Routelock analyzes real-time NetFlow data, actively probes network paths, and dynamically steers BGP routes across your upstream carriers to deliver the lowest latency, highest throughput, and strongest resilience for your traffic.
A comprehensive platform that brings carrier-grade BGP intelligence to your network.
Ingest and analyze NetFlow v5/v9 and IPFIX at wire speed. Identify top talkers, traffic patterns, and prefix-level utilization across all carriers.
Continuously probe destination prefixes via each upstream with ICMP, TCP, and HTTP probes. Measure latency, jitter, loss, and MOS scores in real time.
Full BGP session management via BIRD 2.x. Receive full routing tables from multiple upstreams and inject optimized routes with controlled prepending.
Multi-criteria scoring engine weighing latency, jitter, loss, throughput, and cost. Automatically selects the optimal upstream for each prefix.
EWMA-based anomaly detection with FlowSpec blackholing and XDP/eBPF inline packet scrubbing. Protect your network at line rate.
Track interface utilization, bandwidth usage, and link health via SNMP polling. Enforce capacity limits per carrier with automatic rebalancing.
JWT tokens, LDAP/Active Directory, SSO via SAML/OIDC, and TOTP two-factor authentication. Role-based access control with granular permissions.
85 RESTful API endpoints with OpenAPI documentation. Real-time WebSocket updates push route changes, alerts, and metrics to your dashboard instantly.
Schedule maintenance windows to pause optimization during planned changes. Automatic route pinning prevents disruption during upgrades.
Manage independent routing domains for multi-site or multi-tenant deployments. Each domain has its own policies, thresholds, and BGP sessions.
Routelock continuously monitors, analyzes, and optimizes your traffic in a closed-loop cycle.
Ingest NetFlow from routers, receive full BGP tables from all upstreams, poll SNMP counters, and run active probes to every destination.
Score each upstream per prefix using weighted criteria: latency, jitter, packet loss, throughput capacity, and cost. Detect anomalies and DDoS attacks.
Inject more-specific BGP routes via BIRD to steer traffic onto the best path. Continuously re-evaluate and adapt as conditions change.
Choose how much automation you want. Graduate from observation to full automation at your own pace.
Routelock collects data, runs analysis, and shows what it would do -- without making any changes. Perfect for evaluation and baselining your network.
Every route optimization is queued for human review. Your team approves or rejects each change before BGP routes are injected. Full audit trail included.
Routelock autonomously optimizes routes within your defined policy guardrails. Rate limits, cooldowns, and safety checks prevent runaway changes.
Monitor every aspect of your network's routing health from a single pane of glass.
Modern, high-performance stack designed for carrier-scale networks.
25K+ lines of compiled, concurrent Go code. Low latency, low memory, rock-solid reliability.
Time-series optimized PostgreSQL for billions of NetFlow records, probe results, and metrics.
Industry-standard BGP daemon handling 1.1M+ routes with full table support from multiple peers.
Kernel-bypass packet processing for DDoS scrubbing at line rate. Filter millions of packets per second.
From DDoS mitigation to access control, security is built into every layer.
EWMA-based anomaly detection identifies volumetric, protocol, and application-layer attacks in seconds. Automatic escalation through multiple mitigation tiers.
XDP/eBPF scrubber processes packets in kernel space at line rate. TCP SYN validation, UDP rate limiting, GRE/IP-in-IP filtering, and geo-based blocking.
Automatically propagate filtering rules to upstream routers via BGP FlowSpec. Distribute mitigation across your entire network edge.
JWT authentication, LDAP/AD integration, SAML/OIDC SSO, and TOTP 2FA. Role-based access control with per-action permissions and full audit logging.
From install to first optimized route in four simple steps.
Add your upstream providers, set BGP session parameters, and define capacity limits.
Settings → Carriers → Add Carrier
Point your routers' NetFlow exports to Routelock. We support v5, v9, and IPFIX.
ip flow-export destination <routelock-ip> 2055
Peer Routelock with your border routers. Receive full tables and announce optimized routes.
neighbor <routelock-ip> remote-as 65000
Start in Test mode to observe, graduate to Human for supervised changes, then Robot for full automation.
Settings → System → Operating Mode
Take control of your BGP routing with real-time intelligence and automated optimization.