Country / Region
With the continuous popularization and development of network technology, cyberattacks have become increasingly frequent. Through various attack tools, even beginners with basic computer knowledge can launch attacks on networks. Meanwhile, the proliferation of various network viruses has further heightened the risk of network attacks.
AFC (Anti-DDoS) is a high-performance network security solution designed for operators, internet data centers, financial industry data centers, government and enterprise office networks, as well as various industry markets. In terms of security features, the product provides users with a comprehensive security defense system and remote secure access capabilities. It supports real-time monitoring of traffic, packet counts, and connection numbers for protected objects, while filtering and cleansing abnormal traffic. Additionally, the product enables filtering and matching of data packets based on specific business requirements, blocking insecure protocols and ports, limiting attack traffic on protected objects, and generating various security reports and log records. These capabilities effectively ensure network security.
The following contents are complex, and it is recommended to browse on PC.

Enter c.h3c.com.cn on the PC browser and operate according to the page to synchronize to the PC and continue browsing.
Continue by mobile
Traffic-Based Defense Types
Supports defense against single-packet attacks such as Smurf, Ping of Death, Teardrop, IP Fragmentation, Winnuke, and Traceroute.
Application Layer Protocol Defense
Supports custom protocol types to defend specific application layer protocols, such as those used in online gaming, voice, and instant messaging.
Supports slow attacks like HTTP slow header, HTTP slow post, and connection number limitation.
Provides protection against cache DNS server and authoritative DNS server crashes, domain hijacking prevention, and supports DNS IP address TopN, DNS domain name TopN, and DNS QPS statistics.
Supports automatic analysis of payload length and patterns in non-connection protocols like UDP for automatic filtering.
Allows customization of business logic policies for both connection and non-connection protocols.
Protection Features
Automatically identifies all protected hosts and their IP addresses, ensuring that an attack on one host does not disrupt the normal services of others.
Allows setting automatic protection triggers based on attack traffic and connection count thresholds, with flexible control over connection count thresholds under varying conditions.
Supports algorithm adjustment functionality, enabling manual algorithm tuning when default algorithms prove ineffective or suboptimal.
Facilitates both automatic and manual addition of allowlists and blocklists, along with flexible rule configurations.
Provides fingerprint-based protection, enabling custom frequency and connection limits based on packet headers, protocol types, field values, and specific characteristics.
Offers fine-grained dynamic traffic baseline learning capabilities, with learning results directly applicable as defense thresholds.
Supports Super ACL (filtering by protocol, port, IP, protocol code, protocol flags, state, country, and province combinations).
Enables multi-dimensional signature-based filtering policies (e.g., signatures, signature packet length, signature packet frequency, signature flow trust, and automatic allowlisting/blocklisting of source IPs based on signatures).
Supports attack traceback capabilities.
Domain Name Audit Function
Supports per-domain rate limiting / designated domain rate limiting.
Supports domain name allowlist and blocklist features.
Tiered protection, enabling separate protection for primary and secondary domains. For example: Primary domain can be set to allow, while secondary domains can be blocked.
Traction Method
Supports both static and dynamic diversion methods, including OSPF, BGP, and IS-IS protocols.
Supports multiple injection methods, such as Layer 2 injection, policy-based routing injection, GRE injection, MPLS LSP injection, and MPLS VPN injection.
Comprehensive Reports
Supports report output in multiple formats.
System Operation and Maintenance
Supports automatic packet capture functionality. When under attack, it automatically captures attack packets from the targeted host, facilitating network administrators' monitoring and evidence collection.
Supports online packet analysis, enabling the generation of analysis reports based on HTTP and data payloads.
Supports various packet capture parameters, such as specifying target/source IP addresses and MAC addresses, for manual analysis of attack types.
