> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/netflow-ddos-detector/interface/config.md).

# Config

<figure><img src="/files/6p5zNH8DaurLEzUfib2u" alt=""><figcaption></figcaption></figure>

## Overview

As described in the [Introduction](/product-guides/netflow-ddos-detector/introduction.md#how-it-works), Netflow DDoS Detector analyzes the traffic that customers are receiving. When specified limits are exceeded, traffic can be rerouted through Link11 for filtering.&#x20;

Link11 can perform the rerouting automatically, or the system can merely notify customers that traffic thresholds have been exceeded. At any time, manual rerouting can be performed. Rerouting includes customization options for traffic engineering with per-router granularity.

The *Config* window (shown above) is for configuring the traffic rerouting parameters. It consists of three sections:

* **Reroute Limits** (top section): definitions of traffic conditions that will trigger rerouting. Prefixes appearing in this list are not currently experiencing traffic in excess of these conditions.
* **Not Rerouted** (middle section): prefixes currently being attacked, which were not rerouted because **Auto Reroute** was disabled.
* **Rerouted** (bottom section): prefixes that were rerouted. Rerouting can occur automatically, or customers can trigger it manually.&#x20;

Each section is described further below.

{% hint style="warning" %}
The limits defined in the *Config* interface can only (potentially) cause traffic to be rerouted. Even when limits are exceeded and traffic is rerouted, this does not trigger [Attack Mode](/product-guides/network-ddos-v3/introduction.md#three-modes-of-security-posture) (which is based on different criteria).
{% endhint %}

{% hint style="info" %}
When configuring this service, it can be useful to run a test, to verify that rerouting occurs as expected.\
\
When sending traffic, the minimum requirements for testing the rerouting functionality are:

* To exceed at least one configured threshold (a **Mbps Limit** or **Kpps Limit**)...
* And trigger at least one enabled anomaly reason (from the **Reasons (optional)** list)...
* While originating from at least 50 unique source IP addresses.
  {% endhint %}

***

## Reroute Limits

The **Mbps Limit** and **Kpps Limit** define traffic thresholds. Everything (for a single IP in the prefix) under the bandwidth and package limit will be accepted.&#x20;

{% hint style="info" %}
*Mbps* *Limit* and *Kpps Limit* refer to the configured thresholds. To see the actual traffic values being experienced by the prefixes, select the  controls (`>`) to expand the entries.
{% endhint %}

If one of the defined limits for prefixes (Mbps or Kpps) is reached, an algorithm checks whether any reasons for rerouting (any of the **Reasons (optional)**, described below) were fulfilled. If so, the following will occur:

* An entry will appear in [Traffic Anomalies](/product-guides/netflow-ddos-detector/interface/traffic-anomalies.md)
* **Auto Reroute** is evaluated
  * If it is enabled, then:
    * Automatic rerouting will occur.
    * The prefix will be moved to the [Rerouted](#rerouted) list.
    * If one or more email recipients were defined, notification email(s) will be sent.&#x20;
  * Otherwise, the prefix will merely be moved to the [Not Rerouted](#not-rerouted) list.

{% hint style="warning" %}
If **Auto Reroute** is disabled, [Traffic Anomalies](/product-guides/netflow-ddos-detector/interface/traffic-anomalies.md) should be monitored regularly, so that you will know when traffic limits are breached, and can perform a manual rerouting if desired. Otherwise, **if manual rerouting is not performed, Link11 will be unable to filter the traffic.**
{% endhint %}

Limits are defined by selecting the **+ Add Reroute Limit** button to add a prefix to the list, or the **Edit** button to re-configure an existing one. This window will appear:

<figure><img src="/files/fPksS6gX2Ou0uNVmrLtn" alt=""><figcaption><p>For display purposes, most of the Reasons list is not included in this screenshot.</p></figcaption></figure>

Reroute Limit parameters are:

* **Prefix**: the one for which settings are applied
* **Mbps Limit**: the traffic limit on one source IP per minute (can be set to 0)
* **Kpps Limit**: the limit for packets on one source IP per minute (can also be set to 0)
* **Reasons (optional)**: granular criteria of various types. The enabled Reasons are evaluated when an Mbps Limit or Kpps Limit is exceeded. If it is desirable to disable any Reasons, begin with the lower values (since lower limits trigger first).&#x20;
* **Optional BGP Session Settings**: see discussion below.
* **Enable Auto Reroute**: when enabled, rerouting will occur automatically. If not enabled, see the previous warning about the implications.
* **Receive Notification**: enables notification emails to be sent when automatic rerouting occurs.
* **Notification Recipient Email Address**: enter email address(es) to receive the notifications. Multiple addresses are separated with a comma.

