Skip to content

Vendor profile

HARPP DDoS Mitigator: Architecture, Capabilities and Trade-offs

Last updated: August 2026 · Four checkable properties, stated as such · Reading time ~11 min

A sealed chamber with amber entering one side and a teal-green thread leaving the other, a closed teal-green loop circulating entirely within its walls, two smaller partitioned loops side by side inside it, and no cable or conduit leaving it in any direction.

HARPP DDoS Mitigator is an on-premises appliance with four properties a buyer can check directly: detection runs on the customer's own infrastructure with no dependency on a vendor-operated intelligence cloud; L3–L7 coverage in a single appliance; per-customer protection profiles on shared hardware; and a commercial relationship that is separate from the upstream tier. The manufacturer's documentation was read for this profile but is not yet published, so nothing here can be checked at source the way the peer profiles allow.

Best for:

multi-tenant providers, and estates with a data-residency or evidence-custody requirement

Four properties are asserted here because a buyer can confirm each directly; the rest describes what the manufacturer’s documentation establishes. That documentation is not yet published, which is a real weakness of this page rather than a formality — read the Sources note before using it in an evaluation.

At a glance

ApplianceValueEvidence
ManufacturerLabris NetworksVendor-stated
CategoryOn-premises applianceVendor-stated
DeploymentInline, as a transparent bridge or as a gatewayVendor-stated
Detection locationCustomer's own infrastructure; no vendor intelligence cloud dependencyVendor-stated, verifiable on a test bench
Layer coverageL3–L7 in a single applianceVendor-stated, verifiable on a test bench
Multi-tenancyPer-customer protection profiles on shared hardwareVendor-stated, verifiable on a test bench
Own global scrubbing cloudNoVendor-stated
Published capacity figures200 Gbps, 80–90 Mpps for a single applianceVendor-stated, not independently tested
Best-fit environmentMulti-tenant providers and estates with a residency or evidence-custody requirementEditorial inference

Architecture

An inline on-premises appliance. The architectural property that distinguishes it from a decomposed design is that Layer 3 through Layer 7 coverage lives in a single unit vendor-stated, rather than an edge appliance handling the network layers and a separate component handling the application layer.

Whether that helps depends on the estate: it removes an integration and puts more of the defence behind one failure domain, a trade the multi-vendor architecture assessment works through properly.

Detection and classification

Detection runs entirely on the customer’s own infrastructure, with no dependency on a vendor-operated intelligence cloud vendor-stated.

The test is simple and settles the question for any product: disconnect the appliance’s outbound path to the manufacturer, repeat the same attack, compare the two runs. Local classification degrades gracefully on novel vectors; a dependency on an external service degrades in a step. Two documented details support the claim structurally — heuristic signatures ship with the appliance, and the geographic database is a versioned package installed on it rather than a lookup service.

Layer 3 and Layer 4 mitigation

Covered in the same unit as the application layer vendor-stated. SYN flood protection runs in a symmetric or asymmetric mode chosen to match whether the device sees both directions of traffic, with a configurable handshake window; malformed-packet handling, protocol blocking, rate limits and country rules sit alongside it. Behaviour under packet-rate stress should still be measured at 64-byte packet sizes rather than inferred from a bit-rate figure.

Layer 7 mitigation

Covered in the same unit vendor-stated. The documented DNS work is specific enough to name: query-rate limits per source, random-subdomain and NXDOMAIN detection, a novel-name mode for topologies where responses are not visible, and a per-domain aggregate ceiling. Depth relative to purpose-built application-layer designs is what a proof of concept with replayed application traffic exists to measure.

Capacity and packet-rate considerations

The manufacturer publishes 200 Gbps of mitigation throughput and 80–90 million packets per second for a single appliance vendor-stated. Untested independently, and not a design input: a family-level figure describes the largest model, not the unit quoted. One trap will catch anyone who checks — the figures still on the manufacturer’s public website belong to an earlier hardware generation and are several times lower. Establish which generation a quotation covers.

Multi-tenancy

Per-customer protection profiles on shared hardware vendor-stated. For a provider selling protection as a service this decides whether the product is usable at all, and it is verifiable: configure two tenants with different policies, attack one, confirm isolation and per-customer reporting.

HA, bypass and failure modes

A hardware bypass exists and its state is reported on the dashboard vendor-stated. Establish the behaviour on power loss and on software fault, and the measured failover time — the same questions asked of every inline appliance on this site, and the ones a status indicator does not answer.

Management and telemetry

Telemetry stays on infrastructure the customer controls, which is the consequence of local detection. Syslog and SNMP export are documented, alongside per-zone and per-rule traffic statistics, top-talker views, an alarm record that doubles as the incident log, and packet capture that shows the pass or drop decision taken for each packet vendor-stated. Retention behaviour and report formats should be established against the quoted configuration.

