Setup guides
Router setup guides
How to send flow data from your routers and switches to Heimnull, and how to let it announce blackholes and FlowSpec rules back to them. Each guide has the configuration, what each line does, and how to check it.
| Guide | Flow export | Mitigation |
|---|---|---|
| Juniper MX | IPFIX packet samples (inline monitoring), or inline J-Flow | iBGP: RTBH blackholes and FlowSpec, IPv4 and IPv6 |
| MikroTik RouterOS 7 | NetFlow v9 or IPFIX | iBGP: RTBH blackholes (RouterOS has no FlowSpec) |
| Juniper EX | sFlow v5 | None: a switch, for visibility |
| Juniper SRX | J-Flow v9, plus NAT session logs | None: names the internal host behind NAT |
Ports on the Heimnull server
Every flow port accepts every format, so a router sending IPFIX to the NetFlow port still works. Allow the flow, BGP and log ports from your routers only.
Using something else? Any router or switch that exports NetFlow v9, IPFIX or sFlow v5 works, and any router that accepts BGP routes can act on a blackhole. Write to us with your model.
| Port | For |
|---|---|
| 2055/udp | NetFlow v9 |
| 4739/udp | IPFIX |
| 6343/udp | sFlow v5 |
| 179/tcp | BGP, once you set up mitigation |
| 5514/udp | Juniper SRX session logs, only when turned on |
| 80/tcp | The web console |
Before you start
- Your networks in Heimnull. Inbound and outbound come from your prefixes, so add them first (Configure → Networks).
- A stable source address. Heimnull identifies each exporter by the address its datagrams come from. Use a loopback or a fixed interface.
- Sample once per packet. Sample at the edge, on the WAN side, so no packet is counted twice.
- Mitigation stays off. Hostgroups start at "notify". Set up BGP, use the preview and a dry run, then choose an action. See FlowSpec and RTBH blackholes.
Questions about your setup?
Write to us with your router model and software release, or try the demo to see what Heimnull does with the data.
info@heimnull.com