Made4Flow 2.11.1: NetFlow export for DDoS mitigation, new alerts, and much more
Check out what’s new in Made4Flow 2.11.1: export NetFlow V5, V9, and sFlow to DDoS mitigation platforms, configure alerts by router, and integrate with external systems via REST API. Anyone who operates a medium- or large-scale network knows that traffic visibility isn’t a competitive advantage—it’s a matter of survival. Identifying an ongoing DDoS attack, determining which country the anomalous traffic is coming from, or integrating the NetFlow analyzer with the carrier’s mitigation platform without having to reconfigure routers: these are real day-to-day challenges for NOC and security teams. Version 2.11.1 of Made4Flow, available starting February 27, 2026, addresses precisely these needs. In this article, we detail each new feature and what it accomplishes in practice. What is Made4Flow, and who is this update for? Made4Flow is a NetFlow and sFlow analyzer developed by Made4it for internet service providers, telecom operators, and NOC teams that need detailed visibility into network traffic. It collects flows exported by routers (NetFlow V5, V9, sFlow, IPFIX), applies intelligence to this data, and delivers real-time graphs, alerts, and analytics. This update is particularly relevant for those who: How to Export NetFlow to a DDoS Mitigation Platform — Without Configuring the Routers This is the most eagerly awaited new feature in version 2.11.1 for teams that operate DDoS mitigation platforms. The previous scenario was as follows: to send flows to a third-party mitigation solution, you had to configure the router to export simultaneously to two destinations—the Made4Flow collector and the mitigation platform’s collector. In many environments, this is not simple, is risky, or is simply unfeasible. With Made4Flow’s new flow replicator, the router continues to export flows to Made4Flow as usual. From there, the platform itself replicates and forwards the flows to any external destination in the following formats: Configuration is performed directly through the Made4Flow interface—no downtime, no maintenance window on the routers, and no operational risk. For service providers using solutions such as Wanguard, NSFOCUS, Arbor, or any other platform that uses NetFlow or sFlow, this feature eliminates a complex dependency and speeds up integration. Integrate your DDoS mitigation platform with Made4Flow and replicate NetFlow V5, V9, IPFIX, or sFlow with just one configuration. Threat Analysis: New Visualization to Identify Internal Attacks The Made4Flow Threat Analysis page has been completely redesigned in version 2.11.1. The new layout consolidates the key security metrics on a single screen: total detected threats, suspicious IP addresses, volume of malicious traffic, temporal distribution of incidents, and the main targets. The geographic view of threats has also been enhanced, making it easier to correlate the attack’s origin with its impact on the network. For security teams that need to respond quickly to incidents, this means fewer clicks and more context available at the critical moment. Find out who is launching attacks within your internal network with just ONE CLICK. Sampling Rate and Router Alerts: Stop Analyzing Distorted Data One of the most subtle issues in NetFlow monitoring is sampling rate incompatibility. When the value configured in the analysis tool differs from the one the router is actually using, all traffic graphs become distorted—and the team may make decisions based on incorrect data without realizing it. Version 2.11.1 adds two types of alerts specific to this scenario: Sampling Rate Incompatibility Alert It automatically notifies you when the sampling value configured in Made4Flow differs from what the router is reporting. This is especially useful in environments with multiple routers from different manufacturers (Cisco, Huawei, MikroTik, Juniper), where the sampling pattern may vary. Explicit alerts by router Each router registered in Made4Flow can now have its own active alerts, which are visible directly in the device list and on the edit page. This simplifies management in environments with dozens or hundreds of monitored routers. Get notified before the problem affects your