### Optional BGP Session Settings

If the **Optional BGP Session Settings** toggle is enabled, the following parameters become available to control traffic flow:

* **AS Path**: Optional. Allows for controlling route preference via appending additional ASNs. Example: if two ASNs are chosen here, the resulting AS-Path value will be: \[*origin ASN1, origin ASN2, customer ASN, Link11's ASN*]. The available choices are determined from the **Prefix**(es) entered at the top of the form.&#x20;
* **AS Path Prepends**: The number of times the origin ASN is prepended for prefixes announced on this BGP session.
* **Next Hop**: A valid IPv4/IPv6 address to be set as the next hop in the advertised route.
* **Communities**: One or more standard or extended communities to tag routes. Link11 supports a range of BGP community values: [see the list here](/reference/bgp-community-values.md).

***

## **Not Rerouted**

<figure><img src="/files/OjNs5rdd5uoUeX6H27r2" alt=""><figcaption></figcaption></figure>

Netflow DDoS Detector offers the option to track when a prefix is under attack, while also disabling automatic rerouting. In cases where traffic limits are exceeded but rerouting is disabled, these prefixes will be displayed here.&#x20;

Customers have the option to manually trigger rerouting for any of the listed prefixes, using the \
**+ Announce** **Reroute** button. When the parameters in the [manual rerouting window](#manual-rerouting) are successfully completed, the new routes are announced and the prefixes are moved to the [Rerouted](#rerouted) section.

**Note:** Routes cannot be updated for the first 60 minutes after they are added. To remove a route before the 60 minute timeout is complete, please contact our support team at <support@link11.com>.

***

## **Rerouted**

<figure><img src="/files/f8ug7QuMxGi1tYqGiDJv" alt=""><figcaption></figcaption></figure>

Prefix ranges that have been routed to Link11 either automatically due to exceeding defined limits, or manually by a customer, are all displayed here. Routes can be removed by clicking the **Remove Reroute** button.&#x20;

**Note:** Routes cannot be removed for the first 60 minutes after they are added. To remove a route before the 60 minute timeout is complete, please contact our Support team at <support@link11.com>.

Manual rerouting is available via the **+ Add Manual Rerouting** button.&#x20;

***

## **Manual Rerouting**

Traffic can be routed to Link11 manually at any time. All routes will be announced as /24 CIDRs but smaller or larger ranges can be added.

Manual rerouting is done via the **+ Announce** **Reroute** button in the **Not Rerouted** section, or the **+ Add Manual Rerouting** button in the **Rerouted** section. In the window that appears, the following parameters are available.

* **Prefix**: One or more prefixes to reroute.
* **BGP Sessions**: One or more of the BGP Sessions configured for Network DDoS must be selected. The selected BGP Sessions will be used to determine where this route should be announced and where Link11 will ingest traffic. In general it is recommended to select all BGP Sessions that contain the selected prefix(es).
* **Remove Date & Time**: the date and time when the route will be released.
* **Optional BGP Session Settings**: same as described [above](#optional-bgp-session-settings).

## Additional information

### Limit evaluation

Here are expanded illustrations of how the system evaluates active Rerouting Limits.

