DDoS protection cost for a network with its own AS: one-off deployment from RTBH to 100GE filtering, annual WanGuard licenses, support and a worked example.
The DDoS protection cost for a network with its own AS number (the network’s identifier in BGP) starts at €2,500 as a one-off fee for the blackholing-only (RTBH) option, while a typical operator configuration, a sensor and filter on 100GE links, costs €6,000 one-off. Annual licenses and technical support are added on top.
Price list validity. The price list is revised periodically; the calculator on the pricing page always shows the current rates.
The four components of the bill
- Sensor and filter deployment: one-off, scales with port bandwidth.
- Additional services: one-off, optional (BGP FlowSpec configuration, NetFlow / sFlow / IPFIX archiving, filtering gateway).
- WanGuard licenses: annual, depending on the number of sensors and the detection method.
- Technical support: monthly, depending on how much of the work remains with the customer’s team.
Component 1: deployment and what determines its price
The single largest factor is how the system sees the traffic, followed closely by the bandwidth of the monitored ports.
Port mirroring with DPDK delivers a copy of the traffic directly to the sensor. The system sees every packet, detects an attack and triggers RTBH after about 1 s, and allows precise BGP FlowSpec rules to be built, with selective filtering working after 6–10 s. At higher bandwidths it requires a more powerful server, which raises the cost.
NetFlow, sFlow and IPFIX are data reported by the routers: a cheaper method, independent of link bandwidth and covering many devices at once. The classic, sampled variants pay for this with detection times of 35–95 s and limited visibility of some attack vectors.
The exception is IPFIX 315, available on some routing platforms. It exports a section of the frame from the Ethernet header up to the transport layer, and the immediate cache timeout mode sends each record as soon as it is created instead of waiting for the flow to end. Detection delay is therefore significantly lower than with classic NetFlow. For organisations that want to limit server spend, this is a realistic alternative to port mirroring, as the hardware requirements remain considerably lower.
| Deployment option | One-off cost |
|---|---|
| 2 × 10GE: blackholing only (RTBH) | €2,500 |
| 2 × 10GE: sensor and filter | €3,000 |
| NetFlow / sFlow / IPFIX from 2 routers | €4,000 |
| 2 × 40GE: sensor and filter | €4,500 |
| 2 × 100GE: sensor and filter | €6,000 |
| 1 × 400GE: sensor and filter | €12,000 |
The blackholing-only (RTBH) option is the lowest entry point: the system detects the attack and cuts off the targeted address, without selective filtering. It is often sufficient where the priority is protecting the uplink and the remaining customers. The deployment price includes installation, training and one month of tuning; we install the licenses once the deployment is complete and the system is operating correctly.
Filtering and the safety of production traffic
We most often deploy filtering when the customer has a router that supports BGP FlowSpec. The filtering rules are then executed by the router, while WanGuard handles detection and control: stopping the system during a maintenance window or for any other reason does not affect production traffic. A packet filter placed inline, between the router and the customers, introduces an element whose failure or restart can mean a loss of internet access for end customers.
Component 2: additional services
| Service | One-off cost |
|---|---|
| BGP FlowSpec configuration (Cisco, Juniper, Arista) | €1,000 |
| NetFlow / sFlow / IPFIX archiving | €2,000 |
| Juniper MX firewall with Grafana telemetry | €3,000 |
| DNS security for ISPs | €2,500 |
Component 3: WanGuard licenses
Licenses are billed annually. With port mirroring, each set of two ports requires a sensor license, a filter license and a DPDK engine license. With NetFlow, sFlow and IPFIX, one sensor license is required per router, a single filter license is sufficient, and no DPDK license is needed.
| License | Annual cost |
|---|---|
| WanGuard Sensor | €523.85 |
| WanGuard Filter | €876.02 |
| DPDK engine | €1,241.39 |
| WanSight Sensor (reporting) | €303.74 |
For a typical port mirror configuration with one set of ports, the full set of three licenses comes to €2,641.26 per year.
Component 4: technical support
| Package | Scope | Monthly cost |
|---|---|---|
| SILVER | expert back-up, operations handled by the customer’s team | €350 |
| GOLD | ITORO takes over care of the system | €1,500 |
| GOLD + | same scope as GOLD, including weekends and public holidays | €1,800 |
| PLATINUM | full system administration | €4,000 |
With annual payment in advance, the rule is 12 months for the price of 11.
Total DDoS protection cost: an example
An operator with 100GE links deploying port mirroring with filtering and GOLD support: deployment €6,000 one-off, licenses €2,641.26 per year, support €16,500 per year when paid in advance. The first year comes to €25,141.26 and each subsequent year to €19,141.26, because the deployment is not repeated. With SILVER support, the same configuration comes to €12,491.26 in the first year.
You can price your own configuration in the calculator on the pricing page: once you select the detection method, bandwidth and support package, the licenses are matched automatically.
What the total does not include
The total does not include the cost of servers. Component prices change very quickly, and the most expensive parts are usually the disks and RAM. Installation is carried out on the customer’s hardware, so the machines must already be in place or purchased separately. The total also excludes the cost of links and network equipment.
Preparing for deployment
We recommend that organisations planning a deployment contact us before making any purchases. Based on the network profile, we specify which hardware is actually needed and in what configuration, which helps optimise costs and avoid spending on components that would go unused.
On the customer’s side, two things are required for a successful deployment: servers prepared on site and a working router running BGP, on which we configure RTBH and, where the hardware supports BGP FlowSpec, filtering as well.
With a limited budget, a sensible order is: first traffic visibility and blackholing (RTBH), then the filtering module once it becomes necessary to keep specific services available during an attack, and finally the additional services, chosen on the basis of reports from the first months of operation.
Frequently asked questions
How much does DDoS protection cost for a small network?
The lowest entry point is €2,500 one-off for the 2 × 10GE blackholing (RTBH) option, plus a sensor license at €523.85 per year and support from €350 per month.
Does the price depend on the size of the attack?
No. Pricing is based on the bandwidth of the monitored and filtered ports, not on the volume of traffic mitigated.
Is a support package mandatory?
For the first year of operation, the system requires at least the SILVER package. Both the system and the network traffic change constantly, and prefix configuration calls for operational DDoS protection experience, networking knowledge and Linux system administration skills; without them, optimal operation and adequate performance cannot be maintained.
What does the deployment price include?
Installation, configuration and preparation of WanGuard for production use, plus verification of RTBH and of BGP FlowSpec filtering where the edge router supports it. Technical support is billed separately from the deployment. The deployment month covers the deployment itself: we prepare the entire installation and help the customer’s team bring protection into service with correctly set triggers.
Are prices the same worldwide?
Yes. Base prices are set in euros.