Describes how Cisco Secure DDoS Edge Protection identifies and mitigates distributed denial-of-service (DDoS) attacks at the network edge, enhancing overall security and minimizing impact on core bandwidth.
A Cisco Secure DDoS Edge Protection feature is a network security mechanism that
-
enables routers to respond immediately to DDoS threats at the network edge
-
allows malicious traffic to be identified and counteracted directly on the router, and
-
minimizes network and application impact without affecting core bandwidth by avoiding backhaul of malicious traffic.
A centralized controller manages DDoS mitigation using information from detectors deployed on routers. These detectors analyze IPv4 and IPv6 traffic in real time to identify DDoS attacks. Upon detection, the controller enforces deny ACLs to block malicious traffic while allowing legitimate traffic.
Feature history
This table provides the feature history for Cisco Secure DDoS Edge Protection:
| Feature name |
Release information |
Description |
|---|---|---|
| Cisco Secure DDoS Edge Protection |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100]) (select variants only*) *This feature is supported on:
|
| Cisco Secure DDoS Edge Protection |
Release 25.2.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: Q200, P100], 8700 [ASIC: P100, K100], 8010 [ASIC: A100]) (select variants only*); Centralized Systems (8600 [ASIC: Q200]); Modular Systems (8800 [LC ASIC: Q100, Q200, P100]) (select variants only*) You can now enable the router to detect DDoS attacks targeting MPLS traffic using DDoS edge protection. The router analyzes MPLS flows to identify malicious traffic patterns, ensuring the availability and performance of services traversing MPLS networks. |
| Cisco Secure DDoS Edge Protection |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100]) (select variants only*) *This feature is supported on:
|
| Cisco Secure DDoS Edge Protection |
Release 24.4.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100]) (select variants only*); Modular Systems (8800 [LC ASIC: P100]) (select variants only*) *This feature is now supported on:
|
| Cisco Secure DDoS Edge Protection |
Release 24.1.1 |
You can now efficiently block malicious traffic, safeguarding your network's performance and availability. Protection against DDoS attacks is implemented at the network edge, deployed at the ingress point where external network traffic enters. A centralized controller manages DDoS mitigation using information from detectors deployed on the routers. These detectors analyze IPv4 and IPv6 traffic in real time to identify DDoS attacks. Upon detection, the controller enforces deny ACLs to block malicious traffic while allowing legitimate traffic. |