Juniper MX Filtering Gateway — always-on DDoS protection at line rate
A ready-to-deploy DDoS filtering firewall for your Juniper MX204 (4×100GE) that drops attack traffic in hardware at line rate, driven by WanGuard detection and BGP FlowSpec — configured and delivered by ITORO for your router.
Hardware line-rate filtering, always on
Cloud scrubbing reacts in tens of seconds and adds cost per Gbps. An on-prem Juniper MX gateway filters malicious traffic the moment WanGuard detects it — at the router, in hardware, without redirecting your traffic anywhere.
MX204 gateway throughput — sized for ISP and data-center edges.
WanGuard detection triggers FlowSpec rules onto the MX automatically.
Attack traffic dropped in hardware — clean traffic passes untouched.
WanGuard detects, Juniper MX filters
WanGuard sees your traffic via a port mirror and identifies the attack in seconds. It then pushes granular BGP FlowSpec rules to the Juniper MX, which enforces them at line rate on the forwarding plane. RTBH remains available as a last-resort fallback for attacks too large to filter granularly.
- Always-on — no traffic redirection, no scrubbing-center latency.
- FlowSpec on the MX line cards; RTBH as fallback.
- Pre-configured filter package tuned by ITORO.
- Pairs with Juniper MX Telemetry for full NOC visibility.
Juniper MX — always-on DDoS protection
A line-rate stateless firewall, active before any attack reaches your network: transit DDoS filtering on the WAN/LAN interfaces (Layer 1) plus routing-engine protection via lo0 CoPP (Layer 2).
Juniper MX filter package — depth & complexity
Delivered by ITORO as a ready-to-deploy configuration.
Transit filters — hard-blocked categories
- Rate-limited (policed, not dropped): SYN floods · IP fragments · ICMP · DNS · NTP.
Routing Engine CoPP
- Default-deny — all unmatched traffic blocked.
- Thousands of potential attack vectors eliminated by architecture alone.
Every filter term has a named counter
- Real-time visibility via Grafana and Juniper Telemetry.
- Counters follow structured naming — protocol, direction, attack type.
- Live monitoring available also from the JunOS CLI at any time.
Anti-spoofing — uRPF on all interfaces
- Validates source IP addresses before any filter processing occurs.
- Feasible-path mode — supports asymmetric routing in multi-homed environments.
- Dedicated fail-counter — RPF violations logged separately from DDoS counters.
Predictable cost, full control
No per-Gbps fees
Own the hardware; no metered cloud-scrubbing bills that scale with attack size.
Your data stays yours
Traffic never leaves your network — important for ISPs, telecoms and regulated operators.
Deployed by a Gold Partner
ITORO delivers the filtering firewall for your Juniper MX plus the WanGuard integration — as one solution.
Interested in an active Juniper MX filtering gateway?
We deliver a DDoS filtering firewall for your Juniper MX router at the edge — tuned with WanGuard and ready to run.
Contact ITORO