Wanguard 9.0 · July 2026 · what's new →

On-premise DDoS detection and mitigation software.

Wanguard watches your network through NetFlow, sFlow, IPFIX or port mirroring, detects volumetric attacks in seconds and stops them — with BGP Flowspec and RTBH on your own routers, or with line-rate packet filtering on Linux servers you already own. No appliance, no traffic leaving your network, no per-gigabit fees.

Since 2006 · trusted by 1,000+ network operators in 50+ countries

How Wanguard deploys: Sensor and Filter run on Linux servers beside your border router Console Wanguard — Linux packages on servers you already have Internet Your border router unchanged · BGP peer Your servers or your entire network all traffic incl. attacks clean traffic Sensor sees every flow and packet signals your routers via BGP Filter scrubs diverted attack traffic at line rate, on this server flows · packetsBGPattack trafficclean
  1. Your routers keep forwarding as today.They export NetFlow, sFlow or IPFIX to a Sensor — or you mirror a link.
  2. Wanguard Sensor sees every flow and packet.It raises anomalies and signals your routers via BGP Flowspec, RTBH or diversion.
  3. Wanguard Filter scrubs the diverted traffic.At line rate, on a Linux server, and hands the clean traffic back.
  4. Your network and servers stay reachable.No appliance in the path, no traffic leaving your network, no per-gigabit fees.
flows & packets to the SensorBGP signalling back to the routerattack traffic diverted to the Filterclean traffic delivered
Protects the networks of More customers →
Google FiberVodafoneIBMHuaweiEquinixMozillaDigitalOceanNamecheap

Visibility, detection and mitigation in one product

Flow and Packet Sensors feed one Console; the Filter and your own BGP routers do the mitigating. Every component is a Linux package. One license per Sensor or Filter, per year — the Console and clustering are free.

See all your traffic

Flow Sensors collect NetFlow v5/v9, IPFIX and sFlow from any router; Packet Sensors sniff mirrored or in-line links at 10/40/100 Gbps. Dashboards, top talkers, per-IP graphs for hundreds of thousands of addresses, raw flow and packet forensics, 95th-percentile billing.

Flow Sensor · Packet Sensor · Console

Detect attacks in seconds

The anomaly engine checks 150+ metrics against thresholds and learned baselines per host, subnet or group, spots unusual traffic spikes and names the flood — SYN, UDP, ICMP, DNS/NTP amplification, carpet bombing — the moment it starts. Every anomaly comes with a report, a graph and a packet or flow capture.

How detection works →

Mitigate on-premise, automatically

Filter builds dynamic rules that drop only the malicious traffic — on Linux firewalls, in-NIC hardware filters, DPDK at line rate (under one second in 9.0), or pushed to BGP Flowspec routers. Or announce RTBH and divert to a scrubbing provider. No operator needed at 3 a.m.

Filter · Flowspec · RTBH →

Need the visibility without the protection? Wansight is the same Sensors and Console without detection and mitigation — and becomes Wanguard with a license key, no reinstall.

Four components, one Console

Install what the network needs, on as many Linux servers as it takes. Every component is a package; every one clusters; all of them report to the same Console.

Console

The workbench

Web UI, reports, dashboards, users and the API — the brain of the deployment.

Multi-tenant, with 40+ dashboard widgets, scoped views for customers, white-label login for MSSPs, PDF and Excel exports, 10 themes including a dark mode.

License
free, unlimited users
Auth
SAML 2.0, LDAP/AD, RADIUS
Automation
REST API, CLI, scripts
Console in detail →
Flow Sensor

Listens to routers

Collects and analyzes the flows your routers already export.

NetFlow v5/v7/v9, jFlow, cflowd, NetStream, sFlow v4/v5 and IPFIX; one instance per exporter, tens of instances per server; an optional flow collector with interactive flow graphs.

Per instance
1 exporter, tens of 10/40/100 GbE ports
Detection
≤ export time + 5 s
License
$595 / year
Flow Sensor in detail →
Packet Sensor

Sniffs the wire

Inspects packets from a mirror port, a TAP or an in-line link.

libpcap, PF_RING, Netmap or DPDK; 100 GbE and more than 30 Mpps per instance, clustered across CPU cores and servers; packet captures viewable in a Wireshark-like page.

