DDoS Protection
XDP edge guard — live status, blocked sources and traffic at the uplink and all tunnels.
Interface attachments
| Interface | Type | Mode | Action |
|---|
Filters
Per-source thresholds for auto-blocking and the never-block whitelist.
Thresholds
Whitelist
Sources never auto-blocked — one IP per line. Tunnel remotes and gateways are pre-seeded.
Blocklist
Sources dropped at XDP. Manual blocks and auto-blocks live here.
Block a source
Blocked sources
| IP | Time left | Action |
|---|
Traffic
Live aggregate rates across every attached interface, then the top source IPs.
Throughput
Packets / SYN
Top talkers
| Source | Packets | Bytes | SYN |
|---|
Attack logs
Targets under attack (victim ip:port) — live and peak bandwidth, PPS, timestamps.
Active attacks
| Target | Proto | Since | Current | Peak | PPS | Packets | Status |
|---|
Recent attacks
| Target | Proto | Start | End | Duration | Peak | Peak PPS | Packets | Status |
|---|
Filter rules
Advanced XDP filtering — ordered rules matching src/dst CIDR, protocol, ports and SYN, with drop / allow / rate-limit actions. First match wins.
| # | Match | Action | Rate limit | Hits | Status | Actions |
|---|