Everything you need to see, protect and optimize your network
More than 70 modules across ten pillars, from raw flow to routing decision. They all ship in the same binary: your license unlocks what your plan includes.
See every flow, from the last minute to the last month
From raw flow to the executive view: see who talks to whom, over which path and what it costs you. Collects NetFlow v5/v9, IPFIX and sFlow v5, with no dependency on DPI.
Real-time dashboard Starter
Live KPIs, mirrored In/Out traffic, traffic by service, protocols, an attack heat map and overall network status. Click the chart to inspect that exact moment.
My Dashboards (Meus Dashboards) Professional New
Build boards by dragging and resizing 16 widgets, or start from 4 ready-made templates: Security/DDoS, Transit and Peering, Capacity/95th, Services and CDN.
Point-in-time Analysis (Análise do instante) Starter New
Answers “what exactly was going through at that minute”: services, IPs, interfaces, flow versus SNMP and why it did (or didn’t) become a violation. One click builds a pre-filled FlowSpec filter.
Flows Starter
Collected flows in near real time, with filters and export. The raw view for audits and troubleshooting.
Statistics and 95th percentile (Estatísticas) Starter
Inbound and outbound, protocols, 95th percentile and top IPs: your billing and capacity numbers in one place.
Interfaces Starter
Traffic per router port, utilization and a per-interface summary. See which link is filling up.
Flow Explorer Professional
Multi-dimensional Sankey diagram: source AS, ingress and egress interfaces, destination AS and a conversation map. See how it works.
Network Query Builder (Analisador de Rede) Starter New
Visual query builder, no SQL required: dimensions, metrics, filters, drill-down, real time, saved queries and CSV.
Network Analysis (Análise de Rede) Starter New
Applications, protocols, QoS/DSCP and top talkers, with an hour-of-day baseline that flags anomalies.
VRF Visibility Starter New
Traffic broken out per VRF, with a time series for each instance. Built for L3VPN and enterprise customers.
IP Zones (Zonas de IP) Starter
Traffic segmented by registered block (your prefixes and your customers’), with import by ASN and /24 suggestions.
Packet Sensor Starter New
Capture over SPAN, TAP or GRE with libpcap or AF_PACKET, VLAN/QinQ/GRE/MPLS decapsulation and DPI of HTTP Host, TLS SNI, DNS and QUIC.
Tunnel classification Starter New
Recognizes VxLAN, GENEVE, GRE, L2TP, IP-in-IP and MPLS-in-UDP inside the flow.
Who talks to whom, and over which path
A multi-dimensional Sankey diagram shows the full traffic path: source AS, ingress interface, egress interface and destination AS. Spot imbalances, plan capacity and make peering decisions from visual data.
Swipe sideways to see the whole path.
- The big pictureGrouped by ASN: you see “Google 32%”, not a pile of loose IPs.
- The full pathKnow which interface traffic comes in on and which one it leaves through.
- No starting point neededExplore all your traffic without having a specific IP in mind.
Know how much of each CDN enters your edge, and where
EdgeWarden automatically identifies more than 40 content providers (Google, Netflix, Meta, Akamai, Cloudflare, TikTok, Apple, Amazon, Fastly, Valve/Steam and others), separates what is already served by caches inside your network and shows which upstream carrier delivers each CDN.
Find out what your subscribers consume and where it pays to request a cache or open a peering session.
CDNs detected automatically
Ways to find caches in your network: SNI, reverse DNS and TLS certificate
- GoogleCloud3.4 G
- Meta/WhatsAppSocial2.6 G
- NetflixStreaming2.1 G
- TikTokSocial1.5 G
- AkamaiCDN1.2 G
- AWSCloud0.9 G
- CloudflareCDN0.8 G
- ValveGaming0.6 G
- AppleCloud0.5 G
- FastlyCDN0.4 G
CDN Traffic (Tráfego CDN) Professional
How much traffic comes from each CDN (Google, Netflix, Meta, Cloudflare and 40+ providers), with rankings, categories and trends.
CDN by Carrier (CDN por Operadora) Professional New
Which purchased link each CDN comes in on, with latency to the cache. Shows where to request a GGC, OCA or FNA, or open peering at the IX.
On-net Caches (Caches na Rede) Professional New
How much of each CDN is already served by appliances inside your network, identified by SNI, reverse DNS or TLS certificate.
Applications (Aplicações, DPI) Starter New
Applications and domains by TLS SNI, HTTP Host and DNS, plus passive DNS, with categories and top domains.
