Packet Sensor is the component of Wanguard and Wansight that inspects IP packets — from SPAN or RSPAN port mirroring, a network TAP, or a server in the main data path — with libpcap, PF_RING, Netmap or DPDK, at 100 GbE and more than 30 million packets per second per instance. Five-second graphs, one-second detection, packet captures you read in a Wireshark-like page, and the same per-endpoint responses as the Flow Sensor.
Wanguard overviewFlows or packets?Sensor licenses
100 GbE · > 30 Mpps per instance · detects in ≤ 1 s · graphs every 5 s
Six screens from a Packet Sensor on a demo network: its traffic graphs, the same traffic by country and by autonomous system, its top talkers, the captures it is running, and one of them opened in the analyzer. Click any of them to enlarge.
At its core, the same scalable traffic-correlation engine as the Flow Sensor — monitoring hundreds of thousands of IPv4 and IPv6 addresses and ranges — fed by packets instead of flow records, so it sees everything and sees it first.
Traffic accounting and per-IP, per-subnet or per-IP-group graphs for 50+ decoders — IP, the TCP flag combinations, UDP, ICMP, fragments, QUIC, DNS, NTP, SNMP, SSDP, memcached, GRE, IPv4/IPv6, YouTube, Netflix and your own. Tops and graphs for talkers, external IPs, IP groups, autonomous systems and transit ASes, countries, ports and protocols; graphs as fine as five seconds, history for as many years as you keep.
IP reports in the docs →With a Wanguard license: DDoS and unknown volumetric DoS; NTP amplification, UDP, ICMP and SMURF floods; SYN floods, TCP/UDP port 0, LOIC, peer-to-peer attacks; scans and worms hitting illegal or unallocated addresses; traffic missing from critical services. Anomaly checks every second — or every five — and a capture of the attacking traffic for the forensics.
How detection works →Activate on-premise mitigation with Wanguard Filter; announce RTBH blackholes with Flowspec (RFC 5575) or null-routing communities; send BGP off-/on-ramp diversion to an on-premise or cloud scrubber; email alerts from dynamic templates; syslog to your SIEM; capture a sample of the traffic; or run your scripts through an API exposing 130+ parameters.
Response actions in the docs →Flows or packets? A Flow Sensor needs no extra hardware and tens of them share a server; the Packet Sensor needs a mirror port, a TAP or a place in the data path, and in return detects in one second with five-second graphs. Many networks run both — choosing a method of traffic monitoring.
The Packet Sensor runs as a passive sniffer, or as a transparent bridge or pseudo-Layer-3 device that forwards packets between its ports. It scales by running load-balanced across CPU cores and across servers, and reads the encapsulations carriers actually use.
Packet dumps can be downloaded or viewed online in a Wireshark-like interface, with raw hexadecimal and ASCII for inclusion in regular expressions — for forensic investigation, network-wide situational awareness and troubleshooting.
The datasheet and the two reference servers — 10 and 40 Gbit/s — as the specification sheet has them; the DPDK engine license is needed on top of the Sensor license only when the Sensor runs on DPDK.
Datasheet
| Traffic Capturing Technology: |
|
| Capacity per Sensor Instance: | 100 Gigabit Ethernet, >30 Mpackets/s, unlimited number of connections between IPs |
| DDoS Detection Time: | ≤ 1 second |
| IP Graphing Accuracy: | ≥ 5 seconds |
| Traffic Validation Options: | IP classes, MAC addresses, VLANs, BPF |
Minimum system requirements
| Capacity: | 10 Gbit/s (~14 Mpkts/s) | 40 Gbit/s (~30 Mpkts/s) |
|---|---|---|
| Architecture: | Intel Xeon 64 bit, dedicated server | Intel Xeon 64 bit, dedicated server |
| CPU: | 2.4 GHz 10-core Xeon E5-2640v4 | 2.4 GHz 12-core Xeon E5-2680v4 |
| RAM: | 8 GB DDR4 quad-channel | 16 GB DDR4 quad-channel |
| Network Cards: | 1 x 10 GbE adapter (Intel 82599+ or DPDK supported chipset) 1 x Fast Ethernet for management |
1 x 40 GbE adapter (Intel XL710+ or other DPDK supported chipset) 1 x Fast Ethernet for management |
| Operating System*: | RHEL / Rocky / Alma 9 to 10; Debian 11 to 13; Ubuntu Server 20 to 26 | RHEL / Rocky / Alma 9 to 10; Debian 11 to 13; Ubuntu Server 20 to 26 |
| Disk Space: | 10 GB (including OS) | 10 GB (including OS) |
* Other Linux distributions might work but have not yet been tested.
Full system requirements →DPDK configuration →Sensor licenses, $595 / year →DPDK Engine, $1,410 / year →
Packet Sniffing (Port Mirroring, Inline Appliances) Sensor for Wanguard and Wansight
The Packet Sensor component of Wanguard and Wansight is a packet sniffer that inspects IP packets and generates detailed traffic analytics. At its core, it contains a highly scalable traffic correlation engine capable of continuously monitoring hundreds of thousands of IP addresses. Sophisticated statistical algorithms integrate traffic data to build an accurate and detailed picture of real-time and historical traffic flows across the network.
Packet Sensor is one of four components; every one reports to the same Console. Wansight runs the same Sensor without detection and mitigation — and becomes Wanguard with a license key.
Multi-tenant, with 40+ dashboard widgets, scoped views for customers, white-label login for MSSPs, PDF and Excel exports, 10 themes including a dark mode.
NetFlow v5/v7/v9, jFlow, cflowd, NetStream, sFlow v4/v5 and IPFIX; one instance per exporter, tens of instances per server; an optional flow collector with interactive flow graphs.
Packet Filter inspects diverted or in-line packets, with deep packet inspection for payload patterns; Flow Filter derives the same rules from any Flow Sensor's flows on minimal hardware. Both apply them anywhere: local Netfilter, in-NIC filters (Intel 82599, Chelsio T5+, any DPDK Flow API card), BGP Flowspec routers or third-party appliances.
Every feature, any number of servers, 30 days — by requesting a free evaluation license. Our engineers help you set it up.
Fill in the trial form. We review it and email download links, documentation and a 30-day license within 24 hours.
Any 64-bit Intel/AMD box or VM. Packages install under /opt in minutes; size the hardware with the system requirements.
Ask us anything during the trial. When it earns its keep, buy licenses in the online store — the trial installation carries on with the new key.
Wanguard 9.0 is out (23 July 2026). Upgrading from 8.x? Read the release notes first.