Per instance
100 GbE, > 30 Mpps
Detection
≤ 1 s
License
$595 / year
Packet Sensor in detail →
Filter

Scrubs the attack

Turns an anomaly into precise filtering rules, then applies them.

Packet Filter inspects diverted or in-line packets, with deep packet inspection for payload patterns; Flow Filter derives the same rules from any Flow Sensor's flows on minimal hardware. Both apply them anywhere: local Netfilter, in-NIC filters (Intel 82599, Chelsio T5+, any DPDK Flow API card), BGP Flowspec routers or third-party appliances.

Packet Filter
10–40 Gbps per server, rules < 1 s
Flow Filter
1 Tbps+ via Flowspec, rules 5–10 s
License
$995 / year
Filter in detail →

Mitigate where it makes sense — per prefix, per attack

Wanguard does not force one answer on every attack. Each IP group gets its own response, from a blackhole that costs nothing to a scrubbing server that keeps the customer online.

On your routers

BGP Flowspec

The Sensor or Filter announces n-tuple rules (RFC 5575) — prefix, ports, protocol, packet length — and the router drops the flood at the edge. Nothing new in the data path.

Fits when: your edge routers speak Flowspec.
At your upstreams

RTBH blackhole

Null-route the attacked address with the community your transit providers already honour. The target goes dark; every other customer and link stays clean.

Fits when: the attack is bigger than your links.
On your servers

Wanguard Filter

Divert the attacked prefix to a Linux scrubbing server by BGP — or run it in-line — and drop only the malicious packets in software, in the NIC or with DPDK. A Flow Filter does the same from flow data alone, on minimal hardware. Clean traffic goes back by static route or GRE/IPIP.

Fits when: the customer must stay online through the attack.
Third parties

Cloud & appliances

Announce the prefix to your ISP's or an MSSP's scrubbing service, or push ACLs and rules to the firewalls, IPSes and mitigation appliances you already own, through scripts and the REST API.

Fits when: you already pay for scrubbing, or own a box.

Responses are configured per IP group, per attack type and per severity. Next to mitigation they can email, send syslog to your SIEM, raise SNMP traps, notify the attacker's ISP or run your own scripts with 130+ dynamic parameters — and every rule expires when the anomaly does. Choosing a mitigation method, in the docs →

Key features and benefits

DDoS Detection & Mitigation

Its extremely fast and innovative traffic anomaly detection engine identifies every DDoS attack and blocks the malicious packets.

Powerful Reaction Tools

Automatically responds to attacks with routing updates (Flowspec, RTBH), emailing alerts, executing scripts, and more.

Detailed Forensics

Generates detailed visual graphs, captures packets and flow records for each attack. Can email attack reports to designated recipients.

Full Network Visibility

Supports all major traffic monitoring technologies: NetFlow, sFlow, IPFIX, 40/100 Gbps packet sniffing, DPDK, Netmap, PF_RING, and SNMP.

Advanced Web Console

Provides consolidated management through an interactive, multi-tenant web portal with custom dashboards and user roles.

Complex Analytics

Produces advanced analytical reports with aggregated metrics across hosts, subnets, IP groups, ASNs, protocols, countries, interfaces, and more.

Fast & Completely Scalable

The software is engineered to run on low-cost commodity hardware, and all components can be clustered and distributed across multiple servers.

Flow Analyzer and Collector

Integrates a comprehensive NetFlow, sFlow, and IPFIX data collector with powerful storage, searching, filtering, sorting, and export options.

Distributed Packet Sniffer

Integrates a packet sniffer capable of collecting packet dumps from across the network, accessible online or available for download.

Real-Time Reporting

Bandwidth graphs are animated and offer short-term accuracy down to 5 seconds. Live readings are available for all parameters.

Historical Reporting

View reports covering any time range from the last 5 seconds to the last 10 years, and supports 95th percentile billing.

Scheduled Reporting

Any report can be generated and automatically emailed to designated recipients at scheduled intervals: hourly, daily, weekly, or monthly.

