Manual Rules in LiveShield - manual FlowSpec and blackholing rules independent of automatic detection

Manual Rules in LiveShield - manual FlowSpec and blackholing rules independent of automatic detection

Manual Rules is a feature introduced in Manager 1.3.0 that lets an operator manually create a FlowSpec or blackholing (RTBH) rule independently of automatic attack detection - without waiting for traffic to exceed configured thresholds, and without modifying the detection configuration itself. It requires Manager 1.3.0 with Analyser 1.3.1 or newer, plus configured BGP sessions for the relevant address families.

This answers a question that has come up repeatedly for months in conversations with ISP operators deploying LiveShield: what to do when a specific address needs to be blocked immediately, or deliberately excluded from filtering, without adjusting detection thresholds for the entire prefix.

How Manual Rules differ from automatically generated rules


The FlowSpec and RTBH rules LiveShield generates by default are the result of a traffic threshold being exceeded for a given protocol, IP address, or subnet - the system reacts to a detected anomaly, and the rule disappears once traffic returns to normal (per the configured timeout). Manual Rules operate alongside this mechanism, not in place of it: the operator decides when a rule applies, regardless of whether any detection threshold has been crossed.

In practice, this means two independent decision paths running in parallel - an automatic one, based on real-time traffic analysis, and a manual one, fully controlled by the operator. Both paths use the same rule-distribution infrastructure (BGP, FlowSpec and blackholing sessions), so no separate network configuration is required.

How to configure a manual FlowSpec rule (Manual Filtering)


Filtering rules are configured under Manual Rules > Filtering, via the "+" button. The same matching parameters LiveShield uses in automatically generated rules are available:

  • Action: Drop, Rate Limit, Accept, Redirect to VRF, or Redirect to IP (defaults to Drop)
  • Destination (required, IPv4/IPv6 CIDR) and optional source address
  • Protocol: ICMP, TCP, UDP, GRE, ESP, ICMPv6, or custom (0-255)
  • TCP flags (for the TCP protocol)
  • Ports - a single port or separate source/destination ports
  • Fragment options (DF, IsF, FF, LF)
  • Packet length - a single value or a range
  • Optional restriction of the rule to a specific BGP router (empty field = all eligible routers)
The Rate Limit action requires a value in bits per second, Redirect to VRF requires a route target in IPv4 format (e.g. 192.0.2.1:65000), and Redirect to IP requires a host address with no subnet mask. The system rejects duplicate rules with an identical combination of source, destination, protocol, fragment, and ports.

How to configure manual blackholing (Manual Blackholing)


Manual blackholing is configured similarly, under Manual Rules > Blackholing. It requires a prefix (IPv4/IPv6 CIDR, /32 or /128 for a single host) and a BGP community in number:number format. As with filtering, the rule can optionally be restricted to a specific BGP router, and additionally tied to a specific upstream provider (selective blackholing).

One limitation worth knowing upfront: only one manual blackholing rule is allowed per prefix at a time - changing the community or scope is done by editing the existing rule, not by adding another one.

What situations Manual Rules are practically used for


The most obvious use case is urgently, manually blocking or unblocking a specific IP address - a scenario operators had been asking about for a long time before this feature existed in its current form. Previously, the only way to exclude an address from filtering was to create a separate /32 prefix with raised or zeroed-out thresholds within the standard detection configuration - it worked, but required touching the threshold configuration rather than being a dedicated, explicit mechanism.

Other practical uses: setting up a rule ahead of time, before an attack even begins (for example in response to an attack warning or a pattern detected by another system), testing whether a given FlowSpec rule actually gets correctly installed on a specific edge router, or temporarily and deliberately rate-limiting an address generating unusual, but not necessarily malicious, traffic - without waiting for automatic detection to catch it on its own.

Who can create and modify Manual Rules


Access to Manual Rules is split across permission levels. Administrator and SuperOperator have full rights to create, edit, enable, disable, and delete rules across all prefixes. An Operator can view and modify rules within their assigned prefixes, while creation and deletion require additional permissions. A Viewer has read-only access by default, unless the Administrator additionally grants Create or Delete rights.

One important operational safeguard: every change to rule configuration requires an Administrator to click Apply in the sidebar before the rule is actually announced to routers. This prevents a rule from reaching the production network immediately upon being saved, without an extra approval step.

How to edit, disable, and delete a rule


Each rule can be expanded in the list to review its full parameters, and modified through editing and saving. The Enabled toggle lets you disable a rule without deleting its configuration - useful when a rule should stay ready for reuse but shouldn't apply for the time being. Permanent removal requires confirming the delete action. As with creation, all these changes require Administrator approval (Apply) before routers receive the updated configuration.

Summary


Manual Rules, introduced in Manager 1.3.0, give the operator full control over FlowSpec and blackholing rules independent of automatic detection - both for urgently, manually blocking or excluding a specific address, and for planned, test, or preventive actions. Manual rules run on the same distribution infrastructure as automatic ones, and access to them is governed by permission levels and requires Administrator approval before reaching the production network.

Frequently asked questions


Do Manual Rules replace automatic attack detection in LiveShield? No. Manual Rules operate alongside automatic detection, as an independent decision path fully controlled by the operator - they don't disable or modify the standard thresholds and automatically generated rules.

How do you exclude a specific IP address from automatic filtering? Manual Rules allow this directly, without needing to modify detection thresholds for the entire prefix - previously, the only way was to create a separate /32 prefix within the standard configuration.

Does a manual FlowSpec rule reach the router immediately after being saved? No. Every change in Manual Rules requires an Administrator to approve it via the Apply button in the sidebar - only then is the rule announced to BGP routers.

How many manual blackholing rules can you have per prefix? Only one. Changing the BGP community or the scope of the rule is done by editing the existing rule, not by adding another one.

Don't wait for the next DDoS attack.
Contact us today!

Please check filled in fields for errors. If problem persists, contact us directly at office@liveshield.net

Thank you for reaching out to us!

Your message has been successfully sent.
We will get back to you as soon as possible.

Or call us directly

(+48) 880 779 307