data—set it up in minutes. Traffic by Country and App by Prefix: Real-Time Geographic Visibility For internet service providers and telecom operators, knowing where traffic comes from is just as important as knowing how much traffic there is. A spike originating from a particular country may indicate a volumetric attack in progress; a specific prefix consuming an unusually high amount of bandwidth may signal that a customer’s system has been compromised. Version 2.11.1 adds a new overview screen with traffic charts broken down by: This visibility was available in the raw data, but now it is presented in a native visual format, eliminating the need to export data, cross-reference spreadsheets, or use external tools. See in seconds which country or prefix is generating unusual traffic—and take action before the attack escalates. Aggregation by TCP Flags and Countries: Accurately Detect DDoS Attack Patterns Modern DDoS attacks often masquerade as seemingly normal traffic. Analyzing TCP flags—such as SYN, ACK, or RST floods—is one of the most effective ways to identify malicious traffic before it impacts services. Version 2.11.1 adds new aggregation tabs to the Made4Flow raw data: For security teams investigating incidents, the combination of analysis based on flags and geographic origin is particularly powerful for correlating attack techniques with their source. Identify attacks based on TCP flag patterns and geographic origin in seconds, without external tools. Made4Flow REST API: Integrate with Any System Version 2.11.1 marks the arrival of Made4Flow’s official REST API, opening up the platform for programmatic integrations with other systems. The API offers: In practice, this enables integrations with Zabbix, Grafana, ticketing systems, SIEM, external dashboards, and any system that retrieves data via HTTP. Connect Made4Flow to your ecosystem and automate network data using your own stack. Other improvements in version 2.11.1 Fixes in Version 2.11.1 Frequently Asked Questions About Made4Flow 2.11.1 Can Made4Flow export NetFlow data to my DDoS mitigation platform?Yes. Starting with version 2.11.1, Made4Flow includes a native exporter that replicates flows in NetFlow V5, NetFlow V9, or sFlow to any external destination, without requiring any reconfiguration of the routers. What flow formats does the exporter support?NetFlow V5, NetFlow V9, and sFlow. How does the sampling rate alert work?Made4Flow monitors the sampling rate value reported by each router
Updates – Made4Flow, Made4Graph, and Made4OLT – March 2024
Made4Flow – Version 2.7.0 Additions: Router View: Interface Visualization: Prefix Preview: Horizontal Bar: Industry: Polar: Latest Figures: List of ASNs: List of Protocols: List of Applications: Map: Changes: Fixes: Haven’t heard of Made4Flow yet? Made4Graph – Version 2.4.4 Additions: Fixes: Haven’t heard of Made4Graph yet? Made4OLT – Version 1.3.1 [Beta] Additions: Changes: Fixes: Haven’t heard of Made4OLT yet?
Updates – Made4Flow, Made4Graph, and Made4OLT – February 2024
Made4Flow – Version 2.6.2 Changes: Fixes: Made4Graph – Version 2.4.3 Additions: Fixes: Made4OLT – Version 1.3.0 [Beta] Additions: 1 – Added the ability to restart a configured ONU. 2 – Added the maximum number of OLTs per license. 3 – Added options for manual saving and autosaving of OLTs. 4 – Added support for Telnet commands 5 – Added a Telnet terminal on the OLT Changes: 1 – Templates can accept Board, slot, and port as parameters. 2 – DBA profile selectable from 1 to 5. 3 – Fixed a bug: VLANs can only be created within the range of 1 to 4094. Fixes: 1 – Fixed a bug when submitting a new license.2 – Fixed a bug; the VLANs field now only accepts numbers.
Updates – Made4Flow, Made4Graph, and Made4OLT – January 2024
Made4Flow – Version 2.6.1 Additions Changes Corrections Made4Graph – Version 2.4.2 Additions Corrections Made4OLT – Version 1.2.2 [Beta] Additions Changes Corrections
What is FlowSpec? How to use FlowSpec to mitigate DDoS attacks?
Essentially, Flowspec is an extension of the BGP protocol that allows routers to apply rules—such as dynamic ACLs or dynamic firewall rules—to specific types of traffic. These rules can be based on a variety of criteria, including source, destination, protocol, port, and so on.
