 4 h).

The order the engine tries

  1. Divert to your own scrubberIf the attack fits within 80% of measured capacity
  2. External scrubbingIf it doesn’t fit and a mitigation provider is active
  3. Vector-only FlowSpecIf there is nowhere to divert; always for CGNAT
  4. RTBHOnly when nothing above works

Which response for which attack

AttackEdgeWarden response
UDP amplificationDiversion + amplification signature in the NIC driver
Spoofed sourceDiversion + L3/L4 sanity checks
Botnet or reflectors with real sourcesDiversion + per-source token bucket
SYN flood with random sourcesFlowSpec rate-limit or retransmission-based SYN protection in XDP
IPv4/IPv6 carpet bombingDivert the block (IPv4); per-prefix FlowSpec (IPv6)
QUIC (UDP/443)QUIC detector + FlowSpec
Target with its own route (PPPoE, /30, anycast)FlowSpec, set as the zone’s response
Attack larger than scrubber capacityExternal scrubbing, then FlowSpec, then RTBH

The XDP filter reaches tens of Mpps of drops per port on a NIC with native XDP. The architecture is 100G/200G per router, with capacity validated in each deployment.

Automate and verify

The engine decides; you check the result.

  • Decision cascade Professional New

    Picks the path in the order above on its own and logs the reason. A customer’s preference (set on the Managed Object or zone) counts as a preference, not an order. The diversion and external scrubbing steps are Enterprise.

  • Ready-made filter wizard Professional New

    Ready-made filters for DNS, NTP, amplification, ICMP and SYN, plus automatic signatures: the narrowest FlowSpec rule that catches the attack, with at most 1% collateral.

  • Effectiveness measurement Professional New

    Compares residual traffic after mitigation against the baseline and alerts you if the rule isn’t working.

Clean in the NIC driver

The scrubber’s XDP data plane.

  • Signatures and sanity checks Enterprise

    13 amplification signatures (DNS, NTP, SSDP, CLDAP, memcached and more), L3/L4 sanity checks, per-source token bucket and protocol + port filtering, over IPv4 and IPv6.

  • SYN flood protection Enterprise New

    Drops the first SYN and lets through whoever retransmits. Unlike SYN cookies, it doesn’t turn the scrubber into a reflector.

  • Observe-only mode and health watchdog Enterprise

    Test rules by counting without dropping. The watchdog checks the scrubber every 10 s and withdraws diversions after 3 failures in a row.

Harden the edge

Permanent protection, before any attack.

  • JunOS Static Filters (Filtros Estáticos) Starter New

    Generates permanent JunOS hardening (anti-amplification, anti-spoofing, routing-engine CoPP and uRPF) from your zones.

  • Router Filters (Filtros do Roteador) Starter New

    Juniper firewall filter counters over SNMP: what the ASIC drops and never shows up in NetFlow.

  • Server Firewall (Firewall do Servidor) Starter New

    Close ports on the server itself from the web interface without locking yourself out.

intelligent BGP routing

Every Mbps on the right link, at the lowest cost and the best latency

Outside of attacks, the same engine measures your upstreams, reads the BGP tables from your routers and steers both outbound and inbound traffic. Every change is validated against the RIB and recorded in the audit log.

See

The table, the neighbors and the quality of every path.

  • Looking Glass Professional

    BGP routes, ping and traceroute from your routers, sessions, announcement history and per-prefix RPKI validation. A public version is included too.

  • AS Analysis (Análise de AS) Professional

    Top AS pairs and top source and destination ASNs, with a per-AS summary.

  • Peering Analytics Professional

    Traffic and cost per peer, an ASN × peer matrix and the potential savings from peering or an IX.

  • BMP Station Enterprise

    Your routers’ BGP tables in real time (RFC 7854): Adj-RIB-In/Out, pre- and post-policy, validated on Junos and Huawei.

