Flowspec – Knowledgebase
Knowledgebase Contents
- Central Hub
- Does Inter.link Provide an API?
- Automated Provisioning
- BGP Communities
- Cloud Connect
- DDoS Protection
- Inter.link DDoS Protection Templates - FlexEthernet
- FlexTunnel
- Flowspec
- Inter.link Insights
- IP Access
- IP Transit
- Office Fiber
- Peering Policy
- Ports
- Pricing
- Release Notes
- Routing Policies
- What Can I Do in the Inter.link Portal?
Overview
Inter.link provides a fully managed DDoS mitigation service which automatically detects attacks against the customer, redirects the attack traffic through Inter.link’s attack filters, filters out the attack traffic, and then forwards on the genuine traffic to the customer.
FlowSpec is Inter.link’s alternative which enables customers to self-manage DDoS mitigation on their network.
FlowSpec (RFC8955 & RFC8956) is an add-on to Inter.link’s IP Transit service which allows a customer to automatically send messages from their network to the Inter.link network. These messages tell the Inter.link network to drop or rate limit certain traffic which is destined for the customer’s network. This allows the customer to self-operate a basic DDoS protection service.
With FlowSpec, the customer must monitor their own traffic and look for attacks, then their network must signal the Inter.link network to drop the attack traffic before it reaches the customer.
Benefits
- The customer takes responsibility for the traffic filtering rules applied to their traffic (when compared to a hosted/managed DDoS protection service).
- The customer can coordinate filtering across all their upstream carriers (if they all support FlowSpec) to have more effective traffic filtering.
- The cost can be lower (when compared to a managed DDoS protection service).
Supported Features
- All features in RFC8955 and RFC8956 are supported apart from any exceptions listed in the Technical Limitations section below.
- Inter.link supports Flowspec rules with either the drop or rate limitation action attached, or no action (“accept”).
Technical Limitations
Listed below are the limitations of the FlowSpec service.
The following are known the filtering limitations for the Inter.link network:
- All matching components described in RFC8955 are supported except for the following known caveats:
– For TCP flags, the ECE, CWR and NS flags are not supported.
– For fragment flags, only the Is a fragment (IsF) bit is supported, and this is only supported for IPv4 packets. Combining source/dest ports and the Fragment flags in the same rule is not supported.
- All matching components described in RFC8956 are supported except for the following known caveats:
– For TCP flags, the ECE, CWR and NS flags are not supported.
– Matching on IPv6 packet length or IPv6 flow label fields is not supported.
– It is not possible to match IPv6 fragments.
Billing for Flowspec

How to Order
Flowspec support can be requested through the portal, however it will be enabled on customer’s BGP sessions only upon sales approval.
If you are interested in utilising FlowSpec for your network, please email sales@inter.link and a member of Inter.link’s team will be in touch to set this up for you.