Updates – Made4Flow, Made4Graph, and Made4OLT – January 2024
Made4Flow – Version 2.6.0 Additions: -Added the option to manually announce FlowSpec. -Added a feature to send BGP FlowSpec announcements in Anti-DDoS. -Added repeat execution or extension of the alert for attacks involving existing anomalies. -Added the ability to control the time unit for Anti-DDoS actions. -Added the ability to view the announced flowspec. -Added a `select` clause with the IP addresses of the local VM’s interfaces. -Added real-time IPv6 traffic visualization to the main dashboard. -Added the ability to configure a prefix length for IPv6 actions.-Added new validations for cases where two collectors are registered in the tool.-Added the option to select the local interface for binding the IP addresses of BGP sessions. Changes: -Updated to prevent the addition of a new router with the same history data.-The NetFlow collection check for the router has been modified; it now takes place within the collector. Fixes: -Fixed the display of real-time traffic from routers on separate Made4Flow collectors.-Fixed the log flood in BGP announcements in specific scenarios. Made4Graph – Version 2.4.1 Changes: -We have made significant improvements to the performance of the worker responsible for the tasks of TR-069. Now, in the event of task failures, we have implemented an optimized process for removing those tasks from the corresponding CPE. This optimization aims to prevent a substantial increase in server usage, which previously could cause slowdowns. Fixes: -We identified and fixed an issue that could have led to increased server resource consumption as a result of queries made to the TR-069. This fix is intended to optimize server performance, ensuring more stable and efficient operation during queries to TR-069. Made4OLT – Version 1.1.4 [Beta] Additions: 1 – ZTE-C600 (Firmware 1.2.2) approved for viewing and provisioning.2 – Soft delete implemented on TYPE ONUs.3 – Implemented SNMP commands to collect data from ONUs.4 – Added separate queues in Bull to capture different types of data, respecting the request times for each OLT.5 – Added an image to the ONUs Changes: 1 – The UN details screen has been updated 2 – Database optimization by creating indexes for the tables.3 – Changed the business rule for ONUS when no signal is received from it, making it the same as smartOLT4 – Ability to load Slots/Pons/Ports individually via SNMP Fixes: 1 – The focus of this sprint was to correct the values and statuses of the ONUs in production
How to Configure NetFlow on Nokia Routers
Hello Today we’ll show you how to configure your Nokia SR OS router to export NetFlow (IP Netstream). Here we have the Network topology and the Netflow Server information These are the steps required to configure the Nokia SR OS router to export NetFlow v9/v10 via IP Netstream 1 – Configure the NTP server2 – Configure the cflowd parameters with the NetFlow server3 – Configure the interface to enable NetFlow Let’s go through the setup step by step: 1.Configuring the NTP Server It is important to configure an NTP server because flow data uses timestamps based on the router’s time. If the router’s time differs from that of the server, the data will not be time-stamped correctly, resulting in a discrepancy in the information. It is important that you configure at least 2 NTP servers and also your router’s timezone. 2 – Configure the cflowd parameters with the NetFlow server 3- Configure the interface to enable NetFlow Finally, we need to enable NetFlow on the interfaces that will export it. To do this, use the following commands on each interface: Below is the complete configuration of the Router: And enable the following on all interfaces: Detailed description Some additional commands for flow analysis:
The Importance of Made4Flow’s New AntiDDoS Decoders
In recent months, our technical team has seen an alarming increase in DDoS attacks of the Carpet bombing type, characterized by intense traffic spikes generally directed at all IP addresses belonging to the ASN. These attacks have negatively impacted network connectivity, presenting an additional challenge in evading detection by many conventional DDoS security systems. Unlike traditional attacks, which focus on a single IP address, these latest attacks show greater sophistication. They send smaller volumes of traffic distributed among several IP addresses, making identifying patterns and distinguishing between legitimate traffic and DDoS attacks a much more complex task. In response to these evolving cybercriminal tactics, the AntiDDoS development team at Made4Flow has taken proactive measures. We recently implemented a series of new decoders to strengthen our detection system. This improvement aims to enhance the accuracy and reliability of our anomaly detection and analysis tool, significantly improving our ability to identify and neutralize more sophisticated DDoS attacks, by taking automated actions that were previously configured in our tool—such as BGP prefix announcements for mitigation or Clean Pipe (scrubbing center) links — in addition to generating reports on the identified attack. In this article, we’ll explore the details of these new Decoders, developed on the basis of extensive Made4Flow analysis and packet captures. These implementations aim to improve the resilience of AntiDDoS, providing a more efficient defense against the complexities of contemporary DDoS attacks. New Decoders from AntiDDoS Made4Flow: • Port 0: Enables the identification of DDoS attacks that use port ZERO in the UDP protocol within an IP packet, whether as the source or destination, since this tactic is frequently used in DDoS amplification attacks.• DNS: A common feature of DDoS attacks is the receipt of packets from DNS servers or hosts responding to DNS requests. These attacks are known as DNS amplification and involve zombie machines (infected machines), servers or assets responding to DNS requests, and the target.• NTP: Another widely used tactic involves attacks using NTP servers. Like DNS-based attacks, these are known as NTP Amplification, exploiting servers or hosts that respond to NTP requests to direct the attack toward its target. Although it is common for devices connected to the network to make NTP queries to keep the date and time up to date, it is possible to improve the detection of DDoS attacks by setting a standard traffic threshold using a decoder.• SSDP: The Simple Service Discovery Protocol (SSDP) can be exploited to send large volumes of packets to the target, abusing device discovery services to amplify the attack and disrupt the target’s connectivity.• IP Fragmentation: Packet fragmentation can occur when a device is unable to send all the necessary information in a single packet. The main issue is that firewall blocks may not be as effective, and large DNS response packets may use fragmented packets. An excess of these packets can impact the network and consume excessive resources from network devices; with this decoder, we can set a threshold and make detection more accurate.• TCP SYN: This decoder plays a key role in detecting attacks known as SYN floods, which involve consuming the resources of servers or device services, rendering them unavailable for use. By setting the correct threshold, we can implement effective preventive measures, preventing this type of attack from occurring and taking actions that result in immediate mitigation.• LDAP: The LDAP decoder plays an important role in identifying DDoS attacks that exploit servers with active LDAP to perform reflections, thereby amplifying malicious traffic.• Chargen: Although it is an older protocol, it is used in some line printers and can be exploited by attackers. Setting a limit for this type of traffic is also important.• TCP and UDP High Ports: In addition to the protocols mentioned above, we have observed in several DDoS attack reports the use of high ports—above port 1024—with the TCP and UDP transport protocols. Therefore, it is important to set limits for these two protocols, making the detection of attacks that use high ports more effective. The addition of new decoders makes DDoS attack detection more efficient by supporting a variety of protocols, protecting against different types of DDoS attacks, minimizing false positives, and enabling more accurate identification of real threats.
