How it works

Routers (NetFlow / IPFIX / sFlow)
        │
        ▼
   Collector  →  aggregation  →  detection
                                      │
                            Group policy
                     host mode / subnet mode
                     fallback chain
                                      │
                 ┌────────────────────┼────────────────────┐
                 ▼                                         ▼
        BGP speaker (GoBGP)                      Scrub orchestrator
        RTBH / FlowSpec                          /32 or /128 next-hop
                 │                               = scrub node
                 ▼                                         │
        Edge router                                XDP filter (vector)
                                                          │
                                                   clean return
                                                   VLAN or GRE
                 │
                 ▼
        REST API + SSE → operator dashboard + customer panel

The controller is one install. Scrub nodes are separate machines. Live views use SSE.

  1. 1

    Flow data

    Routers send NetFlow, IPFIX and sFlow to the collector.

  2. 2

    Detection

    Group thresholds for pps, bps and flow rate. Carpet-bomb on /24 and /48.

  3. 3

    Mitigation by policy

    Host mode and subnet mode. Fallback chain when a scrub node is unhealthy.

  4. 4

    Scrub and fallback

    Divert the attacked /32 or /128 to the scrub node. Clean return over VLAN or GRE.

Collector

The controller listens for NetFlow v5/v9 and IPFIX on UDP 2055, and sFlow v5 on UDP 6343. IPv4 and IPv6 exporters are supported.

Add each exporter under Flow sources. Unlisted exporters are ignored.

Detection

Each group has thresholds for pps, bps and flow rate. They can be global or per vector: udp, tcp_syn, icmp, fragment, dns, ntp, ldap, ssdp, memcached, chargen. Prefix and threshold changes apply within 5 seconds.

Carpet-bomb detection watches /24 and /48 with detection.carpet_bomb.min_hosts (default 8). Attack states use a global hold-down (default 15 seconds).

Policy and fallback

Per group you set host mode and subnet mode: rtbh, flowspec, both, scrub, or none (alert only). FlowSpec action is drop, rate-limit or redirect.

Escalation order is a fallback chain (default: scrub, then FlowSpec, then RTBH). The controller uses the next step when a scrub node is unhealthy. Customer self-mitigation can be on or off per group.

BGP

The controller embeds GoBGP. RTBH uses community 65535:666 and NO_EXPORT by default. extra_communities can be set globally or per peer.

FlowSpec matches destination plus protocol, amplification source port, SYN flag or fragments. Actions: drop, rate-limit, redirect.

Safety rails: prefix enclosure, a global never-blackhole list of destination prefixes, max announcements, dry run. Open mitigations are re-announced from Postgres after a controller restart.

Peers, ASN and router-id live in /opt/templass/config.yaml (bgp.asn, bgp.router_id, bgp.peers[].address / asn / families). A change there needs a process restart. The GUI shows peer state.

Scrub diversion

On-demand: the controller announces the attacked /32 or /128 with the scrub node as next-hop. The node generates XDP rules for the detected vector (amplification source ports, UDP and SYN rate limits per source and per destination, ICMP, fragments). VLAN and QinQ, IPv4 and IPv6.

Clean traffic returns to the edge over a VLAN or GRE.

If a node stops reporting for about 15 seconds, the controller moves to the next fallback step and logs it. When the node is healthy again for the stability window (default 60 seconds), traffic returns to scrubbing, make-before-break. Nodes report drop and pass rates.

Enrollment, packages and host setup are on Scrub node. Hardware is on Requirements.