How it works
1
Sensor mode activation
Once you request TCP-Track for an IP address, Packets Decreaser places that IP into sensor mode. The system begins passively monitoring all outgoing TCP traffic from that IP.
2
Real-time traffic analysis
Outgoing TCP connections are inspected in real time. The system builds a picture of normal traffic patterns: which destination IPs and ports your server communicates with, and how those connections behave over time.
3
Automatic whitelisting
When traffic on a connection is classified as legitimate, the source IP and its destinations are added to the DDoS filter allowlist. No manual rule creation is required.
4
Seamless filtering under attack
If a DDoS filter activates due to an incoming attack, already-whitelisted flows remain intact. Your established connections are not interrupted, and clients do not need to reconnect.
TCP-Track operates on a best-effort basis. In the event of an attack, detection and filter activation may take a few seconds, during which some new connections could be affected before whitelisting catches up.
Supported port ranges
TCP-Track currently supports automatic whitelisting for the following port ranges:
Support for additional ports may be available on request. Contact support to discuss your use case before requesting activation.
Requesting activation
To enable TCP-Track on an IP address:- Contact Packets Decreaser support.
- Provide the IP address you want to enable TCP-Track on.
- Describe your use case so support can confirm compatibility.
- Sensor mode is activated once support confirms the request.