Flowspec (Custom)

Traffic Type Response Integration

🚧

Prior to creating a Flowspec plugin, you will need to configure at least 1 device with a unicast BGP neighbor.

Flowspec (Custom) differs from Flowspec in that it allows for a custom rule to be added. Rules are written in the flowspec token language, e.g. match destination DSTIP then discard

Prerequisites

Different vendors and products may have their unique documentation and prerequisites for this setup. Below are example links to configure devices with a unicast BGP neighbor:

Netography Portal Steps

In Settings > Response Integrations, click Add Integration. Select Flowspec (Custom)

Configuration

The following fields are specific to the Custom Flowspec integration.

FieldRequiredDescriptionExamples
NeighborsyesIPv4/v6 unicast BGP neighbors configured in the Netography Portal.
Local PreferenceyesUsed to choose the exit path for an autonomous system. Default 100100
RuleyesCustom flowspec token languagematch destination DSTIP then discard
Factorsyessrcip
ExpirationNumber of seconds the blocklist will remain active3600
MaxLimit on number of blocks1000
Allow ListOne or many Allow Lists configured in the Netography Portal, or a List of IP or IP/CIDR addresses
AggregateAggregate IP addresses by mask length