Catch the attack early without burying the NOC in false alarms
Four methods work together: per-zone thresholds, an hour-of-day baseline, burst detection in 100 ms windows and decoders you write yourself. Every violation comes with its vector, target, sources and the rule that fired.
UDP amplification · DNS
- Detected
- Vector-only FlowSpec announced (8 s)
- Residual traffic: 0.2 Gbps
- Mitigated
Carpet-bomb alerts over 11 days and 2.4 billion flows at a customer ISP, after the new detector shipped. The real attacks, from 0.6 to 15 Gbps, were still detected.
50 attack vectors Starter
SYN, ACK, RST, UDP, ICMP and HTTP/HTTPS floods, plus DNS, NTP, SSDP, memcached, LDAP/CLDAP, CharGEN, SNMP, QUIC, SIP, STUN, WS-Discovery amplification and more.
Per-zone thresholds and templates Starter
Thresholds in bits/s and packets/s per zone and per IP, with IPv4 and IPv6 longest-prefix match, a minimum duration to prevent flapping and eight possible responses.
Statistical baseline Starter
A 24-hour baseline by hour of day, with a z-score that rates severity as low, medium, high or critical.
Sub-second bursts Starter New
A 1-second window in 100 ms buckets per destination, using sFlow or Packet Sensor.
Carpet bombing Starter New
Attacks spread across a prefix (/24 IPv4, /48 IPv6), with a 7-day profile and botnet heuristics. At a real customer: from 7,287 down to 79 alerts.
QUIC detection Starter New
Floods and amplification on UDP/443 with dedicated criteria: sources, volume, packet size and pps.
DNS abuse Starter New
Entropy-based DGA detection, NXDOMAIN/water torture and exfiltration.
Spoofing and threat intel Starter New
SAV/BCP38 anti-spoofing against your own prefixes, bogons and the RIB, plus Spamhaus DROP/EDROP, Team Cymru fullbogons and AbuseIPDB.
Custom Decoders Starter New
Write your own vectors in BPF/Wanguard or C/Wireshark syntax, and mix them. Example:
proto 17 and dst port 53.Violations (Violações) and forensics Starter
The incident hub: severity, vector, interfaces, ports and destinations, one-click mitigation, per-attack forensics and CSV/PDF export. It also flags IPs in your own network acting as reflectors.
IP Investigation (Investigação) Professional
Type an IP and see everything it talked to: sources, destinations, protocols and ports. Incident forensics in seconds.
WANGuard import Starter New
Bring in IP Zones from .wan and .csv files, including files over 29 MB.
How long detection takes
The engine runs an analysis cycle every 10 s, configurable down to 1 s, and the burst detector looks at 100 ms buckets in a 1-second window per destination. What changes the total time is when the data arrives, and that depends on the source.
| Source | What arrives | Time to detect | Good to know |
|---|---|---|---|
| sFlow v5 | Packet samples, sent as soon as the router takes them, plus per-interface counters | Under 1 s, with the burst detector | Accuracy depends on the sampling rate set on the router. |
| NetFlow v9 / IPFIX | Flows aggregated on the router, exported at each active timeout | The exporter’s active timeout (usually 15 to 60 s) plus the analysis cycle | The shorter the router’s active timeout, the sooner the attack shows up. Carries IPv6; IPFIX also carries DPI fields. |
| NetFlow v5 | Aggregated flows in a fixed format | Same as v9: active timeout plus the cycle | IPv4 only. A good fit for older routers. |
| Packet Sensorlibpcap | Packet copies over SPAN, TAP or GRE | Under 1 s | Around 1 to 2 Gbps. Works with any NIC. |
| Packet SensorAF_PACKET v3 | Packet copies over SPAN, TAP or GRE | Under 1 s | Around 5 Gbps per interface. |
| SNMPcounters | Bytes and packets per interface | The configured polling interval | Volume only: it shows the link filled up, not the vector or the target. Useful to cross-check flow data. |
Coming soonAF_XDP and DPDK capture in the Packet Sensor, for higher-throughput links. The throughputs above are per-engine estimates; the real limit depends on the server.
Seven ways to stop the attack
Each path has its moment. The engine picks one on its own, in a cascade, and logs the reason for every decision; you can also apply any of them by hand.
