Made4Flow 2.11.1: NetFlow export for DDoS mitigation, new alerts, and much more

Check out what’s new in Made4Flow 2.11.1: export NetFlow V5, V9, and sFlow to DDoS mitigation platforms, configure alerts by router, and integrate with external systems via REST API. Anyone who operates a medium- or large-scale network knows that traffic visibility isn’t a competitive advantage—it’s a matter of survival. Identifying an ongoing DDoS attack, determining which country the anomalous traffic is coming from, or integrating the NetFlow analyzer with the carrier’s mitigation platform without having to reconfigure routers: these are real day-to-day challenges for NOC and security teams. Version 2.11.1 of Made4Flow, available starting February 27, 2026, addresses precisely these needs. In this article, we detail each new feature and what it accomplishes in practice. What is Made4Flow, and who is this update for? Made4Flow is a NetFlow and sFlow analyzer developed by Made4it for internet service providers, telecom operators, and NOC teams that need detailed visibility into network traffic. It collects flows exported by routers (NetFlow V5, V9, sFlow, IPFIX), applies intelligence to this data, and delivers real-time graphs, alerts, and analytics. This update is particularly relevant for those who: How to Export NetFlow to a DDoS Mitigation Platform — Without Configuring the Routers This is the most eagerly awaited new feature in version 2.11.1 for teams that operate DDoS mitigation platforms. The previous scenario was as follows: to send flows to a third-party mitigation solution, you had to configure the router to export simultaneously to two destinations—the Made4Flow collector and the mitigation platform’s collector. In many environments, this is not simple, is risky, or is simply unfeasible. With Made4Flow’s new flow replicator, the router continues to export flows to Made4Flow as usual. From there, the platform itself replicates and forwards the flows to any external destination in the following formats: Configuration is performed directly through the Made4Flow interface—no downtime, no maintenance window on the routers, and no operational risk. For service providers using solutions such as Wanguard, NSFOCUS, Arbor, or any other platform that uses NetFlow or sFlow, this feature eliminates a complex dependency and speeds up integration. Integrate your DDoS mitigation platform with Made4Flow and replicate NetFlow V5, V9, IPFIX, or sFlow with just one configuration. Threat Analysis: New Visualization to Identify Internal Attacks The Made4Flow Threat Analysis page has been completely redesigned in version 2.11.1. The new layout consolidates the key security metrics on a single screen: total detected threats, suspicious IP addresses, volume of malicious traffic, temporal distribution of incidents, and the main targets. The geographic view of threats has also been enhanced, making it easier to correlate the attack’s origin with its impact on the network. For security teams that need to respond quickly to incidents, this means fewer clicks and more context available at the critical moment. Find out who is launching attacks within your internal network with just ONE CLICK. Sampling Rate and Router Alerts: Stop Analyzing Distorted Data One of the most subtle issues in NetFlow monitoring is sampling rate incompatibility. When the value configured in the analysis tool differs from the one the router is actually using, all traffic graphs become distorted—and the team may make decisions based on incorrect data without realizing it. Version 2.11.1 adds two types of alerts specific to this scenario: Sampling Rate Incompatibility Alert It automatically notifies you when the sampling value configured in Made4Flow differs from what the router is reporting. This is especially useful in environments with multiple routers from different manufacturers (Cisco, Huawei, MikroTik, Juniper), where the sampling pattern may vary. Explicit alerts by router Each router registered in Made4Flow can now have its own active alerts, which are visible directly in the device list and on the edit page. This simplifies management in environments with dozens or hundreds of monitored routers. Get notified before the problem affects your data—set it up in minutes. Traffic by Country and App by Prefix: Real-Time Geographic Visibility For internet service providers and telecom operators, knowing where traffic comes from is just as important as knowing how much traffic there is. A spike originating from a particular country may indicate a volumetric attack in progress; a specific prefix consuming an unusually high amount of bandwidth may signal that a customer’s system has been compromised. Version 2.11.1 adds a new overview screen with traffic charts broken down by: This visibility was available in the raw data, but now it is presented in a native visual format, eliminating the need to export data, cross-reference spreadsheets, or use external tools. See in seconds which country or prefix is generating unusual traffic—and take action before the attack escalates. Aggregation by TCP Flags and Countries: Accurately Detect DDoS Attack Patterns Modern DDoS attacks often masquerade as seemingly normal traffic. Analyzing TCP flags—such as SYN, ACK, or RST floods—is one of the most effective ways to identify malicious traffic before it impacts services. Version 2.11.1 adds new aggregation tabs to the Made4Flow raw data: For security teams investigating incidents, the combination of analysis based on flags and geographic origin is particularly powerful for correlating attack techniques with their source. Identify attacks based on TCP flag patterns and geographic origin in seconds, without external tools. Made4Flow REST API: Integrate with Any System Version 2.11.1 marks the arrival of Made4Flow’s official REST API, opening up the platform for programmatic integrations with other systems. The API offers: In practice, this enables integrations with Zabbix, Grafana, ticketing systems, SIEM, external dashboards, and any system that retrieves data via HTTP. Connect Made4Flow to your ecosystem and automate network data using your own stack. Other improvements in version 2.11.1 Fixes in Version 2.11.1 Frequently Asked Questions About Made4Flow 2.11.1 Can Made4Flow export NetFlow data to my DDoS mitigation platform?Yes. Starting with version 2.11.1, Made4Flow includes a native exporter that replicates flows in NetFlow V5, NetFlow V9, or sFlow to any external destination, without requiring any reconfiguration of the routers. What flow formats does the exporter support?NetFlow V5, NetFlow V9, and sFlow. How does the sampling rate alert work?Made4Flow monitors the sampling rate value reported by each router

