The quickest and most cost-effective protection against DDoS attacks is Wanguard on a spare, commodity server — any 64-bit Intel or AMD machine, the Linux you already run, a few minutes to install. Pick the role the server will play, size its four parts from the table below, and it is an appliance.
Wanguard overviewInstallation guideLicenses
64-bit Intel or AMD · installs in minutes under /opt · no appliance to buy
What IP monitoring and DDoS mitigation demand from CPU, RAM, storage and the network card.
The quickest and most cost-effective method of protecting your network and services against DDoS attacks is by installing Andrisoft Wanguard on a spare, commodity server. The software can be installed easily, in just a few minutes, on any 64-bit server equipped with an Intel or AMD processor.
Wanguard was designed to be completely scalable. It can be installed either on a single server with adequate hardware resources or on multiple servers distributed across the network. The exact hardware specifications needed for each Wanguard component are listed on each component page: Console, Packet Sensor, Flow Sensor and Filter. The table below shows how to size the hardware for each software component:
| Component | CPU Speed (> GHz/core) |
CPU Cores (> cores) |
RAM Size (> GB) |
HDD Size (> GB) |
HDD/SSD Speed (> Mbytes/s) |
Network Adapter (Vendor, Model) |
|---|---|---|---|---|---|---|
| Console | High | High | High | Very High | Very High | Very Low |
| Packet Sensor | Very High | High | Medium | Low | Low | Very High |
| Flow Sensor | Low | Low | High | Very High | Medium | Very Low |
| SNMP Sensor | Very Low | Low | Very Low | Very Low | Very Low | Very Low |
| Sensor Cluster | Medium | Medium | Medium | Very Low | Very Low | Very Low |
| Packet Filter | Very High | Very High | Medium | Very Low | Very Low | Very High |
| Flow Filter | Low | Low | High | Very Low | Very Low | Very Low |
| Filter Cluster | Medium | Medium | High | Very Low | Very Low | Very High |
Relative demand: Very LowLowMediumHighVery High
The minimum servers from the component pages, as a starting point — go up from here for more interfaces, more retention or more users.
Fast, uninterrupted access to the disk is the critical requirement: put the database and graph storage on SSD and size it by retention and monitored IPs. No limit on managed components.
Low CPU, RAM for the correlation engine, disk if the Flow Collector keeps the flows. Virtual machines are possible but not recommended in production.
10 Gbit/s (~14 Mpps): 2.4 GHz 10-core Xeon E5-2640v4, 8 GB DDR4 quad-channel, one 10 GbE adapter — Intel 82599 (X520/X540), Chelsio T5+ or any DPDK NIC — plus a management port. 40 Gbit/s (~30 Mpps): 12–14 cores, 32 GB, a 40 GbE Intel XL710+ / Chelsio T5+ / DPDK card. Cluster for 100 Gbit/s and more.
The three decisions that decide whether the box keeps up.
For packet capture load-balanced over several CPU cores: Intel 82599 chipset adapters (Intel X520, X540, HP X560, Silicom PE310G4DBi9-T), PF_RING or Netmap with their supported cards, or any adapter supported by DPDK. For in-NIC hardware packet filtering: Intel 82599 at 1/10 Gbps, Chelsio T5+ at 10/40/100 Gbps, any NIC with the DPDK Flow API; line-rate inline filtering on Mellanox/NVIDIA NICs in 9.0. Management goes on a separate Gigabit port.
DPDK configuration in the docs →You can use Virtual Machines during the trial period, but using dedicated servers for production is highly recommended. A few arguments against using Virtual Machines to run Wanguard on a regular basis:
Before installing Wanguard you will need to install (no advanced Linux skills required) on the designated server one of the following Linux distributions: Red Hat Enterprise Linux 9 or 10 (commercial), Rocky Linux 9 or 10 (free, RHEL-based), AlmaLinux 9 or 10 (free, RHEL-based), Debian 11, 12 or 13 (free, community-supported), Ubuntu 20, 22, 24 or 26 (free, Debian-based).
Wanguard installs itself under /opt, so make sure the root partition has at least 10 GB free space.
Software installation in the docs →The four Wanguard components — install one per server or several together; every one reports to the Console, every one clusters. Wansight is the same Sensors and Console without detection and mitigation.
Multi-tenant, with 40+ dashboard widgets, scoped views for customers, white-label login for MSSPs, PDF and Excel exports, 10 themes including a dark mode.
NetFlow v5/v7/v9, jFlow, cflowd, NetStream, sFlow v4/v5 and IPFIX; one instance per exporter, tens of instances per server; an optional flow collector with interactive flow graphs.
libpcap, PF_RING, Netmap or DPDK; 100 GbE and more than 30 Mpps per instance, clustered across CPU cores and servers; packet captures viewable in a Wireshark-like page.
Packet Filter inspects diverted or in-line packets, with deep packet inspection for payload patterns; Flow Filter derives the same rules from any Flow Sensor's flows on minimal hardware. Both apply them anywhere: local Netfilter, in-NIC filters (Intel 82599, Chelsio T5+, any DPDK Flow API card), BGP Flowspec routers or third-party appliances.
Every feature, any number of servers, 30 days — by requesting a free evaluation license. Our engineers help you set it up.
Fill in the trial form. We review it and email download links, documentation and a 30-day license within 24 hours.
Any 64-bit Intel/AMD box or VM. Packages install under /opt in minutes; size the hardware with the system requirements.
Ask us anything during the trial. When it earns its keep, buy licenses in the online store — the trial installation carries on with the new key.
Wanguard 9.0 is out (23 July 2026). Upgrading from 8.x? Read the release notes first.