Protect your network's reputation before it's on the line.
ZenShield is carrier-grade outbound abuse detection and IP reputation protection for ISPs — it watches outbound traffic and stops abuse before it gets you blacklisted.
Outbound abuse is quietly costing ISPs their IP reputation
Spam relay abuse
Compromised subscriber hosts blast spam through port 25/587, and the ISP's netblock — not the subscriber — gets reported to Spamhaus, SORBS, and other RBLs.
Botnet & worm activity
Telnet, SMB, and NetBIOS scanning from infected devices marks the whole IP range as a threat source in security feeds.
DDoS reflection abuse
Misconfigured NTP, SNMP, UPnP, and Memcached services turn subscriber IPs into unwitting amplification weapons.
Manual, reactive cleanup
Without real-time detection, ISPs only find out after a blacklist listing already hurts subscriber mail deliverability and network standing.
Detect → rate-limit or block → auto-expire → give visibility
Detect
Watches connection attempts on abuse-prone ports as they leave the subscriber network.
Rate-limit or block
Automatically throttles suspicious volume or hard-blocks ports with no legitimate outbound use.
Auto-expire
Temporary blocks clear themselves — no manual cleanup, no stuck subscribers.
Give visibility
A live dashboard shows every block, every whitelist override, and full audit history.
Full outbound attack-surface coverage — not just mail
Most outbound-protection tools only watch port 25. ZenShield covers the full outbound abuse surface.
| Port | Service | Risk |
|---|---|---|
| 25, 587 | SMTP / Submission | Spam relay → RBL listing |
| 123 | NTP | DDoS reflection/amplification |
| 22, 21 | SSH / FTP | Brute-force & scanning source |
| 23 | Telnet | Botnet / malware signature |
| 445, 139 | SMB / NetBIOS | Worm & ransomware propagation |
| 1900, 11211 | UPnP, Memcached | High-multiplier DDoS reflection |
| 19, 17, 161 | CharGEN, QOTD, SNMP | Legacy amplification abuse |
What typical spam-guard tools miss
| Capability | Typical spam-guard tools | ZenShield |
|---|---|---|
| SMTP spam-relay protection | Yes | Yes |
| Botnet / worm detection (Telnet, SMB) | No | Yes |
| DDoS reflection protection (NTP, SNMP, UPnP, Memcached) | No | Yes |
| Brute-force protection (SSH, FTP) | No | Yes |
| Live dashboard & audit history | Varies | Yes |
| Customer-prefix safety scoping | Varies | Yes |
Simple, low-risk deployment — no tunnels, no re-architecture
Traffic on watched ports is redirected to the appliance via a router policy — return traffic never needs to pass through ZenShield, so latency and failure risk stay minimal.
- One-arm appliance — no GRE tunnel, no MTU/fragmentation overhead
- Fail-open by design — if unreachable, the router falls back to normal routing
- Deploys on standard Ubuntu Server hardware or VM
- Built on nftables for kernel-speed enforcement — no per-packet bottleneck
Subscribers
LAN side → Edge Router (policy-based routing) → ZenShield (inspect · rate-limit · block) → Internet (WAN uplink)
Already protecting a live ISP network today: deployed on a Juniper-based carrier network, actively detecting and blocking abusive outbound connections in production, with outbound-only architecture that means zero impact on inbound subscriber traffic or latency.
Full operational visibility, not a black box
Live Events
Real-time feed of every block as it happens, on redirected ports.
Reports
Top offending IPs and most-targeted ports at a glance.
Customer Prefixes
Scope enforcement to your actual subscriber ranges only — anything outside those ranges bypasses inspection entirely.
System Health
CPU, memory, and disk monitoring on the appliance itself.
Whitelist Control
Instantly clear a block or exempt a known-good IP.
Full Audit History
Every block and unblock, timestamped, for compliance and support.
Getting started is low-risk and fast
Pilot deployment
One appliance, one router policy, your choice of subscriber segment. No changes to existing infrastructure.
Tune & validate
Watch real traffic in the dashboard, confirm thresholds fit your subscriber base, adjust customer-prefix scoping.
Scale out
Add appliances per subscriber segment as needed — same enforcement model, no architecture changes.