Try our new research platform with insights from 80,000+ expert users
Security Consultant at a tech services company with 10,001+ employees
Real User
We're able to develop threshold values for clients' servers to help flag suspicious traffic
Pros and Cons
  • "There are a number of valuable features in this product, like Cloud Signaling and Threat Intelligence feeds."
  • "Sometimes it blocks legitimate traffic. If a legitimate user is trying to access the server continuously, the product suspects that this is a DoS traffic file. That is a case where it needs to improve. It needs machine-learning."

What is our primary use case?

Our primary use case is developing threshold values for all groups. We use it to analyze packets to build a use-case for when a server group hits the limit of incoming traffic. In such a case we suspect traffic.

We use it to build use-case scenarios, based on the server input and a client's requirements. Some clients have a number of users accessing a given server which affects the bandwidth. In each case, we need to tell DDoS what is considered legitimate traffic.

How has it helped my organization?

It prevents all unwanted or malicious traffic, using the Threat Intelligence feeds.

What is most valuable?

There are a number of valuable features in this product, like Cloud Signaling and Threat Intelligence feeds.

There are two modes in the product: The first is a learning mode and the other is a production mode. First, we learn the traffic using the learning mode. We use it to fine-tune what is suspicious data and what is legitimate traffic.

What needs improvement?

Sometimes it blocks legitimate traffic. If a legitimate user is trying to access the server continuously, the product suspects that this is a DoS traffic file. That is a case where it needs to improve. It needs machine-learning. Self-learning would be an improvement.

Buyer's Guide
Arbor DDoS
April 2025
Learn what your peers think about Arbor DDoS. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
849,963 professionals have used our research since 2012.

For how long have I used the solution?

One to three years.

What do I think about the stability of the solution?

The stability of Arbor DDoS is good. It's not that complex as a product and stability is not an issue.

What do I think about the scalability of the solution?

The scalability is good. Configuration-wise, an administrator could create issues. But the product itself is good.

I have implemented it multiple times in industries like oil and gas, banking, and insurance.

How are customer service and support?

The response from Arbor's technical support is good. They respond within two days.

How was the initial setup?

The initial setup is straightforward. It's very simple. I have deployed the product for multiple clients. Implementation takes less than three to four hours, but the fine-tuning takes some time, based on the organization's needs. That can take more than a month.

Our implementation strategy is based on how many servers and groups there are and what kind of traffic is coming to/from the internet. These are the factors that affect how we deploy it. Deployment requires two to three consultants who are security architects. For maintenance, one administrator is fine.

What's my experience with pricing, setup cost, and licensing?

Licensing is based on features, I believe.

What other advice do I have?

Implementation is very easy but making the product work optimally is more difficult.

It's the best product. I would rate it at eight out of ten. There are some minor issues with blocking legitimate traffic and that's why it's not a ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
PeerSpot user
CloudSece7fe - PeerSpot reviewer
Cloud Security Specialist at a tech services company with 11-50 employees
Real User
Cloud Signalling enables us to synchronize with on-premise solutions
Pros and Cons
    • "The look and feel of the management console is a little old, excessively simple. If you compare it with other solutions, the look and feel of the console is like you're using technology from five or six years ago. It doesn't show all the technology that is actually behind it. It looks like an older solution, even though it is not."

    What is our primary use case?

    The main focus was DDoS protection.

    How has it helped my organization?

    Some months ago, in Mexico, we had presidential elections. At that time it was very important to deny DDoS attacks, especially on the platform for counting votes in the election. This solution was good for our customers.

    What is most valuable?

    • AIF
    • Cloud Signalling - In my previous environment, we worked with Arbor as a carrier but in my current company some of our customers have the solution on-premise and we have to synchronize the solution with the Arbor solution that our customers have in their enterprises. The ability to work with the Arbor solution on the carrier side and on-premise provides solutions for both types of customers.

    What needs improvement?

    The look and feel of the management console is a little old, excessively simple. If you compare it with other solutions, the look and feel of the console is like you're using technology from five or six years ago. It doesn't show all the technology that is actually behind it. It looks like an older solution, even though it is not.

    The first impression needs to be more mature. It needs to be something that you would be proud to show someone. If you have a visitor to your SOC and you show him your installation, you need something more impressive. The look and feel of other brands is really nice, while Arbor is really simple. It's a good solution but not as spectacular as others. It's a matter of marketing, not performance.

    For how long have I used the solution?

    Three to five years.

    What do I think about the stability of the solution?

    The product is very stable. 

    What do I think about the scalability of the solution?

