RioRey DDoS mitigation appliance
RE110: DDoS Mitigation for 40G and 100G Networks
The RE110 is the successor to the RE100. It runs the same RIOS analytics on the same proven platform, with substantially higher packet filtering capacity: up to 133 million packets per second on a single appliance, across three license levels.
One chassis. Three licenses. License-upgradable to full RE110 throughput without changing hardware.
License levels
RE110 License Levels
Every RE110 is the same appliance. The license sets its filtering capacity, so you can deploy at the capacity your traffic needs today and upgrade in place as it grows.
-
RE110 20G
20 Gbps license
Up to 32 million packets per second.
-
RE110 40G
40 Gbps license
Up to 83 million packets per second.
-
RE110 100G
100 Gbps license
Up to 133 million packets per second.
Dashed line: approximately 148.8 million packets per second, the theoretical packet rate of a 100 Gbps link carrying minimum-size (64 byte) Ethernet frames.
Why packet rate matters
Packet Rate Is the Real Limit, Not Bandwidth
Most DDoS mitigation hardware runs out of packet processing capacity long before it runs out of bandwidth. Floods built from small packets, such as SYN floods and many UDP floods, push very high packet rates through modest bandwidth, and that is where general-purpose equipment falls over.
The RE110 is sized around packets per second for that reason. Its capacity applies to the attack traffic itself, so a small-packet flood on a 100G link is the case it was built for, not an edge case.
RE100 to RE110
What Changed from the RE100
The platform and the RIOS mitigation engine carry over. The difference is filtering capacity, and a new 20G entry license.
| License level | RE100 | RE110 |
|---|---|---|
| 20 Gbps | Not offered | Up to 32M pps |
| 40 Gbps | Up to 40M pps (RE100/40) | Up to 83M pps |
| 100 Gbps | Up to 80M pps | Up to 133M pps |
Deployment
Where the RE110 Fits in Your Network
The RE110 deploys in-line for always-on protection or off-ramp in a scrubbing center, and it plugs into the rest of the RioRey architecture without integration work between vendors.
In-line at the Edge
All traffic passes through the RE110. RIOS filters continuously at line rate, with no operator action needed to start mitigation and no learning period.
Off-ramp with Director
RioRey Director watches NetFlow and sFlow and diverts traffic for a targeted destination through the RE110 only when an attack is detected. Normal traffic never touches the filter.
Hybrid with rCloud
The RE110 handles attacks at your edge. When an attack exceeds your link capacity, Director escalates it to rCloud, which runs the same RIOS engine. One vendor, end to end.
Attack coverage
All 25 Attack Classes, Identified by Method
RIOS identifies attacks by their underlying methodology rather than by signatures or the name of the tool that launched them. A new attack tool is a new variation of a method RIOS already recognizes, not a zero-day. There are no signatures to update and no rules to write, and mitigation typically begins within 0 to 90 seconds.
See the full RioRey Taxonomy of DDoS Attacks.
TCP Based
- SYN Flood
- SYN-ACK Flood
- ACK & PUSH ACK Flood
- Fragmented ACK
- RST or FIN Flood
- Synonymous IP
- Fake Session
- Session Attack
- Misused Application
TCP-HTTP Based
- HTTP Fragmentation
- Excessive VERB
- Excessive VERB Single Session
- Multiple VERB Single Request
- Recursive GET
- Random Recursive GET
- Faulty Application
UDP Based
- UDP Flood
- UDP Fragmentation
- DNS Flood
- VoIP Flood
- Media Data Flood
- Non-Spoofed UDP Flood
ICMP Based
- ICMP Flood
- ICMP Fragmentation
- Ping Flood
Management
Managed in rWeb, Alongside Everything Else
The RE110 is managed through rWeb, the same platform that runs every RioRey appliance, VM, and rCloud deployment. Zones, per-class mitigation settings, real-time and historical traffic, and multi-tenant customer portals all work the same way they do on the rest of your RioRey estate.
For operators offering DDoS protection as a service, that means an RE110 can be added to an existing customer-facing deployment without a new operational model.
RE110 Technical Specifications
The full RE110 specification sheet is in final engineering review and will be published here shortly. For interface, session, and deployment details in the meantime, contact RioRey.
FAQ
RE110 Questions
How is the RE110 different from the RE100?
The RE110 succeeds the RE100 on the same platform and runs the same RIOS mitigation engine. It raises filtering capacity to up to 83 million packets per second on the 40G license and up to 133 million packets per second on the 100G license, and adds a 20G entry license rated at up to 32 million packets per second.
Can I move to a higher license without replacing hardware?
Yes. Every RE110 is the same appliance, and the license determines its capacity. The 20G and 40G licenses are license-upgradable to full RE110 throughput.
Which DDoS attacks does the RE110 mitigate?
All 25 attack classes in the RioRey Taxonomy of DDoS Attacks, across TCP, TCP-HTTP, UDP, and ICMP, at Layer 3, Layer 4, and Layer 7. Detection is based on attack methodology, not signatures.
Can the RE110 be deployed off-ramp or in a hybrid architecture?
Yes. The RE110 can be deployed in-line or off-ramp. Paired with RioRey Director, it can receive diverted attack traffic in a scrubbing center, and Director can escalate attacks that exceed local capacity to rCloud, which runs the same RIOS analytics.
Where can I find RE110 pricing and full specifications?
Hardware pricing is available on request through the RioRey contact page. The full RE110 specification sheet will be published on this page once engineering review is complete.
Size Your RE110 Deployment
Tell us your link speeds, typical utilization, and deployment model, and we will recommend a license level and architecture.