<table data-header-hidden><thead><tr><th width="208">Text</th><th width="218"></th><th></th></tr></thead><tbody><tr><td><strong>Reason</strong><br><br><br></td><td><strong>Explanation</strong> <br>Flow data is received every minute<br></td><td><strong>Pseudocode illustration</strong><br>($d = reason <br>lt = less than <br>gt= greater than)</td></tr><tr><td>X mbits exceeded</td><td>Bandwidth per minute is bigger than defined value (*60) for each IP and Netflow receiver</td><td></td></tr><tr><td>X kpps small packets exceeded</td><td>More than the defined package value was received with an average package size smaller than 100 byte</td><td><code>$d = array();</code><br><code>$d['kpps'] = 250;</code><br><code>$d['nprefixes'] = 50;</code><br><code>$d['avgsizelt'] = 100;</code><br><code>$d['matches'] = 3;</code><br><code>$d['reason'] = '250 kpps with small packets exceeded';</code><br><code>$d['maybe'] = true;</code></td></tr><tr><td>X kpps exceeded</td><td>Package size exceeds defined value</td><td><code>$d = array();</code><br><code>$d['kpps'] = 500;</code><br><code>$d['nprefixes'] = 50;</code><br><code>$d['matches'] = 2;</code><br><code>$d['reason'] = '500 kpps exceeded';</code><br><code>$d['maybe'] = true;</code></td></tr><tr><td>X nprefixes with tiny packets and very low packetrate per srcprefix</td><td><p>A defined number of prefixes sent a very low number of packages (about 1 packet per second) with a tiny package size to the source prefix<br></p><p><em>$d['maybe'] is no longer in the flow data because it is an attack indicator</em></p></td><td><code>$d = array();</code><br><code>$d['nprefixes'] = 250;</code><br><code>$d['avgpacketslt'] = 1.001;</code><br><code>$d['avgsizelt'] = 80;</code><br><code>$d['matches']= 3;</code><br><code>$d['reason'] = '250 nprefixes with tiny packets and very low packetrate per srcprefix';</code></td></tr><tr><td>X nprefixes exceeded</td><td>Number of prefixes talking to source prefix exceed defined value</td><td><code>$d['nprefixes'] = 1250;</code><br><code>$d['matches'] = 1;</code><br><code>$d['reason'] = '1250 nprefixes exceeded';</code><br><code>$d['maybe'] = true;</code></td></tr><tr><td>X nprefixes with at least 5 ports per srcprefix</td><td>Calculates if Nprefixes uses at least 5 ports to talk with srcprefix by dividing nsrcprefixes/nsrcports and if result is smaller than nsrcportprefixfactor it gets detected as a DDoS attack</td><td><code>$d['nsrcports'] = 100;</code><br><code>$d['nprefixes'] = 100;</code><br><code>$d['nsrcportsprefixfactor'] = 0.20;</code><br><code>$d['matches'] = 3;</code><br><code>$d['reason'] = '100 nprefixes with at least 5 ports per srcprefix';</code><br><code>$d['maybe'] = true;</code></td></tr><tr><td>lots of srcports and dsports</td><td></td><td><code>$d = array();</code><br><code>$d['nsrcports'] = 250;</code><br><code>$d['ndstports'] = 250;</code><br><code>$d['nprefixes'] = 100;</code><br><code>$d['nsrcportsprefixfactor'] = 1.0;</code><br><code>$d['matches'] = 4;</code><br><code>$d['reason'] = 'lots of srcports and dstports';</code></td></tr><tr><td>1000 nprefixes with a very low packetrate per srcprefix</td><td>1000 prefixes sent around 1 package per sample minute</td><td><code>$d = array();</code><br><code>$d['nprefixes'] = 1000;</code><br><code>$d['avgpacketslt'] = 1.001;</code><br><code>$d['matches'] = 2;</code><br><code>$d['reason'] = '1000 nprefixes with a very low packetrate per srcprefix';</code></td></tr><tr><td>X nprefixes with tiny packets exceeded</td><td>Number of prefixes sent package with tiny package size</td><td></td></tr><tr><td>100mbits uncommon ip protocols exceeded</td><td>A list with common IP protocols exist, and if the number of packages that were sent over an uncommon IP protocol exceed 100mbits, an attack is detected</td><td><code>$uncommonprotddos[0]['mbits'] = 100;</code><br><code>$uncommonprotddos[0]['nprefixes'] = 50;</code><br><code>$uncommonprotddos[0]['matches'] = 2;</code><br><code>$uncommonprotddos[0]['reason'] = '100 mbits uncommon ip protocols exceeded';</code></td></tr><tr><td>500mbits vpn ip protocols and 100 prefixes exceeded</td><td>VPN Protocols exist if 500mbits of that are exceeded and more than 100 prefixes are exceeded</td><td><code>$vpnprotoddos[0]['mbits'] = 500;</code><br><code>$vpnprotoddos[0]['nprefixes'] = 100;</code><br><code>$vpnprotoddos[0]['matches'] = 2;</code><br><code>$vpnprotoddos[0]['reason'] = '500 mbits vpn ip protocols and 100 prefixes