Wanguard watches your network through NetFlow, sFlow, IPFIX or port mirroring, detects volumetric attacks in seconds and stops them — with BGP Flowspec and RTBH on your own routers, or with line-rate packet filtering on Linux servers you already own. No appliance, no traffic leaving your network, no per-gigabit fees.
Since 2006 · trusted by 1,000+ network operators in 50+ countries








Flow and Packet Sensors feed one Console; the Filter and your own BGP routers do the mitigating. Every component is a Linux package. One license per Sensor or Filter, per year — the Console and clustering are free.
Flow Sensors collect NetFlow v5/v9, IPFIX and sFlow from any router; Packet Sensors sniff mirrored or in-line links at 10/40/100 Gbps. Dashboards, top talkers, per-IP graphs for hundreds of thousands of addresses, raw flow and packet forensics, 95th-percentile billing.
Flow Sensor · Packet Sensor · Console →The anomaly engine checks 150+ metrics against thresholds and learned baselines per host, subnet or group, spots unusual traffic spikes and names the flood — SYN, UDP, ICMP, DNS/NTP amplification, carpet bombing — the moment it starts. Every anomaly comes with a report, a graph and a packet or flow capture.
How detection works →Filter builds dynamic rules that drop only the malicious traffic — on Linux firewalls, in-NIC hardware filters, DPDK at line rate (under one second in 9.0), or pushed to BGP Flowspec routers. Or announce RTBH and divert to a scrubbing provider. No operator needed at 3 a.m.
Filter · Flowspec · RTBH →Need the visibility without the protection? Wansight is the same Sensors and Console without detection and mitigation — and becomes Wanguard with a license key, no reinstall.
Install what the network needs, on as many Linux servers as it takes. Every component is a package; every one clusters; all of them report to the same Console.
Multi-tenant, with 40+ dashboard widgets, scoped views for customers, white-label login for MSSPs, PDF and Excel exports, 10 themes including a dark mode.
NetFlow v5/v7/v9, jFlow, cflowd, NetStream, sFlow v4/v5 and IPFIX; one instance per exporter, tens of instances per server; an optional flow collector with interactive flow graphs.
libpcap, PF_RING, Netmap or DPDK; 100 GbE and more than 30 Mpps per instance, clustered across CPU cores and servers; packet captures viewable in a Wireshark-like page.
Packet Filter inspects diverted or in-line packets, with deep packet inspection for payload patterns; Flow Filter derives the same rules from any Flow Sensor's flows on minimal hardware. Both apply them anywhere: local Netfilter, in-NIC filters (Intel 82599, Chelsio T5+, any DPDK Flow API card), BGP Flowspec routers or third-party appliances.
Wanguard does not force one answer on every attack. Each IP group gets its own response, from a blackhole that costs nothing to a scrubbing server that keeps the customer online.
The Sensor or Filter announces n-tuple rules (RFC 5575) — prefix, ports, protocol, packet length — and the router drops the flood at the edge. Nothing new in the data path.
Null-route the attacked address with the community your transit providers already honour. The target goes dark; every other customer and link stays clean.
Divert the attacked prefix to a Linux scrubbing server by BGP — or run it in-line — and drop only the malicious packets in software, in the NIC or with DPDK. A Flow Filter does the same from flow data alone, on minimal hardware. Clean traffic goes back by static route or GRE/IPIP.
Announce the prefix to your ISP's or an MSSP's scrubbing service, or push ACLs and rules to the firewalls, IPSes and mitigation appliances you already own, through scripts and the REST API.
Responses are configured per IP group, per attack type and per severity. Next to mitigation they can email, send syslog to your SIEM, raise SNMP traps, notify the attacker's ISP or run your own scripts with 130+ dynamic parameters — and every rule expires when the anomaly does. Choosing a mitigation method, in the docs →
Its extremely fast and innovative traffic anomaly detection engine identifies every DDoS attack and blocks the malicious packets.
Automatically responds to attacks with routing updates (Flowspec, RTBH), emailing alerts, executing scripts, and more.
Generates detailed visual graphs, captures packets and flow records for each attack. Can email attack reports to designated recipients.