Model |
| AFC2000-E40-G |
Chassis | Color | Black |
Form Factor | Box type | |
Height | 2U | |
External Dimensions (Length D * Width W * Height H) | 600mm×440mm×89mm | |
Packaging Dimensions (Length D * Width W * Height H) | 730mm×535mm×225mm | |
Gross Weight | 20 Kg | |
Net Weight | 15.76 Kg | |
Storage | Standard Storage | Supports up to 3 SATA drives (HDD/SSD: two external, one internal). Default: one 4TB drive - Seagate ST4000NM000B |
Drive Interface | 2 | |
Standard Interfaces | Management Port (Copper Ports) | 2 |
Console Port | 1 | |
USB | 2 | |
Expansion Slots | Number Of Interface Card Expansion Slots (Used/Total) | 0/8 |
Service Card Slots | 8 | |
Power Supply | Power Supply Methods | Dual power supply (Great Wall) |
Standard Power Supply | Input voltage: 100-240V AC / 180-310V DC | |
Power Consumption | 350W | |
Voltage | AC 100-240V | |
Power Consumption |
| 160W (max 300W, min 126W) |
Fan |
| 4 (1 CPU fan, 1 bridge fan, 2 chassis fans) |
Environmental Stability Parameters | Operating Temperature | 0 °C -40 °C (storage temperature: -20 °C -70 °C) |
Operating Humidity | Operating: 20–80%, non-condensing | |
MTBF | Over 70,000 hours | |
Expansion Modules | Expansion Card 1 | 4-port Ethernet Giga copper and 4-port Ethernet optical card (4 copper/4 optical) |
Expansion Card 2 | 4-port Ethernet Giga copper (includes 2 pairs bypass) and 4-port Ethernet optical card (4 copper/4 optical/2BP) | |
Expansion Card 3 | 4-port Ethernet 10G optical card (4x10G) | |
Expansion Card 4 | 4-port Ethernet 10G optical card (includes 2 pairs bypass, multimode) (4x10G/2BP) | |
Expansion Card 5 | 2-port 40G Ethernet optical card | |
Expansion Card 6 | 16-port Ethernet copper, 16-port Ethernet Giga optical and 4-port Ethernet 10G optical card (16 copper/16 optical/4x10G) |
Description | |
Status Monitoring | Displays real-time input/output traffic, connection count, and intercepted traffic for all devices within the cluster. |
Shows real-time input/output traffic, input-intercepted traffic, and input-intercepted packet count for server IP addresses. | |
Displays server connection status (source IP, destination IP, source port, destination port, protocol status). | |
Supports connection count statistics for server address pairs (source IP address, destination IP address). | |
Ranks server TOP N information (traffic, packet count, intercepted traffic, intercepted packet count, device). | |
Supports online packet capture and analysis. | |
Supports viewing dynamic and static blacklists and whitelists. | |
Traffic Diversion and Blackhole | Supports BGP traffic diversion. |
Supports RIP and RIPng traffic diversion. | |
Supports OSPFv2/v3 traffic diversion. | |
Supports static route traffic diversion. | |
Supports policy-based route traffic diversion. | |
Supports custom diversion configuration (diversion and diversion removal time settings). | |
Supports manual viewing of diversion status. | |
Supports viewing diversion history records. | |
Supports logging of router action commands | |
Supports customization of automatic blackhole routing policies | |
Supports TOP traffic ranking-based traffic steering | |
Supports presetting of router actions | |
Supports ACL-based traffic redirection and IP blocking | |
Supports whitelist protection for routing steering | |
Supports configurable blackhole counting cycles (e.g., first steering, second steering, third steering... with customizable unblocking time for each steering event) | |
Supports steering API interface, including querying steering status, initiating/revoking steering, and configuring IP address ranges or specific IPs for steering rules via the API | |
Supports traffic steering based on the total traffic of one or multiple address groups (defines a traffic threshold; when the combined traffic of all addresses within the rule exceeds the threshold, the TOP1 address by traffic in the group is steered) | |
Traffic Re-injection | PBR Traffic Re-injection |
GRE Traffic Re-injection | |
MPLS Traffic Re-injection | |
MPLS VPN Traffic Re-injection | |
VLAN Layer 2 Traffic Re-injection | |
Dual-Arm Layer 3 Traffic Re-injection | |
Attack Defense | Customizable Attack Rule Thresholds(supports manual input for SYN, TCP, UDP, ICMP, and IP protection trigger thresholds) |
Supports Character/16-bit Hex Signature Filtering | |
Supports Customizable Signature Packet Frequency Rate Limiting | |
Supports Automatic Blacklisting of Source IPs When Signature Packet Frequency Exceeds Limits | |
Supports Automatic Blacklisting of Source IPs Based on Occurrence Count of Single-Packet Signatures | |
Supports Source/Destination Feature Tagging, with Blacklisting or Allowlisting of Source IPs Based on Tags | |
Support filtering based on packet size. | |
Support rate limiting based on specified packet length. | |
Support configuring the number of packets allowed to pass within a specified time period (by source IP or destination IP). | |
Support configuring the traffic volume allowed to pass within a specified time period (by source IP or destination IP). | |
