View the demo

Setup guides

Router setup guides

How to send flow data from your routers and switches to Heimnull, and how to let it announce blackholes and FlowSpec rules back to them. Each guide has the configuration, what each line does, and how to check it.

GuideFlow exportMitigation
Juniper MXIPFIX packet samples (inline monitoring), or inline J-FlowiBGP: RTBH blackholes and FlowSpec, IPv4 and IPv6
MikroTik RouterOS 7NetFlow v9 or IPFIXiBGP: RTBH blackholes (RouterOS has no FlowSpec)
Juniper EXsFlow v5None: a switch, for visibility
Juniper SRXJ-Flow v9, plus NAT session logsNone: names the internal host behind NAT

Ports on the Heimnull server

Every flow port accepts every format, so a router sending IPFIX to the NetFlow port still works. Allow the flow, BGP and log ports from your routers only.

Using something else? Any router or switch that exports NetFlow v9, IPFIX or sFlow v5 works, and any router that accepts BGP routes can act on a blackhole. Write to us with your model.

PortFor
2055/udpNetFlow v9
4739/udpIPFIX
6343/udpsFlow v5
179/tcpBGP, once you set up mitigation
5514/udpJuniper SRX session logs, only when turned on
80/tcpThe web console

Before you start

  • Your networks in Heimnull. Inbound and outbound come from your prefixes, so add them first (Configure → Networks).
  • A stable source address. Heimnull identifies each exporter by the address its datagrams come from. Use a loopback or a fixed interface.
  • Sample once per packet. Sample at the edge, on the WAN side, so no packet is counted twice.
  • Mitigation stays off. Hostgroups start at "notify". Set up BGP, use the preview and a dry run, then choose an action. See FlowSpec and RTBH blackholes.

Questions about your setup?

Write to us with your router model and software release, or try the demo to see what Heimnull does with the data.

info@heimnull.com