Hardware · build your own · any 64-bit server

Build your own anti-DDoS appliance.

The quickest and most cost-effective protection against DDoS attacks is Wanguard on a spare, commodity server — any 64-bit Intel or AMD machine, the Linux you already run, a few minutes to install. Pick the role the server will play, size its four parts from the table below, and it is an appliance.

64-bit Intel or AMD · installs in minutes under /opt · no appliance to buy

Anatomy of a do-it-yourself appliance: any 64-bit x86 server with the CPU, RAM, network card and disk sized for the Wanguard role it will run ANY 64-BIT INTEL OR AMD SERVER CPUcores × GHzPacket Sensor / Filter:10–14 cores at 2.4 GHz+Console: 4 coresRAMGB, quad-channelFlow Sensor / Filter:8 GB runs tens of instancesConsole: 16 GB · Packet: 8–32NIC1 / 10 / 40 / 100 GbEPacket Sensor / Filter:82599 · T5+ · XL710 · DPDKmanagement on its own portSSD / HDDGB · MB/sConsole / Flow Collector:fast SSD — graph and flowstorage grows with retention Linux you chooseRHEL · Rocky · AlmaDebian · Ubuntu ServerWanguard under /optdeb / rpm packagesinstall in minutesOne role, or severalConsole · Sensor · Filtereverything clusters dedicated servers for production — virtual machines for the trial
  1. Any 64-bit Intel or AMD server.A spare one from the rack; the Linux distribution of your choice; Wanguard installs under /opt in minutes.
  2. Size the four parts for the role.Packet Sensors and Filters want cores and a fast NIC; the Console wants a fast disk; Flow Sensors want RAM.
  3. One role per server, or several.Everything clusters; a Console, a Flow Sensor and a Filter can share a box, a 40 Gbps Packet Filter gets its own.
  4. Dedicated hardware for production.Virtual machines are fine for the trial.

Size the parts by role

What IP monitoring and DDoS mitigation demand from CPU, RAM, storage and the network card.

The quickest and most cost-effective method of protecting your network and services against DDoS attacks is by installing Andrisoft Wanguard on a spare, commodity server. The software can be installed easily, in just a few minutes, on any 64-bit server equipped with an Intel or AMD processor.

Wanguard was designed to be completely scalable. It can be installed either on a single server with adequate hardware resources or on multiple servers distributed across the network. The exact hardware specifications needed for each Wanguard component are listed on each component page: Console, Packet Sensor, Flow Sensor and Filter. The table below shows how to size the hardware for each software component:

Component CPU Speed
(> GHz/core)
CPU Cores
(> cores)
RAM Size
(> GB)
HDD Size
(> GB)
HDD/SSD Speed
(> Mbytes/s)
Network Adapter
(Vendor, Model)
Console High High High Very High Very High Very Low
Packet Sensor Very High High Medium Low Low Very High
Flow Sensor Low Low High Very High Medium Very Low
SNMP Sensor Very Low Low Very Low Very Low Very Low Very Low
Sensor Cluster Medium Medium Medium Very Low Very Low Very Low
Packet Filter Very High Very High Medium Very Low Very Low Very High
Flow Filter Low Low High Very Low Very Low Very Low
Filter Cluster Medium Medium High Very Low Very Low Very High

Relative demand: Very LowLowMediumHighVery High

Three reference builds

The minimum servers from the component pages, as a starting point — go up from here for more interfaces, more retention or more users.

Console server

The workbench box

Database, graphs, reports, the web interface — one per deployment, a VM is fine.

Fast, uninterrupted access to the disk is the critical requirement: put the database and graph storage on SSD and size it by retention and monitored IPs. No limit on managed components.

CPU · RAM
2.4 GHz quad-core Xeon · 16 GB
NIC · disk
Gigabit Ethernet · 350 GB SSD
Also fits
a Flow Sensor or two, a Flow Filter
Console requirements →
Flow Sensor server

The flow box

One Flow Sensor per exporter; a server with enough RAM runs tens of them.

Low CPU, RAM for the correlation engine, disk if the Flow Collector keeps the flows. Virtual machines are possible but not recommended in production.

CPU · RAM
2.0 GHz dual-core Xeon · 8 GB per server
NIC · disk
1 × Gigabit Ethernet · 60 GB + flow storage
Also fits
the Console, a Flow Filter
Flow Sensor requirements →
Packet Sensor / Filter server

The wire-speed box

Dedicated: the CPU cores and the network card decide what it can do.

10 Gbit/s (~14 Mpps): 2.4 GHz 10-core Xeon E5-2640v4, 8 GB DDR4 quad-channel, one 10 GbE adapter — Intel 82599 (X520/X540), Chelsio T5+ or any DPDK NIC — plus a management port. 40 Gbit/s (~30 Mpps): 12–14 cores, 32 GB, a 40 GbE Intel XL710+ / Chelsio T5+ / DPDK card. Cluster for 100 Gbit/s and more.