  • Route Quality Enterprise

    Latency, loss and jitter per upstream, with ICMP/TCP probing per link and automatic target discovery.

Move traffic

Outbound and inbound, by SLA, capacity and cost.

  • Traffic Steering Enterprise New

    Automatic outbound and inbound routing by SLA, capacity and cost, with observe-only mode, a cap on changes per hour and a second opinion from the AI.

  • Traffic Engineering Enterprise

    Optimization recommendations, overflow above 85% of CIR, policies and audit log.

  • Route Optimizer and Routing Policies Enterprise New

    Best upstream per prefix based on measurements, permanent FlowSpec, static routes and steering, with JSON and ExaBGP import/export.

  • Inbound Optimization Enterprise New

    Inbound traffic engineering: more-specific announcements, withdrawals or prepending based on signals from the source provider.

  • RIB Guard Enterprise New

    Every routing decision is validated against the BMP RIB: traffic never goes to a neighbor that doesn’t announce the destination.

  • BGP Communities Starter New

    Management of standard, extended and large communities.

Guarantee and plan

Contracts met today and the right links six months from now.

  • SLA & Failover Enterprise

    Per-upstream SLA with 30 days of history and automatic failover confirmed by BMP, with automatic recovery.

  • Capacity Planning Enterprise

    A 6-month forecast from 12 months of history: months until saturation, per peer and per interface, with OK/Plan/Urgent/Saturated alerts.

  • Cost Optimization Enterprise

    Transit, IX and peering contracts, commit vs. 95th percentile, cost per Mbps and a monthly estimate.

Edge routers with documented steering: JuniperMikroTik RouterOS v7Cisco IOS-XEHuawei VRPNokia SR OS
routing security

Prove your network doesn’t leak bad routes or spoofed traffic

Validate every prefix, track your MANRS score and know right away when a route flaps or looks hijacked.

  • MANRS Compliance Professional New

    A compliance score per action (anti-spoofing, IRR filtering, abuse contacts, RPKI), with history and recommendations.

  • RPKI and IRR Professional

    RPKI validation over RTR with alerts on Invalid routes, plus IRR (RIPE and RADb), AS-SETs and prefix lists.

  • Route monitor Starter New

    Flap detection and suspected hijacks from BGP events.

Looking Glass
router borda-01
Sample routes with RPKI state
PrefixAS pathRPKI
203.0.113.0/2465000 64500 64496Valid
198.51.100.0/2464500 64511Invalid
2001:db8::/3265000 64496NotFound
Illustrative data, using documentation prefixes and ASNs.
operational AI

The AI explains and suggests. A deterministic guard decides.

The AI only chooses among options the engine built from measured data, and it receives aggregated numbers, never raw flows. If the AI provider goes down, automation keeps running deterministically.

  • Attack Analyst (Analista de Ataques) Enterprise New

    Classifies each violation as confirmed attack, likely attack, inconclusive or legitimate spike, explains why and tells you which FlowSpec rule would catch it. Runs a sweep every 5 min.

  • AI Decision Engine (Decisor com IA) Enterprise New

    BGP traffic decisions with a closed vocabulary: the AI only picks among measured candidates, and the deterministic guard makes the call. Observe, Propose and Automatic modes.

  • Explain with AI (Explicar com IA) Enterprise New

    A plain-language explanation on every anomaly card. The model only receives the evidence numbers.

  • Analyst Briefing (Boletim do Analista) Enterprise New

    A summary every 1 to 24 h via in-app bell, email, Telegram or webhook. If the AI fails, the briefing goes out as a plain list; nothing takes action on the network.

  • Local or cloud LLM Enterprise New

    Claude, OpenAI, Groq, OpenRouter, Ollama, vLLM or LM Studio. Switch providers without recompiling.

Verdict with illustrative data.
business, cost and capacity

The numbers management asks for, without a spreadsheet

Reports ready to send and the cost of every peer at a glance. Capacity Planning and Cost Optimization live in the BGP pillar.

