DDoS protection for ISPs, hosting providers and data centres

ITORO designs, deploys and maintains DDoS protection based on WanGuard. Detection works on a port mirror copy of traffic or on NetFlow, sFlow and IPFIX exported by the routers. Mitigation runs on the operator's own network edge through BGP FlowSpec and RTBH, so filtering does not depend on an external scrubbing centre.

Pricing Contact an engineer
Andrisoft Gold Partner Juniper-certified engineers WanGuard experience since 2014 Founded in 2017
Andrisoft Gold Partner

Network security for operators: DDoS protection on your own edge

Each deployment covers three stages. Detection identifies the DDoS attack and its vector, mitigation removes the attack traffic at the network edge, and ongoing operation keeps thresholds and filters aligned with changing traffic.

~1 s

DDoS detection

With port mirroring and DPDK, WanGuard analyses every packet. Blackholing of an attacked address starts after about 1 s and selective filtering after 6–10 s. Flow-based detection from NetFlow, sFlow or IPFIX reacts within 35–95 s.

DDoS detection methods ›
BGP

DDoS mitigation

Filtering rules are distributed to the edge routers through BGP FlowSpec and executed at line rate. Typical vectors such as SYN flood, UDP flood and DNS amplification are filtered selectively. RTBH removes traffic to a single attacked address when the volume threatens the uplinks. A hybrid model with an external scrubbing service is available for attacks larger than the uplink capacity.

BGP FlowSpec ›   RTBH ›
SLA

Operation and support

Support packages from SILVER to PLATINUM define which tasks remain with the operator's team and which are performed by ITORO, from technical maintenance to configuration review and alarm handling. Support is billed separately from the deployment.

Support packages ›

Network traffic monitoring for DDoS detection: port mirror, NetFlow, sFlow and IPFIX

The choice of data source determines detection time, hardware requirements and the precision of filtering rules. Both methods can be combined in one WanGuard installation.

MethodDetection timeHardwareTypical use
Port mirror with DPDK (WanGuard Sensor)RTBH: 1 s
Filtering: 6–10 s
Dedicated server sized to the port capacity
(10GE to 400GE)
Transit and peering links of ISPs and data centres
NetFlow, sFlow, IPFIX (WanGuard Flow Sensor)35–95 s, depending on export timersMinimal; WanGuard Flow Sensor acts as a NetFlow analyzer for data exported by existing routersNetworks with many edge routers, network traffic analysis and reporting

Port mirroring or NetFlow · How to install WanGuard

DDoS protection and mitigation services

Available as a complete deployment or individually for an existing WanGuard installation.

WanGuard installation, setup and training

Learn more WanGuard installation, setup and training

Server, BIOS, OS and NIC tuning for DPDK

Learn more Server, BIOS, OS and NIC tuning for DPDK

BGP blackhole routing (RTBH) setup

Learn more BGP blackhole routing (RTBH) setup

Traffic filtering with BGP FlowSpec and WanFilter

Learn more Traffic filtering with BGP FlowSpec and WanFilter

WanGuard consultancy, review and tuning

Learn more WanGuard consultancy, review and tuning

DNS DDoS protection · Hybrid DDoS protection · DDoS readiness assessment

Juniper MX firewall and telemetry

A standalone product for Juniper MX edge routers (MX204, MX304 and larger): firewall filters protecting the router and the network, telemetry collected every 60 seconds from the PFE through a read-only account, two Grafana dashboards (DDoS Streams and Router Health) and an e-mail report sent only when a problem occurs. Deployment is carried out by Juniper-certified engineers. WanGuard is optional; with WanGuard, BGP FlowSpec rules are activated automatically after detection.

Juniper MX firewall

NIS2, cybersecurity and DDoS resilience

The NIS2 Directive requires essential and important entities, including providers of electronic communications networks, to implement cybersecurity measures ensuring the continuity of their services and to report significant incidents. Detection and mitigation of DDoS attacks, with records of attacks and responses, form part of these measures. Our free NIS2 compliance self-assessment tool shows the entity status, supervisory authority, maximum fines and gaps for all 27 EU Member States.

Free NIS 2 assessment

DDoS protection pricing

All prices follow the published price list. The deployment price includes installation, training and one month of deployment work; licenses and support are billed separately.

Blackholing only (RTBH)2 × 10GE sensor, one-off€2,500
Flow-based detectionNetFlow, sFlow, IPFIX from 2 routers€4,000
Sensor and filter2 × 100GE, one-off€6,000
Supportfrom SILVER, per month€350

PricingHow much does DDoS protection cost?

DDoS attack traffic detected and mitigated on the network edge

Why ITORO

Andrisoft Gold Partner and a team of Juniper-certified engineers focused on DDoS protection for operators.

Andrisoft Gold Partner

The only Andrisoft Gold Partner dedicated to WanGuard deployments, with direct access to the manufacturer.

Experience since 2014

Our engineers have run WanGuard in production networks since 2014. ITORO was founded in 2017.

Defined scope

Each offer states which attacks the deployment handles and where the limits lie, for example attacks exceeding the uplink capacity.

Frequently asked questions

What is a DDoS attack?

A distributed denial-of-service (DDoS) attack floods a network, server or service with traffic from many sources so that it stops serving legitimate users. For operators the most common vectors are volumetric floods (UDP, SYN) and amplification attacks (DNS, NTP, memcached).

What does DDoS protection for an ISP include?

Detection of attacks on the operator's traffic, automatic mitigation through BGP FlowSpec or RTBH on the edge routers, alerting and reporting. The scope is defined per network in the offer.

How fast does WanGuard detect a DDoS attack?

With port mirroring, blackholing starts after about 1 s and filtering after 6–10 s. With NetFlow, sFlow or IPFIX, detection takes 35–95 s because of router export timers.

Is additional hardware required?

Port mirror detection requires a dedicated server sized to the monitored ports. Flow-based detection uses data already exported by the routers. Filtering with BGP FlowSpec runs on existing routers that support it.

What happens with attacks larger than the uplink capacity?

Traffic exceeding the uplinks cannot be filtered inside the network. For such attacks we configure RTBH with upstream providers or integration with an external scrubbing service.

Assessment of an existing network

We review the topology, uplinks and router models and propose a deployment variant with its price from the price list.

Contact an engineer