    The scalability is really amazing. That was part of the equation for one particular customer. When they understood how the bandwidth can be shared between different branches of their backbone, that they could really grow by correctly re-routing traffic, they were really happy with the solution.

    How are customer service and technical support?

    My interaction with tech support was really nice. I used to be part of HPE some time ago and I understand how those kinds of companies work. You have to have all the requirements before you make an appointment with the engineers. When we followed up with all the requirements that Arbor needed, the process was very straightforward.

    In terms of submitting a ticket, they are responsive and knowledgeable. They are very experienced people.

    Which solution did I use previously and why did I switch?

    My former company didn't have a previous solution. The company was new in Mexico and there were many considerations regarding government involvement in the industry, so security considerations were not there at that time.

    Arbor is the official solution for my former company, worldwide. Also, Arbor was sold as OEM as part of Cisco, and Cisco has a very strong position in that company. Both of those facts helped push the Arbor solution there.

    How was the initial setup?

    The setup is very straightforward, once the final architecture is decided. 

    However, the decision regarding the final architecture was not very simple because the carrier environment is very complex. In addition, at the time, the carrier I was working for bought another small carrier and was doing the integration between both their installations and backbones. That was very complex. But once all those details were decided, the placement of the Arbor solution was very straightforward.

    The setup work and testing of the Arbor solution took about three to four weeks, not including all the pre-planning and architecture discussions.

    What about the implementation team?

    I played a part, but Arbor engineers do the whole installation process. I helped as much as I could but Arbor wants the implementation done by Arbor techs. I helped with some minor activities.

    For the deployment, there was one senior engineer and one junior engineer. On our side, there were a number of people, me and a couple of other engineers. And when we tested the mitigation between different branches, there were three Arbor engineers with us.

    What's my experience with pricing, setup cost, and licensing?

    Because the solutions from competitors are very different, it's not easy to compare. However, the licensing from Arbor is clear and understandable and the pricing is reasonable when looking at the market, in general.

    What other advice do I have?

    Don't worry that it is complex because, out-of-the-box, it protects you from the basics. Just open it and connect, that's all you have to do. But if you are making an investment of this type because you have to be protected against all scenarios, you have two options: close support from Arbor or a specialized engineer. If you have those resources, all the rest is very straightforward. It becomes a simple solution that can give you good results.

    I give the solution a nine out of ten. I try to put myself in the shoes of our company's owner. If a solution is simple to operate and gives good results, it's good for me. The solution needs to do what it's supposed to do and be simple to manage.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Buyer's Guide
    Arbor DDoS
    April 2025
    Learn what your peers think about Arbor DDoS. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
    849,963 professionals have used our research since 2012.
    it_user667689 - PeerSpot reviewer
    IT Security Manager at a comms service provider with 501-1,000 employees
    Real User
    It helped us to find the best IP network route to reach countries with low latency.

    What is most valuable?

    • As an ISP, it is important to know from where the traffic comes so as to neutralize any attacks.

    • The Arbor Networks SP device provided great visualization of the network traffic.

    • Arbor Networks TMS is for cleaning the DDoS traffic, which is used sparsely.

    How has it helped my organization?

    The Arbor Networks SP device allowed us to optimize the network traffic. For example, it helped us to find the best IP network route to reach certain countries with low latency.

    What needs improvement?

    My opinion is that these Arbor devices should be scalable, in terms of the hardware.

    Network bandwidth is rapidly increasing. Therefore, it is not practical to predict the network traffic as what it will be in five years time and also, to accordingly plan the required hardware specifications.

    For how long have I used the solution?

    I have been using this solution since 2009.

    We have been using the Arbor Peakflow SP CP-5000 and Arbor Peakflow TMS 2700.

    What do I think about the stability of the solution?

    Both the devices were very stable at the operation.

    What do I think about the scalability of the solution?

    Unfortunately, these devices are not scalable and we have to upgrade to the next model in order to increase the threat mitigation capabilities.

    How are customer service and technical support?

    We’ve received technical support mainly from Thailand. The guy who supported us was very competent with the products.

    Which solution did I use previously and why did I switch?

    We were not using any other solution before.

    How was the initial setup?

    The initial IP configuration has to be done in a command line, but the rest you can do via the web interface.

    What's my experience with pricing, setup cost, and licensing?

    As a comparatively medium-scale ISP, we struggled with the license restrictions. By default, the Arbor SP device has only five licenses, which means only five routers can be integrated.

    Which other solutions did I evaluate?

    At that time (2008-09), when we checked the other options, there was not even a single product vendor that had the ability to do both network traffic analysis and DDoS traffic cleansing.