Supports all major traffic monitoring technologies: NetFlow, sFlow, IPFIX, 40/100 Gbps packet sniffing, DPDK, Netmap, PF_RING, and SNMP.
Provides consolidated management through an interactive, multi-tenant web portal with custom dashboards and user roles.
Produces advanced analytical reports with aggregated metrics across hosts, subnets, IP groups, ASNs, protocols, countries, interfaces, and more.
The software is engineered to run on low-cost commodity hardware, and all components can be clustered and distributed across multiple servers.
Integrates a comprehensive NetFlow, sFlow, and IPFIX data collector with powerful storage, searching, filtering, sorting, and export options.
Integrates a packet sniffer capable of collecting packet dumps from across the network, accessible online or available for download.
Bandwidth graphs are animated and offer short-term accuracy down to 5 seconds. Live readings are available for all parameters.
View reports covering any time range from the last 5 seconds to the last 10 years, and supports 95th percentile billing.
Any report can be generated and automatically emailed to designated recipients at scheduled intervals: hourly, daily, weekly, or monthly.
You can fine-tune every aspect of the system in great detail, including the user profiles, remote authentication, data retention, and much more.
All support inquiries are handled by skilled engineers. Enterprise Support guarantees a response time of under one hour, 24/7/365.
The most cost-effective on-premise DDoS mitigation solution, with free support and upgrades included in the annual subscription.
The long version — what the product is, what the components do, and how the protection is layered.
Andrisoft Wanguard is an award-winning, enterprise-grade software solution built to monitor and protect large WAN networks against high-volume DDoS attacks.
Unforeseen traffic patterns can degrade user experience and congest expensive transit links. Delivering reliable network services is essential to the success of modern organizations. As the business impact of network disruptions continues to grow, quickly identifying and mitigating performance and reliability threats has become critical to maintaining SLAs and ensuring network availability. These threats include Distributed Denial-of-Service (DDoS) attacks, SYN floods, NTP amplification, and various UDP or ICMP floods. Wanguard’s comprehensive, network-wide surveillance of complex, multilayer, switched, or routed environments — combined with its unique suite of features — is purpose-built to pinpoint and neutralize such threats with speed and precision.
Flow Sensor and Packet Sensor deliver in-depth traffic analysis, accounting, bandwidth monitoring, and real-time detection of traffic anomalies and DDoS attacks. The collected data enables the generation of detailed traffic reports, graphs, and top statistics; helps instantly identify the causes of network incidents; automates attack responses; reveals application performance patterns; and supports accurate capacity planning decisions.
Filter activates automatically during DoS, DDoS, or DrDoS attacks to apply intelligent filtering rules that precisely scrub malicious traffic without affecting user experience or causing downtime.
Console is a multi-tenant web application that serves as the administrative core of the Wanguard platform. It provides centralized management and reporting by consolidating data from all Sensors and Filters deployed across the network.
Sensor can announce upstream provider routes via BGP to stop routing traffic toward attacked destinations. This widely used DDoS protection technique, known as Remotely Triggered Black Hole (RTBH), requires only a simple agreement with the BGP peer(s). The attacked targets are effectively isolated from the Internet, ensuring that upstream links and other destinations remain uncongested during attacks.
Sensor can also announce routes to an upstream Internet Service Provider (ISP) or a Managed Security Service Provider (MSSP) that offers cloud-based DDoS scrubbing services, allowing malicious traffic to be cleaned before reaching the protected network.
Filter mitigates attacks locally by scrubbing and/or rate-limiting malicious packets using dynamic filtering rules applied to stateless software firewalls, in-NIC hardware packet filters, or BGP Flowspec-capable routers. Dedicated filtering servers can be clustered into high-capacity packet scrubbing farms, providing on-premises protection against attacks that do not saturate upstream links.
Filter can also send notifications to ISPs originating non-spoofed attacks and apply filtering rules or ACLs to third-party DDoS mitigation appliances, firewalls, or routers for extended defense integration.
Andrisoft Wanguard supports the sFlow standards. To learn more about sFlow please visit www.sflow.org.
Sensors listen to flows or mirrored packets, so nothing changes in the data path until you decide to mitigate.
Point your routers at a Flow Sensor, or mirror a link to a Packet Sensor. No change to how traffic flows.