Flexible Configuration

You can fine-tune every aspect of the system in great detail, including the user profiles, remote authentication, data retention, and much more.

Outstanding Support

All support inquiries are handled by skilled engineers. Enterprise Support guarantees a response time of under one hour, 24/7/365.

Affordable On Premise Anti-DDoS

The most cost-effective on-premise DDoS mitigation solution, with free support and upgrades included in the annual subscription.

Wanguard in detail

The long version — what the product is, what the components do, and how the protection is layered.

Andrisoft Wanguard is an award-winning, enterprise-grade software solution built to monitor and protect large WAN networks against high-volume DDoS attacks.

Unforeseen traffic patterns can degrade user experience and congest expensive transit links. Delivering reliable network services is essential to the success of modern organizations. As the business impact of network disruptions continues to grow, quickly identifying and mitigating performance and reliability threats has become critical to maintaining SLAs and ensuring network availability. These threats include Distributed Denial-of-Service (DDoS) attacks, SYN floods, NTP amplification, and various UDP or ICMP floods. Wanguard’s comprehensive, network-wide surveillance of complex, multilayer, switched, or routed environments — combined with its unique suite of features — is purpose-built to pinpoint and neutralize such threats with speed and precision.

Main components overview

Flow Sensor and Packet Sensor deliver in-depth traffic analysis, accounting, bandwidth monitoring, and real-time detection of traffic anomalies and DDoS attacks. The collected data enables the generation of detailed traffic reports, graphs, and top statistics; helps instantly identify the causes of network incidents; automates attack responses; reveals application performance patterns; and supports accurate capacity planning decisions.

Filter activates automatically during DoS, DDoS, or DrDoS attacks to apply intelligent filtering rules that precisely scrub malicious traffic without affecting user experience or causing downtime.

Console is a multi-tenant web application that serves as the administrative core of the Wanguard platform. It provides centralized management and reporting by consolidating data from all Sensors and Filters deployed across the network.

Multi-level DDoS protection technology

Sensor can announce upstream provider routes via BGP to stop routing traffic toward attacked destinations. This widely used DDoS protection technique, known as Remotely Triggered Black Hole (RTBH), requires only a simple agreement with the BGP peer(s). The attacked targets are effectively isolated from the Internet, ensuring that upstream links and other destinations remain uncongested during attacks.

Sensor can also announce routes to an upstream Internet Service Provider (ISP) or a Managed Security Service Provider (MSSP) that offers cloud-based DDoS scrubbing services, allowing malicious traffic to be cleaned before reaching the protected network.

Filter mitigates attacks locally by scrubbing and/or rate-limiting malicious packets using dynamic filtering rules applied to stateless software firewalls, in-NIC hardware packet filters, or BGP Flowspec-capable routers. Dedicated filtering servers can be clustered into high-capacity packet scrubbing farms, providing on-premises protection against attacks that do not saturate upstream links.

Filter can also send notifications to ISPs originating non-spoofed attacks and apply filtering rules or ACLs to third-party DDoS mitigation appliances, firewalls, or routers for extended defense integration.

Andrisoft Wanguard supports the sFlow standards. To learn more about sFlow please visit www.sflow.org.

Deploys beside your routers, not in front of them

Sensors listen to flows or mirrored packets, so nothing changes in the data path until you decide to mitigate.

1

Export flows or mirror packets

Point your routers at a Flow Sensor, or mirror a link to a Packet Sensor. No change to how traffic flows.

2

Sensors detect, Console decides

Sensors analyze traffic and raise anomalies; the Console correlates them, keeps the history and runs the response actions you configured.

3

Mitigate where it makes sense

Filter scrubs on the server or hands rules to Flowspec routers; or RTBH and divert. Clean traffic continues. All components are Linux packages and cluster as you grow.