When to use each path
From what acts without BGP to the most destructive. The badge shows each path’s minimum plan.
| Path | What it does | Use it when | Watch out for |
|---|---|---|---|
| Local packet filternftables / eBPF-XDPEnterprise | Drops, rate-limits or filters by signature in the server’s own kernel, with XDP in the NIC driver. Announces nothing over BGP. | Traffic already flows through the server: it is the scrubber receiving the diversion, or it sits inline with the link. | It only filters what reaches the server, so it can’t relieve a link that is already full upstream. Start in observe-only mode. On a scrubbing appliance, use nftables only, never ufw. |
| Diversion to your own scrubberEnterprise | Announces the target’s /32 or /128 with the scrubber as next hop, a community and NO_EXPORT. The scrubber cleans the traffic and hands the good part back. | The attack fits in your scrubber and the target has to keep serving. It is the first step of the cascade. | Automatic diversion only kicks in up to 80% of measured capacity, counting what is already diverted. Above that, the engine moves to the next step. |
| Mitigation providerexternal scrubbingEnterprise New | Announces the prefix covering the target (the /24, for example) to your contracted provider, with upload PBR pushed over SSH (Huawei, Juniper, MikroTik) and failover between providers. | The attack is larger than your scrubber or your transit links. | It only announces with the provider enabled, the BGP session up, the right address family, a prefix of at least the minimum size and an anti-hijack check. Scrubbing usually has a cost under the contract. |
| Vector-only FlowSpecProfessional | Drops only the protocol and port of the attack that fired the alert. The rest of the target’s traffic flows normally. | The vector is known and there is nowhere to divert, or the target is a CGNAT IP, where this is the mandatory response. | Without a known vector, EdgeWarden refuses and logs it instead of dropping the whole destination. Your edge routers must accept FlowSpec. |
| FlowSpec rate-limitProfessional | Caps the bandwidth of traffic matching the rule (100 Mbps by default) instead of dropping it. | Attack and legitimate traffic can’t be told apart safely, as in a SYN flood with random sources. | Legitimate traffic competes for the same cap. Tune the value to the service the target provides. |
| FlowSpec discardProfessional | Drops all traffic matching the rule: the destination and, if you want, protocol and port. | The matched traffic has no legitimate use for the target, such as amplification on a port it doesn’t use. | A rule that’s too broad turns into a blackhole. To narrow it down, use the ready-made filter wizard. |
| RTBHProfessional | Announces the /32 or /128 with the blackhole community (65000:666 by default), destination- or source-based, and the network drops everything for that IP. | Nothing else works and the attack threatens the whole link. It is the last step of the cascade. | It takes the target offline. It is never used on a CGNAT IP, where it would cut off dozens of subscribers: EdgeWarden switches to vector-only FlowSpec instead. |
Every BGP announcement goes out within 10 s with a TTL and withdraws itself on expiry (5 min by default, up to 4 h).
The order the engine tries
- Divert to your own scrubberIf the attack fits within 80% of measured capacity
- External scrubbingIf it doesn’t fit and a mitigation provider is active
- Vector-only FlowSpecIf there is nowhere to divert; always for CGNAT
- RTBHOnly when nothing above works
Which response for which attack
| Attack | EdgeWarden response |
|---|---|
| UDP amplification | Diversion + amplification signature in the NIC driver |
| Spoofed source | Diversion + L3/L4 sanity checks |
| Botnet or reflectors with real sources | Diversion + per-source token bucket |
| SYN flood with random sources | FlowSpec rate-limit or retransmission-based SYN protection in XDP |
| IPv4/IPv6 carpet bombing | Divert the block (IPv4); per-prefix FlowSpec (IPv6) |
| QUIC (UDP/443) | QUIC detector + FlowSpec |
| Target with its own route (PPPoE, /30, anycast) | FlowSpec, set as the zone’s response |
| Attack larger than scrubber capacity | External scrubbing, then FlowSpec, then RTBH |
The XDP filter reaches tens of Mpps of drops per port on a NIC with native XDP. The architecture is 100G/200G per router, with capacity validated in each deployment.
Automate and verify
The engine decides; you check the result.
Decision cascade Professional New
Picks the path in the order above on its own and logs the reason. A customer’s preference (set on the Managed Object or zone) counts as a preference, not an order. The diversion and external scrubbing steps are Enterprise.
Ready-made filter wizard Professional New
Ready-made filters for DNS, NTP, amplification, ICMP and SYN, plus automatic signatures: the narrowest FlowSpec rule that catches the attack, with at most 1% collateral.
Effectiveness measurement Professional New
Compares residual traffic after mitigation against the baseline and alerts you if the rule isn’t working.
Clean in the NIC driver
The scrubber’s XDP data plane.
Signatures and sanity checks Enterprise
13 amplification signatures (DNS, NTP, SSDP, CLDAP, memcached and more), L3/L4 sanity checks, per-source token bucket and protocol + port filtering, over IPv4 and IPv6.
