SATIS Shield - BGP Blackholing for Single-Router Networks

Show HN: I created a BGP-based blackhole system that you can set up in minutes

SATIS Shield - BGP Blackholing for Single-Router Networks

SATIS Shield brings enterprise-grade DDoS protection to single-router networks. Using BGP blackholing (RTBH), it drops malicious traffic upstream before it reaches your network. No need for multihoming or an existing BGP feed—just a router that speaks BGP and a free private ASN. With a GRE or WireGuard tunnel to a SATIS PoP, you get real-time, shared threat intelligence from other peers. Setup takes minutes, no admin approval. $59/month after a 14-day free trial, no credit card required. Ideal for homelabs, small businesses, and enterprises.

Stop connection-based attacks before they hit your network. Large ISPs and enterprise networks block attacks the same way: dropping malicious traffic upstream, before it ever reaches you, not after.
  1. 112233

    Hopefully upstream peers will use RPKI properly. It would be sad if this actually worked.

  2. smw

    I guess the real question here is what happens if my service _does_ get attacked by a volumetric DDoS? Do you immediately stop advertising?

  3. RationPhantoms

    Your 4. is incorrect. Traffic does not get dropped upstream.

More from this day

2026-09-30