Skip to content
NexCMPNexCMP

Edge network

BGP edge & DDoS defense, built in

The DDoS and BGP module is part of the same platform as billing and the customer portal — it ships when you run BGP, not as a separate product to bolt on.

Where a packet is filtered

Traffic is checked in stages, from the upstream link down to the customer's IP, so most bad traffic never reaches the parts of the stack that cost the most to process.

  1. 1

    Upstream link

    Traffic arrives over your BGP-announced prefixes. Attacks larger than the uplink itself are handed off to the upstream carrier via RTBH.

  2. 2

    XDP / eBPF (kernel)

    Line-rate filtering scoped to protected IPs only: a large malicious-IP feed, established public blocklists, and per-source rate limits, all enforced before the packet reaches the rest of the firewall.

  3. 3

    nftables (blocking rules)

    Per-IP and per-source rules — single IP, CIDR, ASN or country — added from the portal or applied automatically by detection.

  4. 4

    Customer IP

    What is left reaches the VM's dedicated public IP behind its own firewall rules and, when enabled, web-request rate limits.

RTBH

BGP blackhole (RTBH)

For attacks big enough that filtering at the edge is not the right tool, NexCMP can ask the upstream carrier to drop traffic to one address entirely.

Manual blackhole

Request an RTBH for a single attacked IP with a chosen scope and TTL, and withdraw or extend it yourself.

Automatic escalation

When detection and AI analysis confirm a volumetric attack past threshold, the platform requests the upstream blackhole automatically and withdraws it once the attack ends.

Self-service from the customer portal

Customers can request, extend or withdraw an RTBH on their own attacked IP, choosing an international or domestic scope.

Guardrails

  • Only /32 (IPv4) and /128 (IPv6) — never a wider block.
  • Only inside your own announced prefixes.
  • Network and gateway addresses are never blackholed.
  • A cap on how many entries can be active at once.
  • A TTL with automatic withdrawal — nothing stays blackholed forever by default.

Detection & response

Attacks are found automatically, graded by severity, and surfaced where your team already looks.

Per-IP baselining

Continuous, adaptive traffic baselining per IP opens and closes attack events automatically and grades their severity.

AI-assisted blocking

AI reviews a rolling window of traffic and log evidence and can apply temporary blocking rules automatically when confidence is high.

On-demand AI analysis

Ask the AI to analyze a specific attack event, or the last 30 minutes on any protected IP, within a daily usage limit.

Alerting

Real-time alerts to Telegram, webhook or email when an attack starts or ends.

Events & intrusion alerts

Attack history, an audit log of actions on each IP, and Suricata intrusion-detection alerts relevant to that IP, in one place.

Self-service DDoS Shield

Every VM's public IP is linked to its own DDoS Shield automatically, and customers manage it themselves from the portal — no support ticket needed for routine changes.

Per-IP dashboard

Traffic charts, live connections, top sources, events and protection settings for one IP, all on one page.

Live connections & top sources

See top traffic sources by country, ASN and port for any protected IP, with a one-click block on each row.

Blocking rules

Add or remove rules — single IP, CIDR, ASN or country — directly from the portal, with CSV export and bulk delete.

Web-request rate limiting

Set per-source SYN/s and packets/s limits and allowed ports to blunt application-layer floods; changes apply right away, limited to one change per 10 minutes per IP.

IPv6 protection

IPv6 is protected at three levels of detail, from an announced block down to a single address.

Aggregate visibility

Aggregate traffic visibility across announced IPv6 blocks, at the BGP-block level.

Auto-discovered /48 protection

Active customer /48 blocks inside announced ranges are discovered and protected automatically, with automatic cleanup of inactive ones.

Per-address drill-down

Detailed visibility down to individual IPv6 addresses within a customer block, for observation.

What the module needs from you

The DDoS/BGP module runs on infrastructure you operate — it comes with the platform once these pieces are in place.

  • Your own ASN and IP space.
  • At least one BGP session with an upstream carrier that honours blackhole (RTBH) communities.
  • A Linux edge server in the traffic path, running FRR.
  • Commodity network cards work — filtering runs in XDP generic mode, no special hardware required.

Contact sales to review your topology.

Contact sales

What this is not

  • Not a WAF: there is no TLS inspection or Layer-7 signature engine.
  • Filtering runs on the edge servers you operate — this is not a global anycast scrubbing network.
  • An attack larger than your own uplink still needs upstream RTBH; the edge alone cannot absorb it.
  • XDP runs in generic mode — there is no dedicated packet-filtering hardware offload.

Per-IP bandwidth shaping is built end-to-end but is currently in staged rollout and not yet enforcing limits on live traffic.

Live at vnic.cloud

vnic.cloud is the production reference deployment of NexCMP, running its own BGP edge.

10 Gbps

unmetered port

2

autonomous systems (AS401541 & AS401617), multi-homed edge BGP

8

public IPv4 /24 subnets + native IPv6

“Dual autonomous systems with multi-homed edge BGP routing, active line-rate DDoS filtering and upstream blackholing (RTBH) on demand.”

Source: vnic.cloud · accessed 2026-09-27

Run your own network? Bring your BGP.

Tell sales about your ASN, upstream carriers and expected traffic, and get the DDoS/BGP module scoped for your setup.