Support customizing the timeout for each rule's blacklist. | |
Support forcibly terminating connections for blacklisted source IPs. | |
Support globally blacklisting source IPs or blacklisting specific servers. | |
Support rule actions: continue, pass, or exit locally. | |
Support shared register data within rules. | |
Support bidirectional signature filtering. | |
Support relative signature offset filtering starting from TCP data. | |
Support signature filtering based on specified offset positions. | |
Support whitelisting source IPs based on signature values. | |
Support whitelisting source IPs based on packet size. | |
Support traffic rate limiting. | |
Support packet rate limiting. | |
Support real-time connection number-based blacklisting of source-destination IP address pairs. | |
Filter Rule | Support configuring access control policies based on (geolocation, source IP address, destination IP address, source port, destination port, protocol number, and flag bits). |
HTTP Protection Plugin | Support user-transparent JS verification |
Support interactive verification with skip button | |
Support customizable interactive question verification | |
App Security | Support transparent forwarding mode domain protection (HTTP domains and HTTPS domains) |
Support reverse proxy mode domain protection (HTTP domains and HTTPS domains) | |
Support custom protection rule configuration (Method, URL, source IP, Referer, User - Agent, Content - Length, Host, HTTP code, HTTP version) | |
Support various disposal results (frequency limitation, interception, interception and blacklisting, release, release and trust) | |
Support viewing real - time domain information | |
Support real - time acquisition of domain attack analysis records | |
Support domain whitelist protection | |
Support Layer 2 and Layer 3 routing configuration | |
Game Protection Plugin | Maximum connection limit for source and destination addresses |
Server maximum connection protection | |
Automatic release of idle connections | |
DNS Protection Plugin | DNS domain name blacklist and whitelist |
DNS domain name access control and rate limiting | |
Defense against DNS cache poisoning attacks | |
Protection against DNS spoofing attacks | |
Protection against domain hijacking | |
DNS domain name redirection | |
Dynamic DNS cache proxy | |
DNS failover protection | |
DNS TOP N ranking | |
Defense against random DNS domain name attacks | |
Protection against DNS Query and Reply Flood attacks | |
Static Sampling Plugin | UDP Sampling Plugin(Automatically defends against UDP flood attacks) |
ICMP Sampling Plugin(Automatically defends against ICMP flood attacks) | |
IP Sampling Plugin(Automatically defends against IP flood attacks) | |
Deployment Method | Support transparent series deployment, bypass dual - arm deployment, bypass single - arm deployment (Note: The original text repeated "bypass dual - arm deployment", here only translated once), and also supports single - unit hybrid mode deployment. It can adopt routing mode deployment, and a single device can freely switch working modes according to the actual environment |
Attack Tracing | Supports recording attack source addresses and actively analyzing the geographical location and network route of the attacking IPs |
Supports Unified Cluster Management | Enables unified viewing, management, and configuration of the status and network data of all distributed nodes, with no upper limit on the maximum managed cluster capacity |
Custom Security Reports | Security reports can be exported |
Supports configuring scheduled tasks for automatic export of security reports | |
Log Reports | Attack Logs(Includes attack start/end time, peak attack traffic, peak blocked traffic, packet count, blocked packet count, and attacking source IPs) |
Traffic Logs(Device traffic logs, per-server traffic logs—including inbound traffic, outbound traffic, blocked traffic, and connection attempts—default storage period: 30 days) | |
Connection Monitoring Logs | |
Attack Statistical Analysis Reports | |
Custom system identification | Facilitate identification and humanized management for multi - node and multi - cluster users |
Device management source address restriction | Source address access can be restricted |
License configuration | Support free switching between AFC and AFD (Clear the database before switching) |
Users | Support two - factor authentication (Including account password login and email verification code login) |
Item | AFC2000-E40-G |
Protection capabilities(1518 bytes) | 40 Gbps |
Throughput (1518 bytes) | 40 Gbps |
New Sessions / Second (HTTP) | 1,400,000cps |
Concurrent Sessions | 120,000,000cps |
Application Layer Throughput | 40 Gbps |
Flow Detection | 750,000Fps |
In a series deployment scenario, the addition of a physical device to the network increases potential failure points. It is recommended to adopt a dual-machine active-active hot standby approach when using series deployment to mitigate network failure risks.
