Hardware Configuration · Filter

The DDoS mitigation performance of Wanguard Filter

Wanguard Filter translates each detected attack pattern into filtering rules that can be applied on the server’s Netfilter stateless firewall, on the built-in DPDK Dataplane Firewall, on the network adapter’s hardware packet filter, or on third-party firewalls, routers and mitigation appliances (via helper scripts or BGP Flowspec).

These filtering methods complement each other in performance and features:

  • The Netfilter software firewall is the most flexible and supports the largest number of filtering rules. Wanguard Filter does not use the connection-tracking system specific to stateful firewalls, which ensures much better filtering performance — but, depending on the hardware, the Linux kernel may still struggle with 10 Gbps+ of small packets. The achievable rate depends on many parameters: CPU, kernel version, NIC chipset and driver, attack type, server load, interrupt balancing, number of rules, and so on.
  • The DPDK Dataplane Firewall bypasses the kernel and makes Packet Sensor and Packet Filter fast enough for inline deployments: on a single Intel Xeon 6212U CPU they can analyze, switch and filter around 50 million packets/s between two 100 Gbps interfaces. It supports more filtering rules than Flowspec, but fewer than Netfilter.
  • The hardware packet filter of NICs such as Chelsio or Mellanox drops most DDoS traffic patterns at line rate in hardware, on 10/40/100 Gbps ports, without straining the CPU — paired with such a NIC, Flow Filter can mitigate 100 Gbps attacks using almost no CPU resources. It applies a subset of the rules available to the software firewall.

When a DDoS attack saturates the uplink bandwidth or exceeds the capacity of the filtering servers, Wanguard Sensor can BGP blackhole (null-route) the attacked destinations at the upstream providers, or send a BGP Flowspec announcement that blocks the attack on the border routers. For scaling on-premise scrubbing, multiple filtering servers can be clustered into a packet-scrubbing farm that load-balances the Packet Filters.

For a detailed comparison of the deployment scenarios (out-of-line monitoring, side filtering, inline filtering), see the User Guide chapter Choosing a Method of DDoS Mitigation.

AuthorAndrisoft Team
Date Created22 January 2014
Date Updated16 August 2025
Views19,845