> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/netflow-ddos-detector/introduction.md).

# Introduction

Link11 Netflow DDoS Detector is an add-on service to [Network DDoS Protection](/product-guides/network-ddos-v3.md). It provides:

* **On-demand DDoS scrubbing**: Netflow DDoS Detector provides customers with a dynamic capability for advertisement management. When attacks occur, traffic can be routed into Link11, then released again.
* **Fine-tuning** of threat and response criteria.
* **Traffic engineering**, using BGP attributes to influence routing
* **In-depth analytics**, with additional insights and more granularity than Network DDoS alone.

## How it works

Netflow DDoS Detector uses Netflow records exported from customer flow speakers. Link11 analyzes the traffic customers are receiving.

When attacks are detected, Link11 injects routes on the customer's behalf. It then ingests and filters the traffic until the attack is over. The routes are then de-announced.&#x20;

Announcements and de-announcements can all be done automatically or manually.

## **Requirements**

* Flow records (Netflow v1, v5, v7, v9 and IPFIX are supported)
* /23 of IP space or greater

In the event Link11 detects an attack, a /24 covering the affected destination will be advertised from the Link11 routers. Traffic will be analyzed, filtered and forwarded to the customer over either an L2 or GRE tunnel connection established between Link11 and the customer infrastructure.

If the customer (in the case of an auto-route event on the part of Link11) only announces a /24 , it is not possible to take over the attacked /24. This is due to the RFC regulations in the BGP protocol.

## **Limitations**

* Requires a more specific route for announcement. A customer must advertise a less specific route (/23 or greater) to avoid route confusion when Link11 injects routes.
* Designed to protect individual destination IPs; does not protect against carpet-bombing attacks.
* Smaller then a /24 Protected network does not work here, so the protected IP needs to be in at least in a protected /24 Basic Protection or Full Protection Network.