Updates – Made4Flow, Made4Graph, and Made4OLT – Dec. 14
Made4Flow – Version 2.5.0 Additions Made4Graph – Version 2.4.0 Additions API *Note: For these functions to work properly, the CPE must be properly certified. Documentation: https://demo.made4graph.com.br/api/v1/doc/ Installation Wizard Class-Action Lawsuits Daily: Weekly: Monthly: Note: In the image, we can see that the option mentioned earlier has been disabled. Therefore, where there were originally 2 CPEs in the main task, upon rescheduling, the system identified two additional CPEs that matched the selected filter. Corrections: Made4OLT – Version 1.1.3 [Beta] Additions Firmware 1.12 [Furukawa 3008]. Firmware 2.18 [Furukawa 3032]. MA5800V100R018C00 Firmware [Huawei MA5800-X17]. MA5800V100R017C10 Firmware [Huawei MA5800-X17]. MA5800V100R018C00 Firmware [Huawei MA5800-X15]. MA5800V100R018C10 Firmware [Huawei MA5800-X15]. MA5800V100R021C01 Firmware [Huawei MA5800-X7]. MA5800V100R018C00 Firmware [Huawei MA5800-X7]. MA5800V600R015C00 Firmware [Huawei MA5683T]. MA5800V600R018C00 Firmware [Huawei MA5683T]. MA5600V800R018C10 Firmware [Huawei MA5603T]. MA5800V600R015C00 Firmware [Huawei MA5600T]. Firmware 8.4.0 [Datacom 4615]. Firmware 6.6.0 [Datacom 4615]. Firmware 1.2.2 [ZTE C610]. ZTE (C650, C610, C350, C320, C300). Huawei. Datacom. Changes Corrections
Updates – Made4Graph, Made4Flow, and Made4OLT – September 14
Made4Flow – Version 2.4.0 Additions A new configuration wizard has been added for the Anti-DDoS module. Added new dashboards and charts for new CDNs (Globo, Azion, Cloudflare, and CDN.TV) Added the option to add images to dashboard charts. Added the ability to pre-register communities for use in BGP announcements. Made4Graph – Version 2.3.10 Added The software installation wizard has been launched. Images have been implemented in the hub registry in accordance with the manufacturer’s specifications. This feature has been implemented in the API, where it is now possible to retrieve or update CPE information using either the WAN MAC address or the LAN MAC address. The option to register the database and the NAS using the installation wizard has been implemented. The option to authenticate the API using “Basic” has been implemented. Support for capturing LibreSpeed speed tests via the IXC API has been implemented. Corrected Fixed an issue on the TR-069 dashboard where, in the manufacturers chart, the totals might not add up correctly due to differences in names. Fixed an issue where, even without TR-069 permission, the reports menu would appear in some cases. Fixed an issue where WAN information was sometimes not displayed correctly in certain cases. Made4OLT – Version 1.0.3 – Beta Added Added the ability to sort items by name, number, door, sign, etc. Added the ability to filter by Onus on the main dashboard by selecting the OLT to display only information specific to that OLT. Added a feature that displays the total for each corresponding item on your screen. Added new HUAWEI MA5608T certification commands Added new certification commands for the ZTE C650 and C300 Added new FURUKAWA 3008 and 3032 type approval commands Added a specific PON reset feature. Changes Changed the structure of the Dashboard code, resulting in a functional component with improved response time. Corrections Fixed a bug related to storing the company name in the database.