10 Gbps
10 cores · 8 GB · 10 GbE
40 Gbps
12–14 cores · 32 GB · 40 GbE
Licenses
Sensor $595 · Filter $995 · DPDK Engine $1,410 / year
Packet Sensor requirements · Filter requirements

Network cards, virtual machines, operating system

The three decisions that decide whether the box keeps up.

Network cards

For packet capture load-balanced over several CPU cores: Intel 82599 chipset adapters (Intel X520, X540, HP X560, Silicom PE310G4DBi9-T), PF_RING or Netmap with their supported cards, or any adapter supported by DPDK. For in-NIC hardware packet filtering: Intel 82599 at 1/10 Gbps, Chelsio T5+ at 10/40/100 Gbps, any NIC with the DPDK Flow API; line-rate inline filtering on Mellanox/NVIDIA NICs in 9.0. Management goes on a separate Gigabit port.

DPDK configuration in the docs →

Virtual machines

You can use Virtual Machines during the trial period, but using dedicated servers for production is highly recommended. A few arguments against using Virtual Machines to run Wanguard on a regular basis:

  • Having fast and uninterrupted access to the hard disk is a critical requirement for the Console.
  • The resources must be provisioned in a predictable and timely manner.
  • Some Virtual Machines do not have a stable clock source.

Operating system

Before installing Wanguard you will need to install (no advanced Linux skills required) on the designated server one of the following Linux distributions: Red Hat Enterprise Linux 9 or 10 (commercial), Rocky Linux 9 or 10 (free, RHEL-based), AlmaLinux 9 or 10 (free, RHEL-based), Debian 11, 12 or 13 (free, community-supported), Ubuntu 20, 22, 24 or 26 (free, Debian-based).

Wanguard installs itself under /opt, so make sure the root partition has at least 10 GB free space.

Software installation in the docs →

What runs on it

The four Wanguard components — install one per server or several together; every one reports to the Console, every one clusters. Wansight is the same Sensors and Console without detection and mitigation.

Console

The workbench

Web UI, reports, dashboards, users and the API — the brain of the deployment.

Multi-tenant, with 40+ dashboard widgets, scoped views for customers, white-label login for MSSPs, PDF and Excel exports, 10 themes including a dark mode.

License
free, unlimited users
Auth
SAML 2.0, LDAP/AD, RADIUS
Automation
REST API, CLI, scripts
Console in detail →
Flow Sensor

Listens to routers

Collects and analyzes the flows your routers already export.

NetFlow v5/v7/v9, jFlow, cflowd, NetStream, sFlow v4/v5 and IPFIX; one instance per exporter, tens of instances per server; an optional flow collector with interactive flow graphs.

Per instance
1 exporter, tens of 10/40/100 GbE ports
Detection
≤ export time + 5 s
License
$595 / year
Flow Sensor in detail →
Packet Sensor

Sniffs the wire

Inspects packets from a mirror port, a TAP or an in-line link.

libpcap, PF_RING, Netmap or DPDK; 100 GbE and more than 30 Mpps per instance, clustered across CPU cores and servers; packet captures viewable in a Wireshark-like page.

Per instance
100 GbE, > 30 Mpps
Detection
≤ 1 s
License
$595 / year
Packet Sensor in detail →
Filter

Scrubs the attack

Turns an anomaly into precise filtering rules, then applies them.

Packet Filter inspects diverted or in-line packets, with deep packet inspection for payload patterns; Flow Filter derives the same rules from any Flow Sensor's flows on minimal hardware. Both apply them anywhere: local Netfilter, in-NIC filters (Intel 82599, Chelsio T5+, any DPDK Flow API card), BGP Flowspec routers or third-party appliances.

Packet Filter
10–40 Gbps per server, rules < 1 s
Flow Filter
1 Tbps+ via Flowspec, rules 5–10 s
License
$995 / year
Filter in detail →

Wanguard overview →  ·  Wansight →  ·  Pricing →

Try the full product on your own hardware

Every feature, any number of servers, 30 days — by requesting a free evaluation license. Our engineers help you set it up.

Request a trial key
Debian 11–13Ubuntu 20–26RHEL 9–10RockyAlmaLinux
1

Request a key

Fill in the trial form. We review it and email download links, documentation and a 30-day license within 24 hours.

2

Install on a spare Linux server

Any 64-bit Intel/AMD box or VM. Packages install under /opt in minutes; size the hardware with the system requirements.

3

Run it for real, then buy

Ask us anything during the trial. When it earns its keep, buy licenses in the online store — the trial installation carries on with the new key.

Already running Wanguard?

Wanguard 9.0 is out (23 July 2026). Upgrading from 8.x? Read the release notes first.