Packet Sensor is the component of Wanguard and Wansight that inspects IP packets — from SPAN or RSPAN port mirroring, a network TAP, or a server in the main data path — with libpcap, PF_RING, Netmap or DPDK, at 100 GbE and more than 30 million packets per second per instance. Five-second graphs, one-second detection, packet captures you read in a Wireshark-like page, and the same per-endpoint responses as the Flow Sensor.
Wanguard overviewFlows or packets?Sensor licenses
100 GbE · > 30 Mpps per instance · detects in ≤ 1 s · graphs every 5 s
At its core, the same scalable traffic-correlation engine as the Flow Sensor — monitoring hundreds of thousands of IPv4 and IPv6 addresses and ranges — fed by packets instead of flow records, so it sees everything and sees it first.
Traffic accounting and per-IP, per-subnet or per-IP-group graphs for 50+ decoders — IP, the TCP flag combinations, UDP, ICMP, fragments, QUIC, DNS, NTP, SNMP, SSDP, memcached, GRE, IPv4/IPv6, YouTube, Netflix and your own. Tops and graphs for talkers, external IPs, IP groups, autonomous systems and transit ASes, countries, ports and protocols; graphs as fine as five seconds, history for as many years as you keep.
IP reports in the docs →With a Wanguard license: DDoS and unknown volumetric DoS; NTP amplification, UDP, ICMP and SMURF floods; SYN floods, TCP/UDP port 0, LOIC, peer-to-peer attacks; scans and worms hitting illegal or unallocated addresses; traffic missing from critical services. Anomaly checks every second — or every five — and a capture of the attacking traffic for the forensics.
How detection works →Activate on-premise mitigation with Wanguard Filter; announce RTBH blackholes with Flowspec (RFC 5575) or null-routing communities; send BGP off-/on-ramp diversion to an on-premise or cloud scrubber; email alerts from dynamic templates; syslog to your SIEM; capture a sample of the traffic; or run your scripts through an API exposing 130+ parameters.
Response actions in the docs →Flows or packets? A Flow Sensor needs no extra hardware and tens of them share a server; the Packet Sensor needs a mirror port, a TAP or a place in the data path, and in return detects in one second with five-second graphs. Many networks run both — choosing a method of traffic monitoring.
The Packet Sensor runs as a passive sniffer, or as a transparent bridge or pseudo-Layer-3 device that forwards packets between its ports. It scales by running load-balanced across CPU cores and across servers, and reads the encapsulations carriers actually use.
Packet dumps can be downloaded or viewed online in a Wireshark-like interface, with raw hexadecimal and ASCII for inclusion in regular expressions — for forensic investigation, network-wide situational awareness and troubleshooting.
The datasheet and the two reference servers — 10 and 40 Gbit/s — as the specification sheet has them; the DPDK engine license is needed on top of the Sensor license only when the Sensor runs on DPDK.
Datasheet
| Traffic Capturing Technology: |
|
| Capacity per Sensor Instance: | 100 Gigabit Ethernet, >30 Mpackets/s, unlimited number of connections between IPs |
| DDoS Detection Time: | ≤ 1 second |
| IP Graphing Accuracy: | ≥ 5 seconds |
| Traffic Validation Options: | IP classes, MAC addresses, VLANs, BPF |
Minimum system requirements
| Capacity: | 10 Gbit/s (~14 Mpkts/s) | 40 Gbit/s (~30 Mpkts/s) |
|---|---|---|
| Architecture: | Intel Xeon 64 bit, dedicated server | Intel Xeon 64 bit, dedicated server |
| CPU: | 2.4 GHz 10-core Xeon E5-2640v4 | 2.4 GHz 12-core Xeon E5-2680v4 |
| RAM: | 8 GB DDR4 quad-channel | 16 GB DDR4 quad-channel |
| Network Cards: | 1 x 10 GbE adapter (Intel 82599+ or DPDK supported chipset) 1 x Fast Ethernet for management |
1 x 40 GbE adapter (Intel XL710+ or other DPDK supported chipset) 1 x Fast Ethernet for management |
| Operating System*: | RHEL / Rocky / Alma 9 to 10; Debian 11 to 13; Ubuntu Server 20 to 26 | RHEL / Rocky / Alma 9 to 10; Debian 11 to 13; Ubuntu Server 20 to 26 |
| Disk Space: | 10 GB (including OS) | 10 GB (including OS) |
* Other Linux distributions might work but have not yet been tested.
Full system requirements →DPDK configuration →Sensor licenses, $595 / year →DPDK Engine, $1,410 / year →
Packet Sniffing (Port Mirroring, Inline Appliances) Sensor for Wanguard and Wansight
The Packet Sensor component of Wanguard and Wansight is a packet sniffer that inspects IP packets and generates detailed traffic analytics. At its core, it contains a highly scalable traffic correlation engine capable of continuously monitoring hundreds of thousands of IP addresses. Sophisticated statistical algorithms integrate traffic data to build an accurate and detailed picture of real-time and historical traffic flows across the network.
Packet Sensor is one of four components; every one reports to the same Console. Wansight runs the same Sensor without detection and mitigation — and becomes Wanguard with a license key.
Multi-tenant, with 40+ dashboard widgets, scoped views for customers, white-label login for MSSPs, PDF and Excel exports, 10 themes including a dark mode.
NetFlow v5/v7/v9, jFlow, cflowd, NetStream, sFlow v4/v5 and IPFIX; one instance per exporter, tens of instances per server; an optional flow collector with interactive flow graphs.
Packet Filter inspects diverted or in-line packets, with deep packet inspection for payload patterns; Flow Filter derives the same rules from any Flow Sensor's flows on minimal hardware. Both apply them anywhere: local Netfilter, in-NIC filters (Intel 82599, Chelsio T5+, any DPDK Flow API card), BGP Flowspec routers or third-party appliances.
Every feature, any number of servers, 30 days — by requesting a free evaluation license. Our engineers help you set it up.
Fill in the trial form. We review it and email download links, documentation and a 30-day license within 24 hours.
Any 64-bit Intel/AMD box or VM. Packages install under /opt in minutes; size the hardware with the system requirements.
Ask us anything during the trial. When it earns its keep, buy licenses in the online store — the trial installation carries on with the new key.
Wanguard 9.0 is out (23 July 2026). Upgrading from 8.x? Read the release notes first.