deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (native)

SATIS Shield brings ISP-style BGP blackholing to single-router networks for $59/month

A new service called SATIS Shield offers remotely triggered black hole routing over a private ASN and a WireGuard or GRE tunnel, with no transit contract, multihoming, or existing BGP peering required.

SATIS Shield brings ISP-style BGP blackholing to single-router networks for $59/month

A Show HN launch for ISP-grade filtering

A service called SATIS Shield has launched via a Show HN post on Hacker News, offering BGP-based remote-triggered black hole (RTBH) filtering to networks far too small to use the technique conventionally. According to the product page, this approach — announcing routes that cause upstream routers to discard traffic associated with hostile IP addresses — has traditionally required a transit contract and a network engineering team. Shield packages it as a $59-per-month subscription aimed at a single router.

The vendor says peering requests are approved automatically, with no manual review queue, so a new user can typically go from signup to an active BGP session in one sitting. A 14-day trial runs without a credit card on file; if no plan is added, the session is revoked rather than charged, with a countdown email before it lapses.

One router, one private ASN, one tunnel

The requirements are deliberately minimal. A customer needs any router that can speak BGP — the site lists generated configurations for Cisco IOS/IOS-XE, Juniper JunOS, OpenWrt, pfSense/OPNsense, VyOS, OpenBSD, and Linux running BIRD or FRR — plus a private ASN in the 64512–65534 range, which SATIS issues free of charge with no regional registry paperwork.

The router connects over a GRE or WireGuard tunnel to one of the company's points of presence in Los Angeles, Dallas, or Buffalo, and peers directly with SATIS's network, AS23026. The company emphasizes that this is infrastructure it operates itself for collecting and blackholing threats, not a SaaS layer reselling another provider's feed.

Crucially, no multihoming is required. The vendor explains that public ASNs and multiple transit providers matter only when announcing your own routes to the wider internet, not for receiving and acting on a blackhole feed. SATIS can even be a customer's first-ever BGP session, and the service works behind residential or small-business ISP connections: bridge mode on the ISP gateway is described as the cleanest setup, but the outbound-initiated tunnel also functions through double NAT.

A shared feed with a severity dial

Shield is not merely a way to push a personal blocklist. Attacks that other peers on the network have already observed are shared as BGP routes, so a threat one participant sees gets blocked for everyone in near real time. Each user sets a single severity threshold that determines which advertised IPs get dropped, and the same intelligence is available through an API capped at 2,000 requests per day.

What blackholing can and cannot stop

The FAQ is candid about the technique's scope. RTBH is effective against connection-completing attacks — brute-force attempts, exploit scanning, command-and-control callbacks — but it cannot absorb a volumetric flood such as a UDP or SYN flood or a reflection attack on its own. For those, the page says, reverse-path filtering (uRPF) must be enabled on the customer's own router; SATIS documents that configuration but does not set it up for you.

Why it matters

RTBH has been an ISP-grade capability for decades, gated behind transit relationships, letters of authorization, and engineering effort that homelabs and small offices rarely have. If the product works as advertised — and it is worth noting these claims come from the vendor's own launch page rather than independent testing — it converts an organizational barrier into a subscription, the same commoditization cloud platforms have already applied to load balancers and web application firewalls. The shared feed cuts both ways: one peer's early sighting of an attack protects everyone else, but a misjudged indicator would propagate just as quickly, which makes the severity threshold and the provider's editorial judgment the real product being bought.

  • #bgp
  • #networking
  • #security
  • #ddos-mitigation
  • #routing

Related posts