How Pontonet got out of server chaos and reduced costs with Proxmox

Find out how Made4it transformed a total failure scenario into a modern, resilient and cheaper infrastructure. 16/09/2025 – By Made4it The scene is familiar to any IT manager: end of the month, bills to be issued, system running… until everything crashes. This is exactly what happened to Pontonet, when a simultaneous failure in a physical server put the entire business at risk. Stop and think: if all your disks crashed today, how much would it cost to recover a whole year’s worth of information? That’s when Made4it stepped in to turn disaster into opportunity. The problem: simultaneous failure and no backup This is the kind of risk that many companies ignore until it’s too late. Solutions on the table: keep VMware or migrate? Faced with the disaster, we evaluated two alternatives: Continue to VMware Migrate to Proxmox Why Proxmox? Proxmox is more than a free alternative. It offers: When compared to VMware, Proxmox has proven to be more agile, economical and secure. Made4it’s role in this turnaround Pontonet was already a client of Made4it’s networks and servers. When the failure occurred, we took the following actions: This process demonstrated our technical mastery and ability to turn crises into opportunities for innovation. Results: safety and savings After the migration: Proxmox and Made4it: the winning combination This story shows that technology and strategy go hand in hand. There’s no point in investing in expensive licenses if the project doesn’t include redundancy and backup; likewise, an open source solution requires expertise to be applied safely. Made4it delivers both: in-depth knowledge and affordable solutions. Do you know someone who still relies on an old server with no backup? Send them this article! And if you don’t want to be shocked to discover that your company is vulnerable, talk to our experts.

Why Have Your Own Server with Your Internet Service Provider?

These days, IT infrastructure is the foundation of any business, especially when it comes to Internet service providers (ISPs) and corporate customers.The ability to deliver reliable, high-performance services depends significantly on the choice between using in-house servers or relying on third-party services.In this article, we’ll explore the reasons why having an in-house server is a strategic and advantageous choice for ISPs and corporate businesses. 1 – Full control of the infrastructure: By owning your own servers, you gain full control over the infrastructure. This means you can tailor server resources to your organization’s specific needs.From processing to data storage, you decide how the infrastructure is configured and managed.This results in greater flexibility to meet the ever-changing demands of the market. 2 – Security customization: Security is a key concern in any IT operation. Having your own server allows you to customize security measures according to your specific standards and requirements.You can implement firewalls, intrusion detection systems, encryption, and other layers of security as needed, ensuring data protection and customer privacy. 3 – Optimized performance and latency: Performance is crucial for ISPs and corporate enterprises that need to serve a large number of customers or employees.On-premises servers offer the ability to tailor hardware and network configurations to optimize performance and reduce latency. This results in faster, more reliable services, which can be key to gaining and maintaining customer satisfaction. 4 – On-demand scalability: Scalability is vital for handling spikes in demand or future expansion. With your own servers, you have direct control over how and when to scale your resources according to your needs.This means you aren’t bound by third-party limitations and can grow as your organization requires. 5 – Long-term cost reduction: While the initial investment in your own servers may seem significant, in the long run, this usually results in cost savings.You eliminate the recurring expenses associated with using third-party services and achieve a faster return on investment.In addition, you can plan hardware maintenance and upgrades according to your own schedule, avoiding unexpected costs. 6 – Compliance and privacy: Many organizations, especially those that handle sensitive data, must comply with specific privacy and security regulations.Having your own servers provides greater control over compliance with these regulations, ensuring that customer data is protected and that the organization complies with applicable laws. 7 – Customized support and maintenance: When you have your own servers, you can establish customized support and maintenance policies. This means you can respond quickly to technical issues and ensure minimal downtime.In addition, you’re in charge of ensuring that the servers are always up to date, in top working condition, and have backup routines set up, for example. In short, choosing to host your own servers offers unprecedented control over your IT infrastructure. This not only allows for greater flexibility and customization, but can also result in long-term savings and significant improvements in performance and security.For ISPs and corporate companies seeking excellence in IT services, having your own server is a strategic and advantageous choice! Do you need to address any of the topics above, or don’t have your own server yet? Count on us to work with you to validate each necessary step and set up a resilient server infrastructure for your company! Contact Us

The importance of a provider having its own DNS

A provider always seeks to provide the best quality internet for its customers, and a very important factor for us to be able to browse the internet is to have a recursive DNS server configured, the reason for this and how it works we already understand, but how to have a server within your network will improve navigation for your customers even more?

Creating VPN using PFSense and OpenVPN

Basically, VPN stands for Virtual Private Network, and it serves as a tunnel between two connection points. When you set up a VPN between a computer at your home and a PFsense at your company, for example, the tunnel created allows your computer to act as if it were “inside” your company’s local network, granting access to servers and equipment, provided that the PFsense is reachable from your home computer. Now that we understand what VPN is all about, let’s learn how to set it up using PFSense to establish the connection between your different networks. Configuring the VPN We’ll use PFSense’s built-in “Wizard” for this configuration. To do this, go to the VPN > OpenVPN. Then, click the Wizardstab: So, that’s it, folks. This was our guide to setting up OpenVPN using pfSense and configuring a connection to it using the OpenVPN Client, with the files provided by pfSense itself.If you need help or support with pfSense maintenance, please contact us —we’re here to help!Thanks, and see you next time!

Installation of PFSense as your network’s Gateway.

512px PfSense logo

At the end of the Wizard, we have our PFSense ready to use! In upcoming posts. We will teach you how to create a VPN using PFSense, so you can access your Internal Network from your home. Thank you and see you in the next posts. Adriano Elias de SouzaIT ConsultantMade4it

Made4it arises to meet the needs of the market, which has been demanding more and more personalized solutions.