SYN flood protection Enterprise New
Drops the first SYN and lets through whoever retransmits. Unlike SYN cookies, it doesn’t turn the scrubber into a reflector.
Observe-only mode and health watchdog Enterprise
Test rules by counting without dropping. The watchdog checks the scrubber every 10 s and withdraws diversions after 3 failures in a row.
Harden the edge
Permanent protection, before any attack.
JunOS Static Filters (Filtros Estáticos) Starter New
Generates permanent JunOS hardening (anti-amplification, anti-spoofing, routing-engine CoPP and uRPF) from your zones.
Router Filters (Filtros do Roteador) Starter New
Juniper firewall filter counters over SNMP: what the ASIC drops and never shows up in NetFlow.
Server Firewall (Firewall do Servidor) Starter New
Close ports on the server itself from the web interface without locking yourself out.
Every Mbps on the right link, at the lowest cost and the best latency
Outside of attacks, the same engine measures your upstreams, reads the BGP tables from your routers and steers both outbound and inbound traffic. Every change is validated against the RIB and recorded in the audit log.
See
The table, the neighbors and the quality of every path.
Looking Glass Professional
BGP routes, ping and traceroute from your routers, sessions, announcement history and per-prefix RPKI validation. A public version is included too.
AS Analysis (Análise de AS) Professional
Top AS pairs and top source and destination ASNs, with a per-AS summary.
Peering Analytics Professional
Traffic and cost per peer, an ASN × peer matrix and the potential savings from peering or an IX.
BMP Station Enterprise
Your routers’ BGP tables in real time (RFC 7854): Adj-RIB-In/Out, pre- and post-policy, validated on Junos and Huawei.
Route Quality Enterprise
Latency, loss and jitter per upstream, with ICMP/TCP probing per link and automatic target discovery.
Move traffic
Outbound and inbound, by SLA, capacity and cost.
Traffic Steering Enterprise New
Automatic outbound and inbound routing by SLA, capacity and cost, with observe-only mode, a cap on changes per hour and a second opinion from the AI.
Traffic Engineering Enterprise
Optimization recommendations, overflow above 85% of CIR, policies and audit log.
Route Optimizer and Routing Policies Enterprise New
Best upstream per prefix based on measurements, permanent FlowSpec, static routes and steering, with JSON and ExaBGP import/export.
Inbound Optimization Enterprise New
Inbound traffic engineering: more-specific announcements, withdrawals or prepending based on signals from the source provider.
RIB Guard Enterprise New
Every routing decision is validated against the BMP RIB: traffic never goes to a neighbor that doesn’t announce the destination.
BGP Communities Starter New
Management of standard, extended and large communities.
Guarantee and plan
Contracts met today and the right links six months from now.
SLA & Failover Enterprise
Per-upstream SLA with 30 days of history and automatic failover confirmed by BMP, with automatic recovery.
Capacity Planning Enterprise
A 6-month forecast from 12 months of history: months until saturation, per peer and per interface, with OK/Plan/Urgent/Saturated alerts.
Cost Optimization Enterprise
Transit, IX and peering contracts, commit vs. 95th percentile, cost per Mbps and a monthly estimate.
Prove your network doesn’t leak bad routes or spoofed traffic
Validate every prefix, track your MANRS score and know right away when a route flaps or looks hijacked.
MANRS Compliance Professional New
A compliance score per action (anti-spoofing, IRR filtering, abuse contacts, RPKI), with history and recommendations.
RPKI and IRR Professional
RPKI validation over RTR with alerts on Invalid routes, plus IRR (RIPE and RADb), AS-SETs and prefix lists.
Route monitor Starter New
Flap detection and suspected hijacks from BGP events.
| Prefix | AS path | RPKI |
|---|---|---|
| 203.0.113.0/24 | 65000 64500 64496 | Valid |
| 198.51.100.0/24 | 64500 64511 | Invalid |
| 2001:db8::/32 | 65000 64496 | NotFound |
The AI explains and suggests. A deterministic guard decides.
The AI only chooses among options the engine built from measured data, and it receives aggregated numbers, never raw flows. If the AI provider goes down, automation keeps running deterministically.
Attack Analyst (Analista de Ataques) Enterprise New
Classifies each violation as confirmed attack, likely attack, inconclusive or legitimate spike, explains why and tells you which FlowSpec rule would catch it. Runs a sweep every 5 min.
AI Decision Engine (Decisor com IA) Enterprise New
BGP traffic decisions with a closed vocabulary: the AI only picks among measured candidates, and the deterministic guard makes the call. Observe, Propose and Automatic modes.