    There were other proposals such as Radware and Cisco Guard for DDOS protection.

    What other advice do I have?

    It is vital to identify the number of routers that are going to be integrated and the scrubbing capacity required for the expected lifetime of the product, as it is not scalable once you have purchased it.

    For others who expect to implement Arbor, the key prerequisite is to identify the network devices that are going to integrate, since it will dictate the licensing. Since it is not scalable, so users should have to get this right before purchasing the product.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    it_user710730 - PeerSpot reviewer
    it_user710730Cloud Services Architect EMEA at a tech vendor with 501-1,000 employees
    Real User

    I am an Arbor employee.
    Licensing has been made much more flexible in recent years, and price-per-gigabit of mitigation capacity has gone down consistently. New models, both hardware- and software-based have been added to improve scalability.

    it_user626721 - PeerSpot reviewer
    Security Consultant & IT Professional at Sistemas Aplicativos, SISAP
    Consultant
    It provides mitigation templates for volumetric and application-level attacks.

    What is most valuable?

    The deployment methods are really important as are the mitigation templates for volumetric and application-level attacks.

    How has it helped my organization?

    We do not have this product in our organization. We are service providers for Arbor.

    This product improves the application's availability; we have mitigated targeted attacks for some clients.

    What needs improvement?

    I believe that the Arbor Cloud should be available, even if the customer does not have any Arbor appliance on-premise.

    For how long have I used the solution?

    I have been using Arbor technologies for about two years.

    What do I think about the stability of the solution?

    In the two years I have been using the product, I haven't encountered any stability issues. The solution is pretty robust and stable.

    What do I think about the scalability of the solution?

    Both solutions, Arbor Networks SP/TMS and APS, are very scalable.

    The important point about Arbor Networks APS is that it is usually deployed inline, so you have to be aware of the number of switch ports available for each model.

    How is customer service and technical support?

    I have a lot of experience with the technical support for multiple vendors (HPE, Cisco, Palo Alto Networks, Imperva, etc.) and the Arbor support is really good; usually, they respond with the workaround for your issue.

    I really recommend the technical support from Arbor.

    How was the initial setup?

    Setup complexity depends on the appliance:

    • Arbor Networks APS: The setup is really straightforward; deployment and tuning are not that hard.
    • Arbor Networks SP/TMS: This a complex solution and usually deployed in Diversion/Reinjection mode. Customers have to know the concepts and configuration about BGP, routing etc.

    What's my experience with pricing, setup cost, and licensing?

    Arbor Networks APS licensing usually depends on the throughput of the enterprise.

    Arbor Networks SP/TMS licensing usually depends on the throughput and the number of managed routers.

    Note: It is not a cheap solution, but this is the most deployed anti-DDoS solution worldwide.

    Which other solutions did I evaluate?

    This is the first enterprise anti-DDoS product that we acquired. It later became Imperva.

    What other advice do I have?

    You have to be clear as to what do you want to protect, i.e., the applications, networks, etc.

    The most complex appliances are for the Arbor Networks SP/TMS solutions, so you have to know the BGP, peering, diversion, and reinjection concepts.

    Disclosure: My company has a business relationship with this vendor other than being a customer: We are partners.
    PeerSpot user
    it_user710730 - PeerSpot reviewer
    it_user710730Cloud Services Architect EMEA at a tech vendor with 501-1,000 employees
    Real User


    Arbor Cloud is now available "cloud only" too, although we still think that a hybrid, multi layer solution provides the most comprehensive protection.

    it_user664614 - PeerSpot reviewer
    Cyber Security Analyst at a tech services company with 10,001+ employees
    Real User
    It provides predefined filters/techniques to easily stop attacks. The auto-mitigation feature starts with the default filters, which could impact a customer’s link.

    What is most valuable?

    • It is user-friendly and has a very easy GUI.

    • It provides the simplest method of mitigation.

    • It provides predefined filters/techniques to easily stop attacks.

    How has it helped my organization?

    My last project was with (almost all of) the biggest banks and MNCs in India. It helped us to protect their network from the present DDoS attacks.

    What needs improvement?

    The auto-mitigation feature is provided when DDoS is observed on any of the links/customers (configured under auto-mitigation). It automatically starts mitigation with the default filters. In the default filter mode, there could be an impact on a customer’s link.

    For example, if we have enabled monitoring of the internal traffic for that link/customer, it starts mitigation on legitimate traffic. It can also create looping in the network for any misconfiguration. This can impact the ISP's internal network and the customer's link utilization.

    For how long have I used the solution?

    I have used this solution for two years.

    What do I think about the stability of the solution?

    We did not have stability issues.

