Made4Flow 2.11.1: NetFlow export for DDoS mitigation, new alerts, and much more

Check out what’s new in Made4Flow 2.11.1: export NetFlow V5, V9, and sFlow to DDoS mitigation platforms, configure alerts by router, and integrate with external systems via REST API. Anyone who operates a medium- or large-scale network knows that traffic visibility isn’t a competitive advantage—it’s a matter of survival. Identifying an ongoing DDoS attack, determining which country the anomalous traffic is coming from, or integrating the NetFlow analyzer with the carrier’s mitigation platform without having to reconfigure routers: these are real day-to-day challenges for NOC and security teams. Version 2.11.1 of Made4Flow, available starting February 27, 2026, addresses precisely these needs. In this article, we detail each new feature and what it accomplishes in practice. What is Made4Flow, and who is this update for? Made4Flow is a NetFlow and sFlow analyzer developed by Made4it for internet service providers, telecom operators, and NOC teams that need detailed visibility into network traffic. It collects flows exported by routers (NetFlow V5, V9, sFlow, IPFIX), applies intelligence to this data, and delivers real-time graphs, alerts, and analytics. This update is particularly relevant for those who: How to Export NetFlow to a DDoS Mitigation Platform — Without Configuring the Routers This is the most eagerly awaited new feature in version 2.11.1 for teams that operate DDoS mitigation platforms. The previous scenario was as follows: to send flows to a third-party mitigation solution, you had to configure the router to export simultaneously to two destinations—the Made4Flow collector and the mitigation platform’s collector. In many environments, this is not simple, is risky, or is simply unfeasible. With Made4Flow’s new flow replicator, the router continues to export flows to Made4Flow as usual. From there, the platform itself replicates and forwards the flows to any external destination in the following formats: Configuration is performed directly through the Made4Flow interface—no downtime, no maintenance window on the routers, and no operational risk. For service providers using solutions such as Wanguard, NSFOCUS, Arbor, or any other platform that uses NetFlow or sFlow, this feature eliminates a complex dependency and speeds up integration. Integrate your DDoS mitigation platform with Made4Flow and replicate NetFlow V5, V9, IPFIX, or sFlow with just one configuration. Threat Analysis: New Visualization to Identify Internal Attacks The Made4Flow Threat Analysis page has been completely redesigned in version 2.11.1. The new layout consolidates the key security metrics on a single screen: total detected threats, suspicious IP addresses, volume of malicious traffic, temporal distribution of incidents, and the main targets. The geographic view of threats has also been enhanced, making it easier to correlate the attack’s origin with its impact on the network. For security teams that need to respond quickly to incidents, this means fewer clicks and more context available at the critical moment. Find out who is launching attacks within your internal network with just ONE CLICK. Sampling Rate and Router Alerts: Stop Analyzing Distorted Data One of the most subtle issues in NetFlow monitoring is sampling rate incompatibility. When the value configured in the analysis tool differs from the one the router is actually using, all traffic graphs become distorted—and the team may make decisions based on incorrect data without realizing it. Version 2.11.1 adds two types of alerts specific to this scenario: Sampling Rate Incompatibility Alert It automatically notifies you when the sampling value configured in Made4Flow differs from what the router is reporting. This is especially useful in environments with multiple routers from different manufacturers (Cisco, Huawei, MikroTik, Juniper), where the sampling pattern may vary. Explicit alerts by router Each router registered in Made4Flow can now have its own active alerts, which are visible directly in the device list and on the edit page. This simplifies management in environments with dozens or hundreds of monitored routers. Get notified before the problem affects your data—set it up in minutes. Traffic by Country and App by Prefix: Real-Time Geographic Visibility For internet service providers and telecom operators, knowing where traffic comes from is just as important as knowing how much traffic there is. A spike originating from a particular country may indicate a volumetric attack in progress; a specific prefix consuming an unusually high amount of bandwidth may signal that a customer’s system has been compromised. Version 2.11.1 adds a new overview screen with traffic charts broken down by: This visibility was available in the raw data, but now it is presented in a native visual format, eliminating the need to export data, cross-reference spreadsheets, or use external tools. See in seconds which country or prefix is generating unusual traffic—and take action before the attack escalates. Aggregation by TCP Flags and Countries: Accurately Detect DDoS Attack Patterns Modern DDoS attacks often masquerade as seemingly normal traffic. Analyzing TCP flags—such as SYN, ACK, or RST floods—is one of the most effective ways to identify malicious traffic before it impacts services. Version 2.11.1 adds new aggregation tabs to the Made4Flow raw data: For security teams investigating incidents, the combination of analysis based on flags and geographic origin is particularly powerful for correlating attack techniques with their source. Identify attacks based on TCP flag patterns and geographic origin in seconds, without external tools. Made4Flow REST API: Integrate with Any System Version 2.11.1 marks the arrival of Made4Flow’s official REST API, opening up the platform for programmatic integrations with other systems. The API offers: In practice, this enables integrations with Zabbix, Grafana, ticketing systems, SIEM, external dashboards, and any system that retrieves data via HTTP. Connect Made4Flow to your ecosystem and automate network data using your own stack. Other improvements in version 2.11.1 Fixes in Version 2.11.1 Frequently Asked Questions About Made4Flow 2.11.1 Can Made4Flow export NetFlow data to my DDoS mitigation platform?Yes. Starting with version 2.11.1, Made4Flow includes a native exporter that replicates flows in NetFlow V5, NetFlow V9, or sFlow to any external destination, without requiring any reconfiguration of the routers. What flow formats does the exporter support?NetFlow V5, NetFlow V9, and sFlow. How does the sampling rate alert work?Made4Flow monitors the sampling rate value reported by each router

