DDoS protection for ISPs, hosting providers and data centres
ITORO designs, deploys and maintains DDoS protection based on WanGuard. Detection works on a port mirror copy of traffic or on NetFlow, sFlow and IPFIX exported by the routers. Mitigation runs on the operator's own network edge through BGP FlowSpec and RTBH, so filtering does not depend on an external scrubbing centre.
Pricing Contact an engineer
Network security for operators: DDoS protection on your own edge
Each deployment covers three stages. Detection identifies the DDoS attack and its vector, mitigation removes the attack traffic at the network edge, and ongoing operation keeps thresholds and filters aligned with changing traffic.
DDoS detection
With port mirroring and DPDK, WanGuard analyses every packet. Blackholing of an attacked address starts after about 1 s and selective filtering after 6–10 s. Flow-based detection from NetFlow, sFlow or IPFIX reacts within 35–95 s.
DDoS detection methods ›DDoS mitigation
Filtering rules are distributed to the edge routers through BGP FlowSpec and executed at line rate. Typical vectors such as SYN flood, UDP flood and DNS amplification are filtered selectively. RTBH removes traffic to a single attacked address when the volume threatens the uplinks. A hybrid model with an external scrubbing service is available for attacks larger than the uplink capacity.
BGP FlowSpec › RTBH ›Operation and support
Support packages from SILVER to PLATINUM define which tasks remain with the operator's team and which are performed by ITORO, from technical maintenance to configuration review and alarm handling. Support is billed separately from the deployment.
Support packages ›Network traffic monitoring for DDoS detection: port mirror, NetFlow, sFlow and IPFIX
The choice of data source determines detection time, hardware requirements and the precision of filtering rules. Both methods can be combined in one WanGuard installation.
| Method | Detection time | Hardware | Typical use |
|---|---|---|---|
| Port mirror with DPDK (WanGuard Sensor) | RTBH: 1 s Filtering: 6–10 s | Dedicated server sized to the port capacity (10GE to 400GE) | Transit and peering links of ISPs and data centres |
| NetFlow, sFlow, IPFIX (WanGuard Flow Sensor) | 35–95 s, depending on export timers | Minimal; WanGuard Flow Sensor acts as a NetFlow analyzer for data exported by existing routers | Networks with many edge routers, network traffic analysis and reporting |
DDoS protection and mitigation services
Available as a complete deployment or individually for an existing WanGuard installation.
Traffic filtering with BGP FlowSpec and WanFilter
Learn more Traffic filtering with BGP FlowSpec and WanFilterDNS DDoS protection · Hybrid DDoS protection · DDoS readiness assessment
Juniper MX firewall and telemetry
A standalone product for Juniper MX edge routers (MX204, MX304 and larger): firewall filters protecting the router and the network, telemetry collected every 60 seconds from the PFE through a read-only account, two Grafana dashboards (DDoS Streams and Router Health) and an e-mail report sent only when a problem occurs. Deployment is carried out by Juniper-certified engineers. WanGuard is optional; with WanGuard, BGP FlowSpec rules are activated automatically after detection.
Juniper MX firewallNIS2, cybersecurity and DDoS resilience
The NIS2 Directive requires essential and important entities, including providers of electronic communications networks, to implement cybersecurity measures ensuring the continuity of their services and to report significant incidents. Detection and mitigation of DDoS attacks, with records of attacks and responses, form part of these measures. Our free NIS2 compliance self-assessment tool shows the entity status, supervisory authority, maximum fines and gaps for all 27 EU Member States.
Free NIS 2 assessmentDDoS protection pricing
All prices follow the published price list. The deployment price includes installation, training and one month of deployment work; licenses and support are billed separately.
Why ITORO
Andrisoft Gold Partner and a team of Juniper-certified engineers focused on DDoS protection for operators.
Andrisoft Gold Partner
The only Andrisoft Gold Partner dedicated to WanGuard deployments, with direct access to the manufacturer.
Experience since 2014
Our engineers have run WanGuard in production networks since 2014. ITORO was founded in 2017.
Defined scope
Each offer states which attacks the deployment handles and where the limits lie, for example attacks exceeding the uplink capacity.
Frequently asked questions
What is a DDoS attack?
A distributed denial-of-service (DDoS) attack floods a network, server or service with traffic from many sources so that it stops serving legitimate users. For operators the most common vectors are volumetric floods (UDP, SYN) and amplification attacks (DNS, NTP, memcached).
What does DDoS protection for an ISP include?
Detection of attacks on the operator's traffic, automatic mitigation through BGP FlowSpec or RTBH on the edge routers, alerting and reporting. The scope is defined per network in the offer.
How fast does WanGuard detect a DDoS attack?
With port mirroring, blackholing starts after about 1 s and filtering after 6–10 s. With NetFlow, sFlow or IPFIX, detection takes 35–95 s because of router export timers.
Is additional hardware required?
Port mirror detection requires a dedicated server sized to the monitored ports. Flow-based detection uses data already exported by the routers. Filtering with BGP FlowSpec runs on existing routers that support it.
What happens with attacks larger than the uplink capacity?
Traffic exceeding the uplinks cannot be filtered inside the network. For such attacks we configure RTBH with upstream providers or integration with an external scrubbing service.