    What do I think about the scalability of the solution?

    We did not have scalability issues.

    How are customer service and technical support?

    I would rate the technical support a 7/10.

    Which solution did I use previously and why did I switch?

    We were using black-hole mitigation. We switched from that technique because we were dropping all the traffic of the attacked link, rather than vulnerable traffic; there were many more loopholes.

    How was the initial setup?

    The setup is a little complex regarding the methods of configuration with the customers, as we need to provide them with a clean pipe path during mitigation. Also, it is mostly used on ISPs so the configuration on gateways is a little hectic.

    What's my experience with pricing, setup cost, and licensing?

    They offer good prices.

    Which other solutions did I evaluate?

    I did not evaluate other options.

    What other advice do I have?

    Be in direct contact with Arbor, rather than choosing a vendor in between.

    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    reviewer1435824 - PeerSpot reviewer
    System Administrator at a tech vendor with 10,001+ employees
    MSP
    Top 20
    Excellent tool for scrubbing
    Pros and Cons
    • "Arbor DDoS's best feature is that we can put the certificates in, and it will look at layer seven and the encrypted traffic and do the required signaling."
    • "An improvement to Arbor DDoS would be to make evaluation licenses and virtual machines available."

    What is our primary use case?

    I primarily use Arbor DDoS for scrubbing.

    What is most valuable?

    Arbor DDoS's best feature is that we can put the certificates in, and it will look at layer seven and the encrypted traffic and do the required signaling.

    What needs improvement?

    An improvement to Arbor DDoS would be to make evaluation licenses and virtual machines available. This would allow us to learn the system and to spread word about the product to others.

    For how long have I used the solution?

    I've been using Arbor DDoS for almost five years.

    What do I think about the stability of the solution?

    Arbor DDoS is very stable.

    What do I think about the scalability of the solution?

    Arbor DDoS is scalable.

    How was the initial setup?

    The complexity of the setup depends on the user's experience, but it's very quick to deploy.

    What was our ROI?

    Arbor DDoS has given us a very good ROI - I would rate it five out of five.

    What other advice do I have?

    I would rate Arbor DDoS ten out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Engineer at railtel corporation of india
    Real User
    I like the IP location policy to control traffic based on geolocation.

    What is our primary use case?

    Mitigating network level volumetric attacks, complete network visibility and complete control on applying countermeasures.

    What is most valuable?

    • DDoS amplification
    • Flow specs
    • Blackhole mitigation, and
    • IP location policy to control traffic based on geolocation.

    What needs improvement?

    Cloud signaling integration with third-party DDoS solution provider. Currently, it supports only its DDoS APS box.

    For how long have I used the solution?

    One to three years.
    Disclosure: I am a real user, and this review is based on my own experience and opinions.
    PeerSpot user
    Network Consultant at a comms service provider with 51-200 employees
    Consultant
    We are able to respond quickly and prevent DDoS attacks
    Pros and Cons
    • "We are able to respond quickly and prevent DDoS attacks."
    • "Its scalability is big. It is for large deployments of big organizations and service providers."
    • "There is some room for AI to take place."

    What is our primary use case?

    It is mostly for Internet Service Providers (ISPs). It is for operations on the service provider and network security operations. It is a good solution.

    How has it helped my organization?

    It improves our organization by preventing attacks and improving the availability of the network on services, which provides a better service to customers.

    What is most valuable?

    We are able to respond quickly and prevent DDoS attacks.

    What needs improvement?

    There is some room for AI to take place.

    For how long have I used the solution?

    More than five years.

    What do I think about the stability of the solution?

    Stability is perfectly good. I have not seen an issue in years.

    What do I think about the scalability of the solution?

    Its scalability is big. It is for large deployments of big organizations and service providers.

    How is customer service and technical support?

    Technical support is good. They provide quite good support. They have different levels depending on the pockets that you have bought, so you get the relative support. They have a lot of levels for support and good SLAs.

    How was the initial setup?

    The initial setup is complex, but experts are involved. Even with experts from both the vendor and the operator side, the initial set up can take some time, though it is essential.

    What's my experience with pricing, setup cost, and licensing?

    We work with different vendors from different industries.

    What other advice do I have?

    Most important important criteria when selecting a vendor:

    • How the offering covers the business needs.
    • The reputation of the vendor.
    Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
    PeerSpot user
    Buyer's Guide
    Download our free Arbor DDoS Report and get advice and tips from experienced pros sharing their opinions.
    Updated: April 2025
    Buyer's Guide
    Download our free Arbor DDoS Report and get advice and tips from experienced pros sharing their opinions.