FastNetMon is a very high performance DDoS detector built on top of multiple packet capture engines: NetFlow, IPFIX, sFlow and SPAN/port mirror.
It could detect malicious traffic in your network and immediately block it with BGP blackhole or BGP flow spec rules.
It has solid support for all top network vendors and has unlimited scalability due to flexible design.
You could integrate FastNetMon into any existing network without any changes and additional hardware!
Based on our record, OpenWrt seems to be a lot more popular than FastNetMon. While we know about 103 links to OpenWrt, we've tracked only 3 mentions of FastNetMon. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.
If you have a BGP peering with you ISP/upstream provider, ask them if they have a blackhole community you can broadcast to. Usually they are ASN:666. The only downside is you would only be able to advertise your IP address to that, essentially killing your internet (if that's your only IP) as long as the block is up. We usually set our filter to 15 minutes and most attackers give up after that. At this level, you... Source: 11 months ago
Have you looked at fastnetmon ? It's freemium and It looks like the commercial version would work you, but I think the community edition is aslo worth a look. It's primary function is to detect DDOS attacks, but it can export data in ways that might be useful to you. Source: almost 2 years ago
To mitigate DoS attacks means you need information - preferably before the users start screaming. Running sampling on your edge router with something like Fastnetmon will give you alerting of a probable DDoS attack before it becomes a significant problem. Source: over 2 years ago
If your current router supports a custom firmware like openWRT then you could do this without having to buy a new one. Source: 5 months ago
Unfortunately, I can't create an account via Github on the openwrt site. Source: 7 months ago
Anyone else having trouble reaching openwrt.org right now? I can't get the forums, main page or downloads. I've done plenty of troubleshooting and there isn't anything else on my network having trouble reaching anything else on the internet. Source: 8 months ago
On the router. openwrt.org has lots of great documentation that lays out exactly what you're looking for and then some. Source: 11 months ago
Is the Verizon one a combined modem/router? If you want to add your own router, you might have to call them and ask them to put it into bridged mode. I like OpenWRT because it gives you a lot of customization options. I've just been running it on an old TP-Link Archer C7 for the past 5 years or so and I haven't had any issues, but that's ancient hardware now. Source: 11 months ago
Andrisoft WanGuard - DDoS protection software solution for networks. Attacks detected by NetFlow,NetStream,sFlow,jFlow,IPFIX,Port Mirroring and mitigated with firewall filters
MikroTik RouterOS - The main product of MikroTik is a Linux-based operating system known as MikroTik RouterOS.
NetVizura NetFlow Analyzer - NetFlow Analyzer is a solution for bandwidth monitoring and traffic analysis. It helps with traffic investigation, analysis and reporting
pfSense - pfSense is a free and open source firewall and router that also features unified threat management, load balancing, multi WAN, and more
Arbor - Easily manage product development
OPNsense - OPNsense® you next open source firewall. Free Download. High-end Security Made Easy™. Offers Intrusion Prevention, Captive Portal, Traffic Shaping and more.