Under series deployment, full bidirectional network traffic can be monitored, enabling detailed analysis of server traffic. This makes it particularly suitable for protecting against application-layer (resource-consuming) network attacks such as web CC and gaming CC.

Figure 1. AFC Series Connection Scenario Networking Diagram
AFC is deployed in parallel with the user's network core devices. A BGP adjacency relationship is established between AFC and the core devices. AFC introduces protected traffic by advertising host addresses or long-mask route information to the core devices. AFC receives real-time traffic of the protected objects through its interconnection ports with the core devices. The traffic is filtered by the scrubbing system's defense engine, and the attack-free traffic is forwarded back to the core devices via the same interconnection ports, completing the filtered traffic reinjection. In this mode, the user's network devices must preconfigure policy-based routing on the ingress direction of the interconnection ports. This ensures that traffic matching the destination address of the protected objects is directly forwarded to downstream aggregation nodes, preventing routing loops.
In the bypass diversion scenario, traffic is forwarded to AFC via dynamic routing. If the device fails, dynamic routing automatically converges, and service traffic reverts to the original forwarding path. Thus, adding more AFC does not introduce additional network failure points.
Since the server's upstream data does not pass through AFC in the bypass diversion scenario, AFC cannot fully take over all server traffic for precise analysis. Therefore, bypass deployment is generally not recommended for application-layer protection scenarios such as Web CC, gaming CC, and DNS outage protection.
This deployment method fully utilizes the uplink and downlink bandwidth of the interconnection interfaces between the core devices and AFC, reducing the interface occupancy rate of the core devices. Consequently, it lowers the cost pressure associated with expanding core device interfaces.

Figure 2. The Networking Diagram for the AFC Bypass Static Diversion Scenario
Both AFC and AFD are deployed in bypass mode on the side of the user's core network equipment. Traffic is forwarded to AFD in real time via mirroring or optical splitting. When an abnormal traffic attack is detected, the affected traffic is dynamically diverted to AFC.
This deployment mode is simple and does not require adjustments to the existing network structure.
Dynamic Diversion: Under normal conditions, traffic bypasses AFC. When an attack is detected on a service address, AFD collaborates with AFC to dynamically divert the attacked traffic to AFC, reducing the load on AFC.
Dynamic Recovery: If AFC fails, the diversion routing automatically converges, restoring the original forwarding path for traffic, ensuring uninterrupted service operation.
High Reliability: During normal operation, non-attacked traffic continues to follow its original path, preventing any disruption caused by misconfigured defense policies.
Low Network Port Usage: In single-arm bypass deployment, only one network port per link is required for setup.
This solution is suitable for scenarios such as data center egresses of telecom operators, where high bandwidth capacity and network reliability are critical, and serial deployment of AFC is prohibited.

Figure 3. The Networking Diagram for AFC Bypass Detection In Dynamic Drainage Scenarios
The AFC2000 series products are independently developed by New H3C Technologies Co., Ltd. Users can select and purchase products according to their actual needs based on the product models.
Item | Description |
Hardware appliance | H3C SecPath AFC2000-E40-G, Anomaly Flow Cleaner Appliance, System Software License (Including 20G Throughput Lic) |
License | H3C SecPath AFC2000-E40-G, System Software License (Including 20G Throughput Lic) |
Modules | H3C SecPath IPC603X, 4-Port 10/100/1000BASE-T Interface (RJ45) + 4-Port 1000BASE-X Interface (SFP) Module |
H3C SecPath IPC603X, 4-Port 10/100/1000BASE-T Interface (RJ45, 2 Pair Bypass)+ 4-Port 1000BASE-X Interface (SFP) Module | |
H3C SecPath IPC603X, 4-Port 10G Ethernet Interface Module (SFP+) | |
H3C SecPath IPC603X, 4-Port 10G Ethernet Interface Module (SFP+, 2 Pair Bypass, Multi-Mode) | |
H3C SecPath IPC603X, 2-Port 40G Ethernet Interface Module (QSFP+) |