exceeded';</code></td></tr><tr><td>X countries <em>(after MaxMind Database)</em></td><td>Origin gets traffic from more than defined value of countries</td><td></td></tr><tr><td>X isps</td><td>Origin gets traffic from more than defined value of ISPs</td><td></td></tr><tr><td>1500 mbit udp amplification traffic</td><td>At least 1500mbit (250 packets) of the traffic is udp amplification traffic (on specific ports)</td><td><code>$udpampddos[0]['mbits'] = 1500;</code><br><code>$udpampddos[0]['nprefixes'] = 250;</code><br><code>$udpampddos[0]['matches'] = 2;</code><br><code>$udpampddos[0]['reason'] = '1500 mbit udp amplification traffic';</code></td></tr><tr><td>majority is udp amplification traffic</td><td>50% of the 1500mbit traffic sent is UDP amplification traffic</td><td><code>$udpampddos[1]['mbits'] = 50;</code><br><code>$udpampddos[1]['nprefixes'] = 90;</code><br><code>$udpampddos[1]['mbitsfactor']  = 2;</code><br><code>$udpampddos[1]['matches'] = 3;</code><br><code>$udpampddos[1]['reason'] = 'majority is udp amplification traffic';</code></td></tr><tr><td>uncommon udp amplification traffic</td><td>There are different ports for UDP traffic. A list defines uncommonly used ports; if traffic is received there, this reason triggers.</td><td></td></tr><tr><td>udp amplification traffic with fragments</td><td>Amplification traffic uses fragments and a source port can't be assigned. For every 4. packet we match it to this rule in case of attack.</td><td><code>$udpfragmentddos[0]['mbits'] = 50;</code><br><code>$udpfragmentddos[0]['nprefixes'] = 90;</code><br><code>$udpfragmentddos[0]['mbitsfactor'] = 4; // for udp amp with fragment ddos we expect less traffic to be from a amplification source port</code><br><code>$udpfragmentddos[0]['matches'] = 3;</code><br><code>$udpfragmentddos[0]['reason'] = 'udp amplification traffic with fragments'; // if this string is changed, it needs to be changed in the maybe recheck path as well</code><br><code>$udpfragmentddos[0]['maybe'] = true;</code></td></tr><tr><td>mismatched udp traffic to tcp ports</td><td>UDP amplification attack to the wrong TCP port indicates an attack.</td><td><code>$mismatchedudptcp[0]['mbits'] = 50;</code><br><code>$mismatchedudptcp[0]['nprefixes'] = 15;</code><br><code>$mismatchedudptcp[0]['matches'] = 2;</code><br><code>$mismatchedudptcp[0]['reason'] = 'mismatched udp traffic to tcp ports';</code></td></tr><tr><td>low flow port receiving X mbit flows</td><td>A (lowflow) port that usually doesn't receive a lot of traffic suddenly receives a lot of traffic from a single source IP. Indicates a DDoS attack. Average MBits per prefix</td><td><code>$lowflowudpddos[0]['mbits'] = 50;</code><br><code>$lowflowudpddos[0]['avgmbits'] = 5;</code><br><code>$lowflowudpddos[0]['nprefixes'] = 15;</code><br><code>$lowflowudpddos[0]['matches'] = 3;</code></td></tr><tr><td>mbits traffic from unassigned/rfc1918 space</td><td>RFC 1918 manages internal LAN IPs. In this list, there are prefixes that aren’t/shouldn’t be used on the internet. If traffic from these IPs is received, it’s probably a DDoS attack (badly programmed flooder).</td><td><code>$rfc1918ddos[0]['mbits'] = 1;</code><br><code>$rfc1918ddos[0]['nprefixes'] = 2;</code><br><code>$rfc1918ddos[0]['matches'] = 2;</code><br><code>$rfc1918ddos[0]['reason'] = 'mbits traffic from unassigned/rfc1918 space';</code></td></tr><tr><td>mbits traffic from and to privileged ports</td><td>A list of privileged ports (all ports &#x3C;1024) that can only be used by admins. These usually don’t get used unless a random port talks to another random port.</td><td><code>$privportsddos[0]['mbits'] = 10;</code><br><code>$privportsddos[0]['nprefixes'] = 10;</code><br><code>$privportsddos[0]['matches'] = 2;</code><br><code>$privportsddos[0]['reason'] = 'mbits traffic from and to privileged ports';</code></td></tr></tbody></table>

***

### **Notification Templates**

**Auto Rerouting Active:**

```
Link11 has Detected a Potential Attack Against {{prefix}} and rerouted the prefix

Link11 has detected a netflow event that triggered a rerouting event. The current bandwidth of the event is: {{mbps}} Mbps.
Please log into the WebGUI for more details
```

**Auto Rerouting Inactive:**

```
Link11 has Detected a Potential Attack Against {{prefix}}
Link11 has detected a netflow event that would have triggered rerouting. The current bandwidth of the event is: {{mbps}} Mbps.
Please log into the WebGUI for more details
```