Explain with AI (Explicar com IA) Enterprise New
A plain-language explanation on every anomaly card. The model only receives the evidence numbers.
Analyst Briefing (Boletim do Analista) Enterprise New
A summary every 1 to 24 h via in-app bell, email, Telegram or webhook. If the AI fails, the briefing goes out as a plain list; nothing takes action on the network.
Local or cloud LLM Enterprise New
Claude, OpenAI, Groq, OpenRouter, Ollama, vLLM or LM Studio. Switch providers without recompiling.
Violation #4812 · 203.0.113.10 · UDP/53
The numbers management asks for, without a spreadsheet
Reports ready to send and the cost of every peer at a glance. Capacity Planning and Cost Optimization live in the BGP pillar.
PDF Report (Relatório PDF)
Executive report with a traffic summary, top talkers, protocols, top 10 ASNs and the attacks in the period.
StarterScheduled reports
Automatic delivery by email, including per-customer capacity and security reports.
StarterPeer Costs (Custos de Peer)
Cost per peer and per contract, so you can decide where to buy and where to peer.
Enterprise
Sell DDoS protection as a product
Each customer gets their own zone, contract, SLA, mitigation policy and portal. You run all of it from a single pane, on any plan.
Managed Objects Starter New
Customers, contracts, peers and profiles in a hierarchy up to 5 levels deep, with their own mitigation policy, Bronze/Silver/Gold/Platinum SLA, granular ACLs and auditing.
Customer Portal (Portal do Cliente) Starter New
Your customer sees only their own traffic, commit usage and attacks from the last 7 days, via login or a read-only link.
DDoS Protection-as-a-Service Starter New
Turn your protection into a product: policy and notifications per contract, and reports per customer.
- Example ISP AS65000
- North Reseller own policy
- Example Fiber Customer Gold 203.0.113.0/26
- Alpha Hosting Platinum 198.51.100.0/27
- Direct contracts
- Example City Hall Silver 2001:db8:10::/48
- North Reseller own policy
Fits into the NOC you already run
Send attacks and mitigations to your SIEM, your Zabbix and your ticketing system, and manage the server without leaving the browser.
# create the key under Configurações → Chaves de API (Settings → API Keys) curl -s \ -H "Authorization: Bearer fsk_<id>_<secret>" \ "https://edgewarden.example.net/api/v1/attacks?hours=24" { "data": [ … ], "pagination": { … } }
- 46 endpoints and 60 operations, documented in OpenAPI, with Swagger at
/api-docs. - Scopes such as
attacks:readandmitigations:write, with restrictions by source IP and by customer. - Default limit of 120 requests per minute per key; the server stores only the key’s hash.
REST API v1 Starter New
46 endpoints in OpenAPI/Swagger, scoped keys, IP and customer restrictions and rate limiting.
Syslog / SIEM Enterprise
Events in CEF, JSON or RFC 5424, over UDP or TCP.
SNMP Trap Starter New
v2c traps for Zabbix, PRTG, LibreNMS and SolarWinds.
Notifications Starter
Email, Telegram, webhook and Slack, with a minimum severity and escalation by number of occurrences.
In-browser terminal Starter New
SSH (and Telnet for legacy gear) straight from the browser, with credentials encrypted with AES-256-GCM.
System Status (Status do Sistema) and backup Starter New
Health of CPU, memory, disk, services and ClickHouse, plus backup and restore.
Built-in manual Starter New
About 72 pages of documentation in Brazilian Portuguese inside the product, searchable with Ctrl+K.
Every module, under the name it has in the menu
So you can find each feature in the product after installation. The interface is in Brazilian Portuguese, so the names below are exactly as they appear in the menu, with a translation where needed. Items outside your plan show a padlock and the plan they require.
What’s on the way
Only what isn’t ready yet is listed here. The full roadmap shows what has already shipped and what comes next.
Machine learning detection Coming soon
Models that learn each customer’s normal behavior and flag anomalies no fixed threshold catches, with fewer false positives and earlier alerts.
Certified Huawei edge (NE40E/NE8000) Coming soon
Scrubbing center for Huawei VRP8 edges with an anti-loop template certified in the lab, IPv6 included.
Multi-router scrubbing center Coming soon
A single scrubbing node connected directly to several edge routers, with its own next hop per router and health checks on every path.
Line-rate capture with AF_XDP and DPDK Coming soon
Two new Packet Sensor capture engines for very high-throughput links, alongside the libpcap and AF_PACKET v3 engines already available.
Want to see these modules running on your data?
See EdgeWarden in action with traffic from your own network. The demo license unlocks every Enterprise feature for 7 days.