Features
One license is the controller, XDP scrub software, operator dashboard and customer panel.
One license is the controller, XDP scrub software, operator dashboard and customer panel.
NetFlow v5/v9 and IPFIX on UDP 2055, sFlow v5 on UDP 6343, IPv4 and IPv6. Per-group pps, bps and flow-rate thresholds, global or per vector. Carpet-bomb on /24 and /48. Hold-down on attack state.
RTBH and FlowSpec through embedded GoBGP. Per-group host and subnet modes (rtbh, flowspec, both, scrub, none). Fallback chain when a scrub node is unhealthy. Safety rails: prefix enclosure, never-blackhole whitelist, max announcements, dry run. Open mitigations restored from Postgres after restart.
On-demand diversion of the attacked /32 or /128 to a templass-scrub node. Vector-based XDP rules. Clean return over VLAN or GRE. Drain and disable. Health fallback and restore. Drop and pass rates on the node. Packages: .deb, .rpm, static binary, systemd unit, container.
Overview, attacks with detail pages, mitigations (manual announce and withdraw), organizations, groups, prefixes, thresholds, policy editor, flow sources, BGP peers (read-only), scrub nodes, whitelist, users, audit log.
System: license, white-label brand, logo, support email and public URL, webhook allowlist, SMTP, scrub restore window.
Invite customers by password or one-time link. Preview a customer's panel. Live updates via SSE.
Each customer of the hosting provider logs in and sees their prefixes with status (normal, under attack, scrubbing, mitigated), live attacks, history with CSV export, attack detail, 24h chart.
Manual RTBH or FlowSpec on their own prefixes when the operator allows it. HMAC-SHA256 signed webhooks and email alerts on attack start and end, with a test button and delivery log. API tokens scoped read or mitigate. TOTP 2FA. Their org's audit log.
REST at /api/v1 with an OpenAPI spec. Bearer tokens for operators and customers. SSE at /api/v1/events. Login rate limit and CSRF protection.
Prometheus at /metrics: collector packets and flows, decode errors, unknown exporters, tracked hosts, active attacks, BGP announces, withdraws, rejections, peer state.
Offline bundle with a signed checksum. install.sh for Debian 12/13, Ubuntu 22.04/24.04, RHEL/Alma/Rocky 9. Layout under /opt/templass. templassctl for status, logs, backup, restore, upgrade (signature check, backup first, health check, automatic rollback), rollback, support-bundle (secrets redacted), license, uninstall. Optional daily backup timer.
Offline Ed25519-signed key, pasted on System or passed to the installer. Verified locally. Runs forever. Unlimited nodes, prefixes, organizations and customers. The key carries an updates date.
Commercial terms are on Pricing.