
BGP blackholing for single-router networks
SATIS Shield is a BGP blackholing (RTBH) service aimed at single-router networks. It delivers a live, shared feed of malicious IPs as BGP routes that your router uses to discard traffic from them at the edge — the same technique large ISPs use, made available without a transit contract, a network engineering team, or multihoming.
Not just your own blocklist — a live feed of attacks other peers on the network have already seen, delivered automatically as BGP routes your router blocks in real time. Also available via API (2,000 req/day) if you want to pull it yourself.
A GRE or WireGuard tunnel to a SATIS BGP PoP (Los Angeles, Dallas, or Buffalo), one session, and one severity threshold you control.
A free private ASN (64512–65534) and a router that speaks BGP are all you need — no transit diversity, no LOA paperwork, no public ASN required.
No admin review queue. Request a session, get your generated config, and be live — typically minutes, not days.
Copy-paste BGP peer blocks generated for Cisco IOS/IOS-XE, Juniper JunOS, OpenWrt, pfSense/OPNsense, VyOS, OpenBSD, and Linux running BIRD or FRR.
Setec Astronomy operates its own BGP network (AS23026), built for collecting and blackholing threats, not a SaaS reselling someone else's feed.
Sign up with no card required. The live BGP session comes with the next step.
From the portal, request peering — live immediately, with no human review and no card on file.
Get a GRE or WireGuard tunnel config plus a copy-paste BGP peer block generated for your router's OS.
Once peered, malicious IPs above your chosen severity threshold are blackholed by your router itself before they reach your applications. The feed is not in your traffic path, and stopping volumetric floods before they saturate your link requires uRPF.
Shield costs $59/month with a 14-day free trial (no card required, auto-approval, account reverts to Community if no plan is added). A lifetime Shield tier is offered at $9,995 one-time, limited to the first 15 organizations. Professional and Enterprise tiers build on the same peering, with a 14-day trial on Professional; their prices are not stated.
$59/mo
Full RTBH tier: one BGP session, one GRE/WireGuard tunnel, focused on blackholing. 14-day free trial, no card required; session reverts to Community if no plan is added.
$9,995 one-time
Full Shield tier paid once, never billed again. Limited to the first 15 organizations.
Remote-Triggered Black Hole routing: your router announces a more-specific route for a malicious source IP with a special community tag, telling upstream routers to silently drop traffic to/from it. It's the technique large ISPs use, applied to a single-router network. It is effective against connection-completing attacks (brute force, exploit attempts, C2 callbacks), but doesn't stop volumetric floods unless you also enable uRPF on your router.
No. A single router with a private ASN and a GRE or WireGuard tunnel to a SATIS BGP PoP is enough. Multihoming and public ASNs matter for announcing your own routes to the internet, not for receiving and acting on the blackhole feed.
Yes, as long as you put your own BGP-capable router behind the ISP gateway. With bridge mode, your public IP passes straight through to your router (the cleanest setup); without it, your router works behind the ISP's box (double-NAT'd) since the tunnel is outbound-initiated.
Nothing charges automatically — there's no card on file. Without a plan, your BGP session is revoked and your account reverts to Community, with a countdown email beforehand. You can add Shield anytime self-service from the portal.
Shield is purpose-built for RTBH: one BGP session, one GRE/WireGuard tunnel, focused entirely on blackholing. Professional and Enterprise build on the same peering and add things like real-time SSE streaming and more sessions, with a 14-day trial on Professional.
No. SATIS can be your first BGP session — the requirement is only that your platform can run a BGP daemon. If all you run today is static routes, that's fine, and configs are generated for you.