Sensors analyze traffic and raise anomalies; the Console correlates them, keeps the history and runs the response actions you configured.
Filter scrubs on the server or hands rules to Flowspec routers; or RTBH and divert. Clean traffic continues. All components are Linux packages and cluster as you grow.
| Component | Covers | Minimum server | Notes |
|---|---|---|---|
| Console | the whole deployment | quad-core 2.4 GHz, 16 GB RAM, 350 GB SSD | a VM is fine; no limit on managed components |
| Flow Sensor | one flow exporter | dual-core 2.0 GHz, 8 GB RAM, 1 GbE | tens of instances per server; VMs possible, not recommended |
| Packet Sensor | one 10 / 40 Gbps link | 10 / 14-core Xeon, 8 / 32 GB, Intel 82599-class or DPDK NIC | 100 G+ with a Sensor Cluster over several servers |
| Packet Filter | 10 / 40 Gbps of scrubbing | 10 / 14-core Xeon, 8 / 32 GB, Chelsio T5+, Intel X520/XL710 or DPDK NIC | in-line or out-of-line; Filter Cluster for 100 G+ |
| Flow Filter | mitigation from flow data | minimal — runs beside the Console | rules from any Flow Sensor; 1 Tbps+ via BGP Flowspec |
| Operating system | RHEL / Rocky / AlmaLinux 9–10 · Debian 11–13 · Ubuntu Server 20–26 — 64-bit x86, packages under /opt | ||
Full system requirements →Build your own anti-DDoS appliance →
One license per Sensor or Filter, per year — standard prices in US dollars, with volume discounts on larger deployments. Support, updates and upgrades are included. Console and clusters are free.
Buy in the online store →Flow or Packet Sensor with DDoS detection. One per flow exporter (usually a router) or per packet-sensing server.
On-premise mitigation. One per Packet Filter interface; a single Flow Filter usually covers a whole network.
Add-on for each Packet Sensor or Filter running on DPDK, for the highest rates. Not needed with PF_RING or libpcap.
Standard support (email and portal, Mon–Fri) comes with every license; Priority Support is $1,000 / year and Enterprise Support (one-hour response, 24/7/365) is quoted per network. Visibility without protection: a Wansight Sensor is $345 / year and upgrades to Wanguard with a key.
Every feature, any number of servers, 30 days — by requesting a free evaluation license. Our engineers help you set it up.
Fill in the trial form. We review it and email download links, documentation and a 30-day license within 24 hours.
Any 64-bit Intel/AMD box or VM. Packages install under /opt in minutes; size the hardware with the system requirements.
Ask us anything during the trial. When it earns its keep, buy licenses in the online store — the trial installation carries on with the new key.
No. Sensors listen to flow exports or mirrored packets, so nothing changes in how traffic is forwarded. Only a Filter server sits in-line — and only if you choose in-line or side-filtering over Flowspec and RTBH.
Packet Sensors detect in one second or less; Flow Sensors within your exporter's flow export time plus a second or two. Packet Filter detects and applies filtering rules in under a second, Flow Filter in five to ten; Flowspec and RTBH announcements leave the moment the anomaly triggers.
Wanguard Filter is stateless on purpose: it survives the volumetric floods that exhaust stateful firewalls and IPSes, and blocks volumetric and protocol floods — including payload patterns found by deep packet inspection. Slow, low-volume HTTP attacks are not its job; keep a WAF or IPS behind it.
Threshold anomalies need no training period — they protect from day one. Only profile anomalies build their traffic baselines over the first days, automatically. Every response — Flowspec, RTBH, Filter, scripts — is automatic; operators can still classify, comment and override from the Console.
64-bit x86 servers running RHEL / Rocky / AlmaLinux 9–10, Debian 11–13 or Ubuntu Server 20–26; packages install under /opt. The Console and Flow Sensors run happily in VMs; Packet Sensors and Filters want a dedicated server with a supported NIC.
One license per Sensor or Filter, per year, with support and upgrades included; the Console, clusters and any number of users are free. The Console is multi-tenant: customers and departments get scoped accounts, and MSSPs can white-label the portal.
More questions? Talk to an engineer →
Wanguard 9.0 is out (23 July 2026). Upgrading from 8.x? Read the release notes first.