The Detection Window — What FastNetMon's Own Docs Say

FastNetMon Community Edition is NetFlow/sFlow-based. FastNetMon's own configuration documentation recommends setting active and inactive flow timeouts on your router to 30 seconds as a safe default for NetFlow/IPFIX operation.[1] That timeout is the minimum delay before a flow is exported and analyzed. In practice, detection latency from NetFlow runs 10 to 30 seconds depending on router configuration, sampling rate, and traffic volume.

FastNetMon's own blog acknowledged this explicitly in a February 2024 comparison post: detection time is "thirty seconds when working with Netflow 5/9 and IPFIX," versus two seconds in sFlow or SPAN/mirror mode.[2]

That 30-second window is the time during which an attack is hitting your servers before the detection layer has information about it. Short-burst attacks that complete in under 30 seconds may end before flow-based detection fires. This is a characteristic of all flow-based detection tools, not specific to FastNetMon.

Detection latency is inherent to the flow-based architecture used by FastNetMon and other NetFlow/sFlow-based tools. Operators should consider how this detection window aligns with their threat profile, particularly if short-burst attacks are common in their environment.

No L7 Detection — FastNetMon's Own Limitation Statement

This is stated clearly in FastNetMon's own documentation: "FastNetMon's attack detection engine works only on L3 and L4 layers and does not have options to check content of packets."[5]

L7 attacks such as HTTP floods, DNS query floods, and HTTPS request floods are outside FastNetMon's detection scope. This is consistent with its design as a flow-based L3/L4 detection tool. For environments where application-layer attacks are a significant part of the threat model, additional detection at a different layer may be needed.

Community Edition — What's Not Included

No BGP FlowSpec — Community supports RTBH only. FlowSpec (surgical filtering while keeping destination IP reachable) is Advanced-only.

No REST API — Community offers a gRPC-based API for programmatic access, but the REST HTTP API is available in Advanced only.

No automatic mitigation — Community notifies via scripts. Custom scripting is required for BGP announcement logic.

No management UI — no dashboard, no centralized view.

These are trade-offs of the Community edition's scope. FastNetMon Advanced addresses several of these gaps with FlowSpec, REST API, and SMTP alerting.

The Upgrade Path — FastNetMon Advanced

FastNetMon Advanced (starting at $115/month) adds FlowSpec, REST API, commercial support, and a management UI. It closes several Community gaps. Detection remains NetFlow/sFlow-based, which means the same flow-export-dependent timing applies in NetFlow mode.

Side-by-Side Comparison

Feature FastNetMon Community FastNetMon Advanced Flowtriq
Detection source NetFlow/sFlow NetFlow/sFlow Per-packet
Detection speed 10-30 sec (NetFlow) 10-30 sec (NetFlow) Under 1 second
L7 detection No No Yes
BGP FlowSpec No Yes Yes
Auto-mitigation Script-based BGP blackhole, FlowSpec, scrubbing diversion Built in
PCAP forensics No 20-500 packet sample for FlowSpec rules Continuous pre-attack ring buffer
REST API No Yes Yes
Alerting Custom scripts Email, Slack, Telegram, webhook, Prometheus Discord, Slack, PagerDuty, OpsGenie, SMS, email, webhooks
Price Free $115+/month $9.99/node/month

5-Step Evaluation Checklist

  1. Characterize your attack profile — are attacks short-burst (under 60 seconds) or sustained?
  2. Assess your L7 exposure — if servers handle HTTP, DNS, or game protocols, is application-layer attack traffic in your threat model?
  3. Evaluate your mitigation script — did it fire in time during the last three incidents?
  4. Confirm FlowSpec requirements — if you need surgical traffic filtering, Community does not include FlowSpec (Advanced does).
  5. Model your BGP automation — consider how much of your mitigation workflow is automated vs. manual.

Looking for per-server detection?

Flowtriq uses per-server agents for sub-second detection, attack classification, and PCAP forensics. 14-day free trial.

Start free 14-day trial

Frequently Asked Questions

How long does FastNetMon take to detect a DDoS attack?

FastNetMon's own documentation states detection takes approximately two seconds with sFlow or SPAN/mirror mode, and thirty seconds with NetFlow/IPFIX. Most ISP and hosting deployments use NetFlow, placing detection latency in the 10-30 second range depending on router flow timeout configuration.

Does FastNetMon Community Edition support BGP FlowSpec?

No. FastNetMon Community Edition supports RTBH (blackholing the destination IP) only. BGP FlowSpec is available in FastNetMon Advanced only.

Does FastNetMon detect Layer 7 attacks?

No. FastNetMon's own documentation states its detection engine works only on L3 and L4 layers and does not have options to check content of packets. HTTP floods, DNS query floods, and application-layer attacks are outside FastNetMon's detection scope.

What is an alternative to FastNetMon for sub-second DDoS detection?

Operators who need sub-second detection, L7 visibility, PCAP forensics, and built-in auto-mitigation evaluate per-packet agent-based tools like Flowtriq, which deploy directly on Linux servers and detect attacks in under one second without relying on NetFlow export cycles.

Back to Blog

Related Articles