Tailored to Keep
Your Business Safe

Our Services

What We Do

The ITORO team specializes in implementing the WanGuard anti-DDoS system and offering networking consultancy to ensure complete DDoS protection.

Complete WanGuard Installation, Setup & Training

With numerous installations worldwide, we drastically reduce the time needed to deploy your protection and ensure it's done properly.

Setup & Tuning of BIOS, OS, & Network Cards

Against short, pulse-type DDoS attacks, precise WanGuard tuning is crucial for an effective and fast system response.

Border Gateway Protocol (BGP) Setup for Black Hole Routing

Configuring BGP communities with upstream routers enables RTBH (Remotely Triggered Black Hole) to block attacks. As this can also block legitimate traffic, we take special precautions before deploying it.

Traffic Filtering with WanFilter or BGP FlowSpec

Filtering is complex to set up, but is essential for protecting content providers from DDoS. Our network engineers will assist you in preparing your network.

Consultancy, Review & Tuning for Any WanGuard Installation

If WanGuard is already in your network, we can assist during staff changes, or check whether all settings and WanGuard components are set up correctly.

See Plans & Pricing
DNS · BIND & DNSdist

DNS security & hardening

Beyond WanGuard: we harden your BIND and DNSdist resolvers to NIST SP 800-81r3 and add DNSdist rate-limiting for application-layer DNS floods — NIS2-aligned.

DNS hardening

Our Approach & Process

Every installation and customer is unique. At ITORO, we provide tailored, cost-effective DDoS protection plans and solutions.

  • 1

    Choosing the Right Plan for Your Needs

    Learn about our plans and pick the one that fits. Contact us directly if you need help.

  • 2

    Network Audit & System Recommendation

    After an initial audit, we recommend the network and server setup required to deploy the WanGuard system.

  • 3

    WanGuard Software Installation & Optimization

    Once your server is prepared and connected, we install and optimize the WanGuard software.

  • 4

    Providing a Fully Secured Network

    We deliver final documentation and a remote training schedule. Your system is then ready to mitigate DDoS attacks.

1

Choosing the Right Plan for Your Needs

Learn about our plans and pick the one that fits. Contact us directly if you need help.

2

Network Audit & System Recommendation

After an initial audit, we recommend the network and server setup required to deploy the WanGuard system.

3

WanGuard Software Installation & Optimization

Once your server is prepared and connected, we install and optimize the WanGuard software.

4

Providing a Fully Secured Network

We deliver final documentation and a remote training schedule. Your system is then ready to mitigate DDoS attacks.

Under attack?

Rapid deployment in 2 hours

If your server and router — with RTBH / BGP FlowSpec ready — are prepared in advance, ITORO can bring WanGuard protection online in as little as 2 hours during an active attack. Not prepared yet? Follow our readiness checklist so you're covered if it ever happens.

Get help now Check your DDoS readiness ›

SCENARIOS

DDoS Protection Plans Overview

Learn about DDoS scenarios and choose the plan that fits your needs.

BasicScenario 1

Remotely Triggered Black Hole (RTBH)

Recommended for network operators (ISPs) or data centers, where blocking a single IP address does not disrupt the entire network.

  1. A DDoS attack begins, threatening to saturate your uplink capacity, impacting latency and service availability.
  2. WanGuard detects the attack in 5 seconds and sends a BGP update to initiate RTBH protection, blocking traffic to the targeted IP.
  3. Your router propagates the BGP update to upstream ISPs. Attack traffic is blocked before entering your network.
  4. Normal network traffic and latency are restored.

The limitation is that all traffic to the attacked IP is blocked.

Remotely Triggered Black Hole (RTBH) schema
AdvancedScenario 2

RTBH & FlowSpec Filtering

The highest level of DDoS protection, ensuring network resilience during multiple, simultaneous volumetric and layer-based attacks.

  1. If a DDoS attack requires traffic filtering, we trigger WanFilter for BGP FlowSpec filtering, then monitor whether traffic stays within our uplink limits.
  2. If a DDoS attack is close to saturating uplinks, WanGuard triggers BGP black-hole RTBH (Scenario 1).
  3. To ensure fully automatic protection, we set up additional checks and notifications for your network team.
RTBH & FlowSpec Filtering schema

Is Your Business Safe from DDoS?

DDoS attacks can strike at any time. Don't wait—be proactive in your defense.

See Plans & Pricing