  • PDF Report (Relatório PDF)

    Executive report with a traffic summary, top talkers, protocols, top 10 ASNs and the attacks in the period.

    Starter
  • Scheduled reports

    Automatic delivery by email, including per-customer capacity and security reports.

    Starter
  • Peer Costs (Custos de Peer)

    Cost per peer and per contract, so you can decide where to buy and where to peer.

    Enterprise
multi-tenant and resale

Sell DDoS protection as a product

Each customer gets their own zone, contract, SLA, mitigation policy and portal. You run all of it from a single pane, on any plan.

  • Managed Objects Starter New

    Customers, contracts, peers and profiles in a hierarchy up to 5 levels deep, with their own mitigation policy, Bronze/Silver/Gold/Platinum SLA, granular ACLs and auditing.

  • Customer Portal (Portal do Cliente) Starter New

    Your customer sees only their own traffic, commit usage and attacks from the last 7 days, via login or a read-only link.

  • DDoS Protection-as-a-Service Starter New

    Turn your protection into a product: policy and notifications per contract, and reports per customer.

Illustrative hierarchy.
integrations and operations

Fits into the NOC you already run

Send attacks and mitigations to your SIEM, your Zabbix and your ticketing system, and manage the server without leaving the browser.

REST API v1 · attacks in the last 24 h
# create the key under Configurações → Chaves de API (Settings → API Keys)
curl -s \
  -H "Authorization: Bearer fsk_<id>_<secret>" \
  "https://edgewarden.example.net/api/v1/attacks?hours=24"
{ "data": [ … ], "pagination": { … } }
  • 46 endpoints and 60 operations, documented in OpenAPI, with Swagger at /api-docs.
  • Scopes such as attacks:read and mitigations:write, with restrictions by source IP and by customer.
  • Default limit of 120 requests per minute per key; the server stores only the key’s hash.
  • REST API v1 Starter New

    46 endpoints in OpenAPI/Swagger, scoped keys, IP and customer restrictions and rate limiting.

  • Syslog / SIEM Enterprise

    Events in CEF, JSON or RFC 5424, over UDP or TCP.

  • SNMP Trap Starter New

    v2c traps for Zabbix, PRTG, LibreNMS and SolarWinds.

  • Notifications Starter

    Email, Telegram, webhook and Slack, with a minimum severity and escalation by number of occurrences.

  • In-browser terminal Starter New

    SSH (and Telnet for legacy gear) straight from the browser, with credentials encrypted with AES-256-GCM.

  • System Status (Status do Sistema) and backup Starter New

    Health of CPU, memory, disk, services and ClickHouse, plus backup and restore.

  • Built-in manual Starter New

    About 72 pages of documentation in Brazilian Portuguese inside the product, searchable with Ctrl+K.

menu map

So you can find each feature in the product after installation. The interface is in Brazilian Portuguese, so the names below are exactly as they appear in the menu, with a translation where needed. Items outside your plan show a padlock and the plan they require.

next steps

What’s on the way

Only what isn’t ready yet is listed here. The full roadmap shows what has already shipped and what comes next.

  • Machine learning detection Coming soon

    Models that learn each customer’s normal behavior and flag anomalies no fixed threshold catches, with fewer false positives and earlier alerts.

  • Certified Huawei edge (NE40E/NE8000) Coming soon

    Scrubbing center for Huawei VRP8 edges with an anti-loop template certified in the lab, IPv6 included.

  • Multi-router scrubbing center Coming soon

    A single scrubbing node connected directly to several edge routers, with its own next hop per router and health checks on every path.

  • Line-rate capture with AF_XDP and DPDK Coming soon

    Two new Packet Sensor capture engines for very high-throughput links, alongside the libpcap and AF_PACKET v3 engines already available.

See the full roadmap

Want to see these modules running on your data?

See EdgeWarden in action with traffic from your own network. The demo license unlocks every Enterprise feature for 7 days.