The Console is the web application that runs Wanguard and Wansight: it collects what every Flow Sensor, Packet Sensor and Filter sees, draws the graphs in your browser, keeps the history, runs the response actions — and gives each operator, customer and script exactly the view it should have.
No license · unlimited users · no limit on managed Sensors and Filters
Every graph and chart is drawn in the browser — click to zoom, animated, with tooltips — so an operator moves from a dashboard tile to the flows behind it to the rule that fixed it without changing tools.
Dashboards you build from 40+ widgets — content-driven columns or a free 12-column grid, title bars on or off, per-dashboard time range and refresh down to five seconds. Predefined dashboards for networks, services, servers and components get you started; live tops and animated bandwidth graphs with 95th-percentile values for billing.
Dashboards in the docs →Any report from the last five seconds to the last ten years; SQL-style row filters on every grid, with K/M/G suffixes, to narrow thousands of records to the ones that matter. Flows in the Flow Collector page, packets in a Wireshark-like Packet Tracer — hex and ASCII for your regular expressions — and Sankey, heatmap and stacked flow graphs from ClickHouse.
Flows and packets in the docs →Configure Sensors, Filters, IP Zones, thresholds and responses in one place, with contextual help and a wizard. Send BGP and Flowspec updates for blackholes from the BGP Operations page — bgpd is managed from the UI. Watch the CPU, RAM, NIC and disk of every server and get alerted on errors and overload.
BGP operations in the docs →Role-based access for an unlimited number of users with fine-grained security profiles. Customers and departments see only their own traffic and alerts; operators create profiles inside their scope; MSSPs get a login page and branding of their own.
Authentication is local, Single Sign-On with SAML 2.0, or cascaded LDAP, Active Directory and RADIUS — with built-in LDAP and RADIUS testers that validate the configuration before it is saved. Perpetual cookie-based sessions are optional.
Any report on a schedule — hourly, daily, weekly, monthly — to the people who need it; every report exports to PDF, every grid to Excel.
Navigate flow records with summaries and statistics; save, search, filter, sort and export the flows behind any graph.
Capture packets in a few clicks and read the dump online, Wireshark-style — raw hex and ASCII for inclusion in regular expressions — or download it.
Send BGP and Flowspec prefix updates for remotely-triggered blackholes from the page; bgpd is configured and managed from the web interface.
Processed traffic, CPU, RAM and NIC usage of every server, with alerts on process errors, CPU load, memory, or a disk over 95% full.
Ten UI themes including a dark mode and two icon sets; white-label branding; bookmarks for data you re-enter often and a Quick Search into any report.
IP information — reverse DNS, AS, ISP, country, ping, traceroute, whois; lists of autonomous systems, ports and protocols; an IPv4/IPv6 subnet calculator; a world clock.
Configuration and events in an SQL database you can query, back up and restore; graphs, profiles and flows can additionally go to ClickHouse, free of InfluxDB's cardinality limits.
Drive IP Zones and Sensors from the command line or your scripts, or the whole configuration through the REST API; contextual documentation on every screen.
The Console server holds the database and centralizes the operational logs, graphs and IP accounting data. It has no limit on the number of managed components; its speed follows the server and the software it relies on — MariaDB, Apache, PHP, ClickHouse and InfluxDB.
| Minimum | Console server | Notes |
|---|---|---|
| Architecture | 64-bit x86 server; a virtual machine is fine | fast, uninterrupted disk access matters most |
| CPU · RAM | 2.4 GHz quad-core Xeon · 16 GB | more RAM for ClickHouse and many concurrent users |
| Network cards · disk space | Gigabit Ethernet · 350 GB on RAID 1, SSD recommended | size graph storage by retention and monitored IPs |
| Operating system | RHEL / Rocky / AlmaLinux 9–10 · Debian 11–13 · Ubuntu Server 20–26 | other distributions may work, untested |
| Browsers | Chrome 64+, Firefox 52+, Edge 12+, Opera 43+ — JavaScript and cookies on, no Java, no Flash | best in Chrome at 1280×1024 or more |
Full system requirements →Installation guide →Build your own appliance →
Web User Interface for Wanguard
Console is an OS-independent, web-based application that provides centralized management and reporting for all Wanguard and Wansight components. It aggregates and correlates data from distributed Flow Sensors, Packet Sensors, and Filters, offering a unified operational view of traffic monitoring and network security.
The interface is tightly integrated, highly graphical, and fully interactive, enabling efficient navigation across all monitoring, analysis, and configuration functions. Its graph rendering engine draws every graph and chart directly in the browser, supporting click-to-zoom, animations and rich tooltips, so operators can quickly investigate anomalies, assess network behavior, and validate mitigation actions.
Install what the network needs, on as many Linux servers as it takes; every one reports to this Console. Wansight uses the same Console and the same Sensors, without detection and mitigation.
NetFlow v5/v7/v9, jFlow, cflowd, NetStream, sFlow v4/v5 and IPFIX; one instance per exporter, tens of instances per server; an optional flow collector with interactive flow graphs.
libpcap, PF_RING, Netmap or DPDK; 100 GbE and more than 30 Mpps per instance, clustered across CPU cores and servers; packet captures viewable in a Wireshark-like page.
Packet Filter inspects diverted or in-line packets, with deep packet inspection for payload patterns; Flow Filter derives the same rules from any Flow Sensor's flows on minimal hardware. Both apply them anywhere: local Netfilter, in-NIC filters (Intel 82599, Chelsio T5+, any DPDK Flow API card), BGP Flowspec routers or third-party appliances.
Every feature, any number of servers, 30 days — by requesting a free evaluation license. Our engineers help you set it up.
Fill in the trial form. We review it and email download links, documentation and a 30-day license within 24 hours.
Any 64-bit Intel/AMD box or VM. Packages install under /opt in minutes; size the hardware with the system requirements.
Ask us anything during the trial. When it earns its keep, buy licenses in the online store — the trial installation carries on with the new key.
Wanguard 9.0 is out (23 July 2026). Upgrading from 8.x? Read the release notes first.