We build Wanguard, the on-premise DDoS detection and mitigation software, and Wansight, its traffic-monitoring sibling: Linux packages on commodity hardware, no appliance in the path, no traffic leaving your network, no per-gigabit fees.
Already a customer? Log in to the support portal →
Since 2006 · EU-based · 1,000+ network operators in 50+ countries
Attack detection in seconds — mitigation on your own network.
Sensors watch NetFlow, sFlow, IPFIX or mirrored packets and stop attacks on your routers — Flowspec, RTBH — or on Linux filtering servers. Sensor licenses are $595 a year, with volume discounts; the Console is free.
Explore → Traffic monitoring & accountingThe same Sensors and Console without detection and mitigation: bandwidth graphs, top talkers, flow and packet forensics, 95th-percentile billing. Becomes Wanguard with a key.
Explore → HardwareAny 64-bit Intel or AMD server runs it. Sizing per component, tested network cards for 10–100 Gbps, and why virtual machines are for trials only.
Sizing guide →Six capabilities in the same Linux packages, reporting to one Console — a license key decides which are on.
Flow and Packet Sensors analyze NetFlow, sFlow, IPFIX or mirrored packets; anomaly checks run every second.
Wanguard →Filters scrub diverted attack traffic at line rate on Linux servers — or your routers do it via Flowspec and RTBH.
Filter →Bandwidth graphs for 100,000s of IPs, top talkers, and 95th-percentile accounting for invoicing.
Wansight →An optional Flow Collector with interactive flow graphs; packet captures in a Wireshark-like viewer.
Flow Sensor →A REST API and CLI drive the Console; response actions run your scripts; alerts go by email, syslog, SNMP.
Console →Scoped views for customers and departments, white-label portals for MSSPs, SAML 2.0 / LDAP / RADIUS sign-in.
Console →Sensors sit out of path beside your routers, listening to NetFlow, sFlow, IPFIX or a mirrored link — nothing new goes in the way of your traffic. When an attack starts, mitigation runs where you choose: on your routers via BGP Flowspec or RTBH, or on Wanguard Filter servers that scrub the diverted traffic and hand the clean traffic back.
Deployment options →







Wanguard 9.0 is out (23 July 2026). Upgrading from 8.x? Read the release notes first.