The DDoS mitigation performance of Wanguard Filter

Wanguard Filter translates each detected attack pattern into filtering rules that can be applied on the server’s Netfilter stateless firewall, on the built-in DPDK Dataplane Firewall, on the network adapter’s hardware packet filter, or on third-party firewalls, routers and mitigation appliances (via helper scripts or BGP Flowspec).

These filtering methods complement each other in performance and features:

  • The Netfilter software firewall is the most flexible and supports the largest number of filtering rules. Wanguard Filter does not use the connection-tracking system specific to stateful firewalls, which ensures much better filtering performance — but, depending on the hardware, the Linux kernel may still struggle with 10 Gbps+ of small packets. The achievable rate depends on many parameters: CPU, kernel version, NIC chipset and driver, attack type, server load, interrupt balancing, number of rules, and so on.
  • The DPDK Dataplane Firewall bypasses the kernel and makes Packet Sensor and Packet Filter fast enough for inline deployments: on a single Intel Xeon 6212U CPU they can analyze, switch and filter around 50 million packets/s between two 100 Gbps interfaces. It supports more filtering rules than Flowspec, but fewer than Netfilter.
  • The hardware packet filter of NICs such as Chelsio or Mellanox drops most DDoS traffic patterns at line rate in hardware, on 10/40/100 Gbps ports, without straining the CPU — paired with such a NIC, Flow Filter can mitigate 100 Gbps attacks using almost no CPU resources. It applies a subset of the rules available to the software firewall.

When a DDoS attack saturates the uplink bandwidth or exceeds the capacity of the filtering servers, Wanguard Sensor can BGP blackhole (null-route) the attacked destinations at the upstream providers, or send a BGP Flowspec announcement that blocks the attack on the border routers. For scaling on-premise scrubbing, multiple filtering servers can be clustered into a packet-scrubbing farm that load-balances the Packet Filters.

For a detailed comparison of the deployment scenarios (out-of-line monitoring, side filtering, inline filtering), see the User Guide chapter Choosing a Method of DDoS Mitigation.

AuthorAndrisoft Team
Date Created22 January 2014
Date Updated16 August 2025
Views19,726