DDoS protection & traffic monitoring

Network security software that runs on your own servers.

We build Wanguard, the on-premise DDoS detection and mitigation software, and Wansight, its traffic-monitoring sibling: Linux packages on commodity hardware, no appliance in the path, no traffic leaving your network, no per-gigabit fees.

Already a customer? Log in to the support portal →

Since 2006 · EU-based · 1,000+ network operators in 50+ countries

Attack detection in seconds — mitigation on your own network.

What the stack does

Six capabilities in the same Linux packages, reporting to one Console — a license key decides which are on.

Detection in seconds

Flow and Packet Sensors analyze NetFlow, sFlow, IPFIX or mirrored packets; anomaly checks run every second.

Wanguard →

On-premise mitigation

Filters scrub diverted attack traffic at line rate on Linux servers — or your routers do it via Flowspec and RTBH.

Filter →

Monitoring and billing

Bandwidth graphs for 100,000s of IPs, top talkers, and 95th-percentile accounting for invoicing.

Wansight →

Forensics on demand

An optional Flow Collector with interactive flow graphs; packet captures in a Wireshark-like viewer.

Flow Sensor →

Automation end to end

A REST API and CLI drive the Console; response actions run your scripts; alerts go by email, syslog, SNMP.

Console →

Multi-tenant by design

Scoped views for customers and departments, white-label portals for MSSPs, SAML 2.0 / LDAP / RADIUS sign-in.

Console →

How it fits your network

Sensors sit out of path beside your routers, listening to NetFlow, sFlow, IPFIX or a mirrored link — nothing new goes in the way of your traffic. When an attack starts, mitigation runs where you choose: on your routers via BGP Flowspec or RTBH, or on Wanguard Filter servers that scrub the diverted traffic and hand the clean traffic back.

Deployment options →
How Wanguard deploys: Sensor and Filter run on Linux servers beside your border router Console Wanguard — Linux packages on servers you already have Internet Your border router unchanged · BGP peer Your servers or your entire network all traffic incl. attacks clean traffic Sensor sees every flow and packet signals your routers via BGP Filter scrubs diverted attack traffic at line rate, on this server flows · packetsBGPattack trafficclean
  1. Your routers keep forwarding as today.They export NetFlow, sFlow or IPFIX to a Sensor — or you mirror a link.
  2. Wanguard Sensor sees every flow and packet.It raises anomalies and signals your routers via BGP Flowspec, RTBH or diversion.
  3. Wanguard Filter scrubs the diverted traffic.At line rate, on a Linux server, and hands the clean traffic back.
  4. Your network and servers stay reachable.No appliance in the path, no traffic leaving your network, no per-gigabit fees.
flows & packets to the SensorBGP signalling back to the routerattack traffic diverted to the Filterclean traffic delivered
Runs in the networks of More customers →
Google FiberVodafoneIBMHuaweiEquinixMozillaDigitalOceanNamecheap

Why operators pick Wanguard

100 Gbps+per server analyzing packets with DPDK; Flow Sensors scale to routers with tens or hundreds of 100 GbE interfaces
< 1 secondattack detection with DPDK — filtering rules in the next second; flow-based detection in seconds
150+ metricsper host, subnet, IP group, AS, country or interface — dashboards, forensics and a REST API in one Console
Any topologyout-of-path with BGP diversion, inline with DPDK, or upstream with BGP blackholing when attacks exceed your uplink

Already running Wanguard?

Wanguard 9.0 is out (23 July 2026). Upgrading from 8.x? Read the release notes first.

Release notes by email

A few messages a year, when a version ships. No marketing, unsubscribe anytime.