No more typing reviews! Try our Samantha, our new voice AI agent.

Arbor DDoS vs Neustar UltraDDoS [EOL] comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 2, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Arbor DDoS
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
57
Ranking in other categories
Distributed Denial-of-Service (DDoS) Protection (3rd)
Neustar UltraDDoS [EOL]
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
1
Ranking in other categories
No ranking in other categories
 

Featured Reviews

reviewer1331304 - PeerSpot reviewer
Director Of Research And Development at a comms service provider with 11-50 employees
Automated threat intelligence and flow-based mitigation have improved our DDoS defense
A very useful feature in Arbor DDoS is its ability to send flow spec announcements to routers. For example, if it is clear that a Layer 3 or Layer 4 attack is occurring and the attack pattern is identified through source and destination IP addresses and ports, you can generate flow spec filters. These filters are transferred through BGP to border routers, which automatically build filters, mitigating the attack even at the network's boundary and preventing it from reaching the TMS. This allows the TMS to focus on other tasks. This is a highly effective feature that can mitigate huge volumetric attacks; for example, we experienced a 32-gigabit attack, and all those 32 gigabits were dropped by our border routers, not by Arbor DDoS itself. The flow spec announcement was generated by Arbor DDoS, and as far as I know, the same technology is used by Radware, but it comes under a different feature and a different license. At the time, we were told that flow spec mitigation was an additional very expensive license to purchase from Radware, while Radware included everything in one package.
JT
Manager Strategic Planning at Endurance International Group
Identifies a request that comes up multiple times, block holds that particular IP, and lets the genuine traffic pass through
Genuine traffic coming in is still getting better. While I understand that it's some sort of algorithm that is written in this scale, that algorithm can be a little bit better because sometimes while we are doing DDoS mitigation, genuine traffic does get blocked. While it is one of the greatest features it can still be improved. I would like to see a dashboard that shows you the data that is transferred from which end. It's where people start looking at abuse management. People keep questioning when the mitigation is on what service it is and how many GBs are passing through. An end user dashboard that will help you identify all of these questions and that can be visible in your entire organization is something that would make sense.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We also use it by serving our customers' cloud signaling services with on-premise APS devices."
"Don't worry that it is complex because, out-of-the-box, it protects you from the basics."
"The feature I find most valuable is the packet capture, which beautifully shows the communication between the client and the server, identifying potential malicious activity."
"Using standard BGP, NetFlow and SNMP ensure wide compatibility. There are also peering traffic reports that can help identify upstream peering opportunities. The ATLAS aggregation service allows us to contribute to the global DDoS data and benefit from overall trends."
"I am convinced with the kind of scalability Arbor brings in; the Cloud subscription, which is available as one of its features, makes the scalability limitless."
"The solution provides good protection against volumetric DDoS attacks."
"Valuable features include simple and centralized management of user access and capabilities, as well as Web 2.0 interactive attack alerting, traffic visualization, and mitigation service control."
"Arbor Pravail APS devices provide easy management, high visibility, and quick response capabilities."
"In the DDoS it's difficult to validate what is a genuine request from an end user. We've started being able to do that with the logistics that they have set up. With the protection that they have provided, they are able to identify what is valid and what is not valid. We see that a person who is getting DDoS Neustar service is able to block that particular user. However, while they are doing that it doesn't affect other customers on the server."
"Scalability is awesome, and they have grown two folds or three folds since we started using them, with no concerns even as we protect close to 60,000 hosted sites for business and e-commerce customers."
 

Cons

"I think the diversity of protection is extremely limited. It must be expanded in future upgrades and versions."
"We need a SaaS model for the solution."
"On the main page there are alerts that we are unable to clear, even though the issue has been resolved."
"The implementation should be made easier."
"The support got worse after NETSCOUT acquired Arbor."
"There should be an automatic way to configure it to monitor traffic and decide which is an attack and which is not. In Arbor, you need to tweak and set all parameters manually, whereas in Check Point DDoS Protector, you can select the lowest parameters, and over the weeks, Check Point DDoS Protector will learn the traffic and you can then tighten some of the parameters to decide which traffic is regular and which is malicious."
"Arbor Pravail APS devices do not sync features or config the backup enough. This needs to be improved."
"An issue which needs to be addressed concerns information I received of attacks on the radar and Arbor, allegedly, not taking any action."
"Genuine traffic coming in is still getting better because sometimes while we are doing DDoS mitigation, genuine traffic does get blocked."
"I would like to see a dashboard that shows you the data that is transferred from which end. It's where people start looking at abuse management. People keep questioning when the mitigation is on what service it is and how many GBs are passing through. An end user dashboard that will help you identify all of these questions and that can be visible in your entire organization is something that would make sense."
 

Pricing and Cost Advice

"Arbor is striking a good balance between pricing and what they deliver."
"I believe that the price of Arbor DDoS falls under the bracket of medium to high price."
"As far as I know, they are the best in this sector, in DDoS protection. They know it, I know, because their service prices are too high. They provide cloud DDoS protection for ISPs, but that is also too expensive."
"There is room for improvement with the pricing. It is an expensive solution. The issue with the pricing is more the way it is built. Right now we're paying per router, and there's a limitation there. I would like to see bundle-pricing where there is an overall solution cost."
"Start with a small license. Measure your bandwidth requirements."
"You need to find a way to get a good offering from Arbor by negotiating a price. That is the challenge."
"Our customers always complain about the price of the product."
"Because the solutions from competitors are very different, it's not easy to compare. However, the licensing from Arbor is clear and understandable and the pricing is reasonable when looking at the market, in general."
Information not available
report
Use our free recommendation engine to learn which Distributed Denial-of-Service (DDoS) Protection solutions are best for your needs.
914,109 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Comms Service Provider
12%
Outsourcing Company
11%
Construction Company
6%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business26
Midsize Enterprise14
Large Enterprise29
No data available
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
I would say if it’s an ISP that will build a scrubbing center, Netscout/Arbor is a good solution. In all other solutions, Imperva is a great choice.
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would prefer Arbor.
What is your experience regarding pricing and costs for Arbor DDoS?
The prices for Arbor DDoS are expensive. The licensing is subscription-based. From our sales department, they discuss that prices are very high.
Ask a question
Earn 20 points
 

Also Known As

Arbor Networks SP, Arbor Networks TMS, Arbor Cloud for ENT
Neustar UltraDDoS, UltraDDoS
 

Overview

 

Sample Customers

Xtel Communications
Choxi
Find out what your peers are saying about Radware, Cloudflare, NETSCOUT and others in Distributed Denial-of-Service (DDoS) Protection. Updated: September 2026.
914,109 professionals have used our research since 2012.