Where to use Ufispace

Ufispace Equipment: Uses and Services Supported Introduction Ufispace is a company in the field of networks and telecommunications, specializing in providing high-quality network infrastructure solutions. Its equipment is designed to meet the growing demands for connectivity, capacity and performance in various sectors. In this article, we’ll explore the S9600-72XC, S9600-56DX and S9510-28DC devices, where they can be used and what services they support. Ufispace equipment S9600-72XC – Features 8 40/100G ports, 64 1/10/25G ports, 2 10G ports (MGMT, optical), and 1 100/1000M port (MGMT, electrical); Intel Skylake-D 8-core processor @ 1.9GHz, 32GB DDR4 memory, 128GB SSD storage, switching capacity of 2.4Tbps, and 4GB deep buffer. S9600-56DX – Features 8 40/100/400G ports, 48 40/100G ports, 4 1/10/25G ports, and 1 100/1000M port (MGMT, Power); Intel Icelake-D 8-core processor @ 2.1GHz, 32GB DDR4 memory, 128GB SSD storage, switching capacity of 4.8Tbps, and 8GB deep buffer. S9510-28DC – Features 2 100/400G ports, 2 40/100G ports, 24 10/25G ports, and 1 100/1000M port (MGMT, Power); Intel Denverton-NS 4-core processor @ 1.6GHz (Standard) / Intel Denverton-NS 8-core processor @ 1.7GHz (Premium), 8GB DDR4 memory (Standard) / 16GB DDR4 (Premium), 32GB SSD storage (Standard) / 128GB SSD (Premium), and switching capacity of 800Gbps with a 2GB deep buffer. Use of Ufispace Equipment Due to its high port density and switching capacity. As a Data Center Core or Server Aggregator. They can be used in Core topology scenarios, Aggregation, working as BGP, MPLS, as P and PE. In L2VPN, L3VPN, 6PE scenarios. Conclusion Ufispace switches are a great choice in data centers for critical functions such as server core and aggregation due to their high port density and switching capacity. For ISPs, they offer the robustness and flexibility needed for complex topologies, supporting protocols such as BGP and MPLS, as well as services such as L2VPN and L3VPN. Equipped with state-of-the-art processors, abundant memory and efficient storage, these switches guarantee superior performance and high capacity, making them ideal for building modern and efficient network infrastructures.

