Continuous improvement, delivered with one command
Every update ships through the same update.sh, with rollback. See what just landed on your installation and what we are building right now.
# download the stable package cd /opt curl -fLO https://www.edgewarden.com.br/download/flowspec-analyzer-stable.tar.gz # apply it: keeps configuration, environment and logs /opt/flowspec-analyzer/scripts/update.sh /opt/flowspec-analyzer-stable.tar.gz
- Checks package integrity before installing
- Applies schema and catalogs, then runs a health check at the end
- Historical data stays intact and downtime is usually under 1 minute
To go back to the previous version: update.sh --rollback. Full walkthrough in the installation guide.
Recently shipped
Everything on this timeline is already in version 1.81.0, released on October 3, 2026. With an active license you get it through the update command above, no reinstall needed.
-
Earlier versions
Three updates before this one, all applied with the same
update.sh.- 1.4.1
- 1.6.0
- 1.10.4
-
A license that survives bonds, LACP and VLAN changes
Hardware ID v2 is built from the machine-id, the factory MACs of the physical NICs and the CPU. Building a bond, changing LACP or adding a new VLAN no longer changes the machine ID, so the license stays valid.
-
External scrubbing through API v1 too
Manually sending a prefix to your contracted mitigation provider can now be done through the API, with the same safeguards as the UI.
- Provider enabled and its BGP session up
- Correct address family: never an IPv4 prefix length on an IPv6 target
- Minimum prefix length and an anti-hijack check on the announced block
-
Expanded XDP data plane
The filter that runs in the NIC driver gained new heuristics. Each one can run in observe mode, counting without dropping, until you trust the results.
- SYN flood protection by retransmission: drops the first SYN and lets through clients that retransmit, without turning the scrubber into a reflector the way SYN cookies would.
- UDP payload signatures: up to 1,024, 4 or 8 bytes plus port, with a per-signature counter.
- IPv6 victims and protocol + port filtering, on both IPv4 and IPv6.
- Per-destination rate limit with counters: up to 16,384 victims, tunable per Managed Object.
- IPv6 carpet bombing by prefix, with LPM trie lookup of the targeted block, as IPv4 already had.
-
Core modules configured from the UI
Engine modules are now tuned on screen, with secret fields masked. What you save in the UI overrides
config.tomland takes effect in about a minute, without restarting the service. -
Route Optimizer with per-link next-hop
Each transit or IX link can have its next-hop picked automatically or pinned by you. Announcements carry a TTL and expire on their own, go out with NO_EXPORT or NO_ADVERTISE when needed, and an invalid next-hop is rejected before it reaches the router.
-
More transparent Traffic Steering
Before moving traffic, steering shows its suggestions and explains the reason behind each decision in plain language. You can block destinations manually and see in detail why a change was discarded.
-
v1.81.0 · current version
Signal-driven inbound traffic engineering
To balance download across upstreams, EdgeWarden prepends or withdraws the announcement toward the source provider, triggered by a BGP signal. When you need fine-grained control, you make a manual announcement aimed at a specific provider.
Coming soon
What we are building right now. The list is not in priority order and no item has a committed date: once a feature ships, it moves from here to the timeline above.
-
Detection
Machine Learning detection Coming soon
Models that learn each customer's normal behavior and flag anomalies no fixed threshold catches, with fewer false positives and earlier alerts. Today detection uses thresholds, time-of-day baselines and statistical anomaly detection.
-
Scrubbing center
Multi-router scrubbing center Coming soon
A single scrubbing node connected directly to several edge routers, with its own next-hop per router and a health check on every path. Today the scrubber serves one dirty/clean port pair.
-
Packet capture
High-throughput capture with AF_XDP and DPDK Coming soon
New Packet Sensor capture engines for very high-throughput links. Today the Packet Sensor captures with libpcap and AF_PACKET v3.
-
Supported edges
Certified Huawei edge (NE40E/NE8000) Coming soon
Scrubbing center for Huawei VRP8 edges with a lab-validated anti-loop template, IPv6 included. The current template exists but has not yet been validated on hardware.
-
Mitigation
Capacity ceiling for IPv6 and per-customer diversions Coming soon
The automatic cap at 80% of scrubber capacity will also apply to IPv6 diversions and to per-customer policies (Managed Objects). Today it already covers IPv4 diversions, and a manual diversion that does not fit the scrubber is refused.
-
Mitigation
Non-divertible zones Coming soon
The system recognizes targets with their own route, such as PPPoE, connected /30s and anycast, and automatically picks FlowSpec instead of diverting to the scrubber.
-
Route quality
Bidirectional (TWAMP) and per-PIX quality Coming soon
Latency, loss and jitter measured separately for each direction, plus a comparison across the interconnection points (PIX) of the same IX. Probing per transit and IX link already works today.
-
XDP data plane
802.1Q VLAN in XDP and XDP mode diagnostics Coming soon
Inspection on trunk ports too, and the filter's execution mode (native or generic) shown in the health check, so you know whether the NIC is dropping in the driver.
Is there a feature that would make a difference on your network?
Tell us the problem you want to solve, your edge equipment and the traffic volume involved. Requests from people who run networks every day carry weight in deciding what goes on the roadmap.