Wanguard Filter is the DDoS traffic analyzer and intelligent firewall-rules generator of Wanguard. Working from a Packet Sensor (in-line, port mirroring, TAP) or a Flow Sensor (NetFlow, sFlow, jFlow, IPFIX), it recognizes malicious traffic in under a second and filters it granularly, in-line or on diverted traffic — in software, in the NIC, with DPDK, or on BGP Flowspec routers — without baseline training, without an operator, and without taking the customer down.
Wanguard overviewMitigation methodsFilter licenses
rules in < 5 s (< 1 s on DPDK) · 10–40 Gbps per server · clusters to 100 G+
Filter is stateless on purpose: it keeps working through the volumetric floods that exhaust stateful firewalls, IDSes and IPSes, and it sits at the network's entry points, before them.
Analyzes IP packets (VLAN and MPLS included) or NetFlow, sFlow and IPFIX flow data, with deep packet inspection for patterns inside payloads. Known, unknown and evolving DoS, DDoS and volumetric attacks are recognized and blocked in under a second — with no network baseline training and no operator intervention. Designed for asymmetric routing; a SYN proxy against spoofed SYN, SYN-ACK and ACK floods; optional third-party reputation blacklists.
Anomaly mitigation in the docs →Rules on any combination of source and destination IPv4/IPv6 addresses, TCP and UDP ports, IP protocols, invalid IP headers, ICMP types, common TTL values, packet lengths, payloads, country, DNS transaction ID. Applied by the Netfilter framework or an embedded firewall in software; in the NIC on Intel 82599 (X520, X540, HP 560), Chelsio T5+ at 10/40/100 Gbps, or any DPDK Flow API card; on BGP Flowspec-capable routers; or on third-party firewalls, IPSes and load balancers through the API or scripts.
The Firewall page in the docs →Per-endpoint threat management and an API for scripting the reaction: alert the NOC, the customer or the attacker's ISP with your email templates; syslog to log servers and SIEMs; capture a sample of the attacker's traffic for forensics and legal evidence; run your scripts — ACLs or “shun” commands on routers and PIX firewalls, “route blackhole” on Linux servers, SNMP traps to monitoring stations.
Response actions in the docs →Cleaning servers run in-line or scrub traffic brought to them by BGP off-/on-ramping (sinkhole routing), S/RTBH or Flowspec; cleaned traffic goes back downstream by static routing or GRE/IPIP tunneling. Flow Filter needs no powerful server at all: it detects the same filtering rules from Flow Sensor data and applies them through the same backends — Netfilter, in-NIC, Flowspec or third-party devices; over BGP Flowspec a single instance can mitigate attacks above 1 Tbps. One license per Packet Filter interface, $995 a year — the most affordable on-premise anti-DDoS software on the market.
Side filtering is the usual one: the Filter announces itself as next hop for the attacked prefix, scrubs, and routes the clean traffic back. The others cover in-line links, mirror ports and the servers themselves.

Choosing a method of DDoS mitigation, in the docs → · Network integration guideline →
The filtering methods complement each other — software rules are the most flexible, in-NIC filters drop at wire speed without loading the CPU, Flowspec moves the drop to the routers — and Filters cluster when one server is not enough.
The traffic-filtering methods directly supported by Wanguard Filter complement each other, performance-wise and feature-wise:
The stateless operation of Wanguard Filter ensures the detection and mitigation of volumetric attacks that may cripple even the most powerful stateful devices, such as firewalls, Intrusion Detection Systems (IDS) or Intrusion Protection Systems (IPS). The disadvantage of the stateless operation is that non-volumetric application layer (OSI Layer 7) attacks cannot be blocked, unlike traditional IPSes. Wanguard Filter should be installed on the network's entry points, before other stateful devices.
To increase the packet filtering capacity to 100 Gbit/s or more, you can cluster multiple Packet Filters deployed on different servers with 10+ Gbit/s network adapters. To split the traffic, you can use a hardware load balancer or equal-cost multipath routing.
When a DDoS attack saturates the uplink bandwidth or is above the capacity of the filtering server(s), Sensor can BGP black-hole/null-route the attacked destinations.
Minimum system requirements
| 10 Gbps (~14 Mpps) mitigation | 40 Gbps (~30 Mpps) mitigation | |
|---|---|---|
| Topology: | In-line or out-of-line | Out-of-line recommended |
| CPU: | 2.4 GHz 10-core Intel Xeon E5-2640v4 | 2.4 GHz 14-core Intel Xeon E5-2690v4 |
| RAM: | 8 GB DDR4 quad-channel | 16 GB DDR4 quad-channel |
| Network Cards: | 1 x 10 GbE card (Chelsio T5+, Intel X520+, other DPDK-supported NIC) 1 x Gigabit Ethernet |
1 x 40 GbE card (Chelsio T5+, Intel XL710+, other DPDK-supported NICs) 1 x Gigabit Ethernet |
| Operating System: | RHEL/Rocky/Alma 8 to 10; Debian 10 to 13; Ubuntu 18 to 24 | RHEL/Rocky/Alma 8 to 10; Debian 10 to 13; Ubuntu 18 to 24 |
| Disk Space: | 10 GB (including OS) | 10 GB (including OS) |
Full system requirements →DPDK configuration →Filter licenses, $995 / year →DPDK Engine, $1,410 / year →
DDoS attack mitigation with Wanguard Filter
The Filter component of Wanguard is a DDoS traffic analyzer and intelligent firewall rules generator designed to protect networks from internal and external threats (availability attacks on DNS, VoIP, Mail and similar services, unauthorized traffic resulting in network congestion). It includes sophisticated traffic analysis algorithms that can detect and side-filter malicious traffic in a granular manner, without impacting the user experience or resulting in downtime.
Wanguard Filter works in cooperation with Packet Sensor (for in-line servers, port mirroring or network TAPs) or Flow Sensor (for NetFlow, sFlow, jFlow or IPFIX).
Filter works with the Packet Sensor or the Flow Sensor and reports to the same Console as everything else. Wansight — the same Sensors and Console without detection and mitigation — has no Filter.
Multi-tenant, with 40+ dashboard widgets, scoped views for customers, white-label login for MSSPs, PDF and Excel exports, 10 themes including a dark mode.
NetFlow v5/v7/v9, jFlow, cflowd, NetStream, sFlow v4/v5 and IPFIX; one instance per exporter, tens of instances per server; an optional flow collector with interactive flow graphs.
libpcap, PF_RING, Netmap or DPDK; 100 GbE and more than 30 Mpps per instance, clustered across CPU cores and servers; packet captures viewable in a Wireshark-like page.
Every feature, any number of servers, 30 days — by requesting a free evaluation license. Our engineers help you set it up.
Fill in the trial form. We review it and email download links, documentation and a 30-day license within 24 hours.
Any 64-bit Intel/AMD box or VM. Packages install under /opt in minutes; size the hardware with the system requirements.
Ask us anything during the trial. When it earns its keep, buy licenses in the online store — the trial installation carries on with the new key.
Wanguard 9.0 is out (23 July 2026). Upgrading from 8.x? Read the release notes first.