Why Have Your Own Server with Your Internet Service Provider?

These days, IT infrastructure is the foundation of any business, especially when it comes to Internet service providers (ISPs) and corporate customers.The ability to deliver reliable, high-performance services depends significantly on the choice between using in-house servers or relying on third-party services.In this article, we’ll explore the reasons why having an in-house server is a strategic and advantageous choice for ISPs and corporate businesses. 1 – Full control of the infrastructure: By owning your own servers, you gain full control over the infrastructure. This means you can tailor server resources to your organization’s specific needs.From processing to data storage, you decide how the infrastructure is configured and managed.This results in greater flexibility to meet the ever-changing demands of the market. 2 – Security customization: Security is a key concern in any IT operation. Having your own server allows you to customize security measures according to your specific standards and requirements.You can implement firewalls, intrusion detection systems, encryption, and other layers of security as needed, ensuring data protection and customer privacy. 3 – Optimized performance and latency: Performance is crucial for ISPs and corporate enterprises that need to serve a large number of customers or employees.On-premises servers offer the ability to tailor hardware and network configurations to optimize performance and reduce latency. This results in faster, more reliable services, which can be key to gaining and maintaining customer satisfaction. 4 – On-demand scalability: Scalability is vital for handling spikes in demand or future expansion. With your own servers, you have direct control over how and when to scale your resources according to your needs.This means you aren’t bound by third-party limitations and can grow as your organization requires. 5 – Long-term cost reduction: While the initial investment in your own servers may seem significant, in the long run, this usually results in cost savings.You eliminate the recurring expenses associated with using third-party services and achieve a faster return on investment.In addition, you can plan hardware maintenance and upgrades according to your own schedule, avoiding unexpected costs. 6 – Compliance and privacy: Many organizations, especially those that handle sensitive data, must comply with specific privacy and security regulations.Having your own servers provides greater control over compliance with these regulations, ensuring that customer data is protected and that the organization complies with applicable laws. 7 – Customized support and maintenance: When you have your own servers, you can establish customized support and maintenance policies. This means you can respond quickly to technical issues and ensure minimal downtime.In addition, you’re in charge of ensuring that the servers are always up to date, in top working condition, and have backup routines set up, for example. In short, choosing to host your own servers offers unprecedented control over your IT infrastructure. This not only allows for greater flexibility and customization, but can also result in long-term savings and significant improvements in performance and security.For ISPs and corporate companies seeking excellence in IT services, having your own server is a strategic and advantageous choice! Do you need to address any of the topics above, or don’t have your own server yet? Count on us to work with you to validate each necessary step and set up a resilient server infrastructure for your company! Contact Us

Creating VPN using PFSense and OpenVPN

Basically, VPN stands for Virtual Private Network, and it serves as a tunnel between two connection points. When you set up a VPN between a computer at your home and a PFsense at your company, for example, the tunnel created allows your computer to act as if it were “inside” your company’s local network, granting access to servers and equipment, provided that the PFsense is reachable from your home computer. Now that we understand what VPN is all about, let’s learn how to set it up using PFSense to establish the connection between your different networks. Configuring the VPN We’ll use PFSense’s built-in “Wizard” for this configuration. To do this, go to the VPN > OpenVPN. Then, click the Wizardstab: So, that’s it, folks. This was our guide to setting up OpenVPN using pfSense and configuring a connection to it using the OpenVPN Client, with the files provided by pfSense itself.If you need help or support with pfSense maintenance, please contact us —we’re here to help!Thanks, and see you next time!

Installation of PFSense as your network’s Gateway.

512px PfSense logo

At the end of the Wizard, we have our PFSense ready to use! In upcoming posts. We will teach you how to create a VPN using PFSense, so you can access your Internal Network from your home. Thank you and see you in the next posts. Adriano Elias de SouzaIT ConsultantMade4it

Made4it arises to meet the needs of the market, which has been demanding more and more personalized solutions.