ComponentCoversMinimum serverNotes
Consolethe whole deploymentquad-core 2.4 GHz, 16 GB RAM, 350 GB SSDa VM is fine; no limit on managed components
Flow Sensorone flow exporterdual-core 2.0 GHz, 8 GB RAM, 1 GbEtens of instances per server; VMs possible, not recommended
Packet Sensorone 10 / 40 Gbps link10 / 14-core Xeon, 8 / 32 GB, Intel 82599-class or DPDK NIC100 G+ with a Sensor Cluster over several servers
Packet Filter10 / 40 Gbps of scrubbing10 / 14-core Xeon, 8 / 32 GB, Chelsio T5+, Intel X520/XL710 or DPDK NICin-line or out-of-line; Filter Cluster for 100 G+
Flow Filtermitigation from flow dataminimal — runs beside the Consolerules from any Flow Sensor; 1 Tbps+ via BGP Flowspec
Operating systemRHEL / Rocky / AlmaLinux 9–10 · Debian 11–13 · Ubuntu Server 20–26 — 64-bit x86, packages under /opt

Full system requirements →Build your own anti-DDoS appliance →

Pricing you can read without a sales call

One license per Sensor or Filter, per year — standard prices in US dollars, with volume discounts on larger deployments. Support, updates and upgrades are included. Console and clusters are free.

Buy in the online store →
$595 / year

Flow or Packet Sensor with DDoS detection. One per flow exporter (usually a router) or per packet-sensing server.

$995 / year

On-premise mitigation. One per Packet Filter interface; a single Flow Filter usually covers a whole network.

$1,410 / year

Add-on for each Packet Sensor or Filter running on DPDK, for the highest rates. Not needed with PF_RING or libpcap.

Standard support (email and portal, Mon–Fri) comes with every license; Priority Support is $1,000 / year and Enterprise Support (one-hour response, 24/7/365) is quoted per network. Visibility without protection: a Wansight Sensor is $345 / year and upgrades to Wanguard with a key.

Try the full product on your own hardware

Every feature, any number of servers, 30 days — by requesting a free evaluation license. Our engineers help you set it up.

Request a trial key
Debian 11–13Ubuntu 20–26RHEL 9–10RockyAlmaLinux
1

Request a key

Fill in the trial form. We review it and email download links, documentation and a 30-day license within 24 hours.

2

Install on a spare Linux server

Any 64-bit Intel/AMD box or VM. Packages install under /opt in minutes; size the hardware with the system requirements.

3

Run it for real, then buy

Ask us anything during the trial. When it earns its keep, buy licenses in the online store — the trial installation carries on with the new key.

Questions engineers ask before the trial

Does Wanguard have to sit in the data path?

No. Sensors listen to flow exports or mirrored packets, so nothing changes in how traffic is forwarded. Only a Filter server sits in-line — and only if you choose in-line or side-filtering over Flowspec and RTBH.

How fast is detection and mitigation?

Packet Sensors detect in one second or less; Flow Sensors within your exporter's flow export time plus a second or two. Packet Filter detects and applies filtering rules in under a second, Flow Filter in five to ten; Flowspec and RTBH announcements leave the moment the anomaly triggers.

Does it stop application-layer (Layer 7) attacks?

Wanguard Filter is stateless on purpose: it survives the volumetric floods that exhaust stateful firewalls and IPSes, and blocks volumetric and protocol floods — including payload patterns found by deep packet inspection. Slow, low-volume HTTP attacks are not its job; keep a WAF or IPS behind it.

Does it need baseline training, or an operator at 3 a.m.?

Threshold anomalies need no training period — they protect from day one. Only profile anomalies build their traffic baselines over the first days, automatically. Every response — Flowspec, RTBH, Filter, scripts — is automatic; operators can still classify, comment and override from the Console.

Which Linux distributions and hardware?

64-bit x86 servers running RHEL / Rocky / AlmaLinux 9–10, Debian 11–13 or Ubuntu Server 20–26; packages install under /opt. The Console and Flow Sensors run happily in VMs; Packet Sensors and Filters want a dedicated server with a supported NIC.

How is it licensed — and can our customers log in?

One license per Sensor or Filter, per year, with support and upgrades included; the Console, clusters and any number of users are free. The Console is multi-tenant: customers and departments get scoped accounts, and MSSPs can white-label the portal.

More questions? Talk to an engineer →

Already running Wanguard?

Wanguard 9.0 is out (23 July 2026). Upgrading from 8.x? Read the release notes first.