Data and control-plane dependencies

None stated for classification vendor-stated. Licensing, updates, support and hardware replacement still depend on a live commercial relationship — true of every manufacturer here, and removed by no architectural choice.

Integrations

Syslog and SNMP for telemetry, RADIUS for administrator authentication vendor-stated. Whether that is enough depends on what the receiving side expects: a syslog stream is not the same thing as a maintained connector, and the parsing work lands on the buyer.

Regional support

Not publicly documented here. Support scale is a genuine difference between a multinational and a smaller manufacturer, and the question is the same one asked of everyone: who answers at 3am local time, in which language, under what response commitment.

Licensing and TCO characteristics

The commercial relationship is separate from the upstream or transit tier vendor-stated, so the on-premises decision does not commit the transit decision and either can be renegotiated without the other. A commercial property, not a technical one: it changes what you can renegotiate, not what either tier can absorb. Licensing structure beyond that is not publicly documented here.

Strengths

The four properties above, each checkable rather than asserted. For a provider reselling protection, and for an estate keeping evidence and classification inside a jurisdiction, they meet requirements that are otherwise awkward to satisfy.

Limitations and unknowns

  • No first-party global scrubbing cloud. The upstream volumetric tier must be contracted separately — a property of on-premises appliances generally, but a real constraint on a single-supplier hybrid.
  • Independent test coverage. Less third-party test and analyst material exists than for the long-established names here, so more of an evaluation has to be done rather than read.
  • Documentation not yet public. The material this page rests on was read but cannot be read by you, and the manufacturer’s website describes an earlier generation. Until the consolidated guide is published, this profile is weaker evidence than its peers.
  • Regional support scale relative to a multinational is a difference to establish locally.

Best fit

Service providers needing per-customer policies on shared hardware; organisations under a residency or evidence-custody obligation where classification leaving the country is the problem; estates that specifically want the two tiers under separate contracts.

Poor fit

Buyers wanting one supplier for both the on-premises tier and a global scrubbing cloud; organisations choosing primarily on the volume of independent test material available; estates whose only real exposure is volumetric saturation, where the upstream tier does the work.

POC questions

  1. Disconnect the outbound path to the manufacturer, repeat the same application-layer test, compare the runs. Step degradation and graceful degradation are different answers.
  2. Configure two tenants with different policies, attack one, verify isolation and per-customer reporting.
  3. Replay your own application traffic alongside a Layer 7 attack and measure the false-positive rate at a genuine business peak.
  4. Test at 64-byte packet sizes and record where behaviour changes; compare against the vendor-stated figure for the model quoted.
  5. Trigger the bypass path deliberately and time the failover.
  6. Export the telemetry an incident report needs, in your format and on your schedule.
  7. Ask for sector references in your market and speak to them without the vendor present.

Frequently asked questions

Why can this profile not be checked at source?
Because the documentation it rests on has not been published yet. The user guide and release notes were supplied to this publication and read for this page, and a consolidated edition is being prepared; a link will appear here when it exists. Until then the honest description is that a reader has to take this page's word for it, which is a weaker position than the peer profiles are in, and saying so is better than implying a check is possible when it is not.
Which of these four properties actually matter?
It depends entirely on what you are solving. Detection running locally matters where a degraded international path or a data-residency rule turns a cloud dependency into a compliance question. Single-appliance L3–L7 matters where splitting the layers across two products would mean two design documents and a gap between them. Multi-tenancy matters only if you resell protection. Contractual separation from the upstream tier matters only if you care about being able to change one tier without the other. None of the four is an advantage in the abstract.
What does "no own global scrubbing cloud" mean for a buyer?
It means the upstream volumetric layer has to come from somewhere else — a transit provider or a scrubbing service — and that you will be contracting for it separately. This is not a defect specific to one product: no on-premises appliance from any manufacturer absorbs a saturated circuit, and the difference between products here is whether the same supplier also sells you the upstream tier.
How should the vendor-stated capacity figures be treated?
As a starting point for a conversation, not as an input to a capacity plan. A figure attached to a product line describes its largest model under conditions the manufacturer chose. Require the number for the specific model quoted, in packets per second at a stated packet size, and verify it on your own traffic mix before it enters a design.

Sources

This profile carries no link to the manufacturer's documentation, which every peer profile on this site does. The reason has changed since this page was first written. The user guide and current release notes were supplied to this publication and were read for this revision; a consolidated edition is being prepared for publication, and a link will appear here when it exists. Two consequences a reader should weigh in the meantime. Nothing below can be checked at source, so it remains vendor-stated in the strict sense: the manufacturer says so, and this publication has not tested it. And the material currently on the manufacturer's public website describes an earlier generation with substantially lower figures and a narrower application-layer scope, so it is not a usable substitute — establish which generation any quotation covers before comparing numbers.

Published: August 2026 · Last reviewed: August 2026

Reviewed means the sources above were re-read on that date; the text is only reissued when something material changed.

This guide is updated as vendors release new models and pricing. How we compare vendors