Hybrid DDoS Protection — On-Prem Speed, Cloud Scale

Combine on-premise WanGuard mitigation with upstream cloud scrubbing for layered, hybrid DDoS protection.

Hybrid DDoS protection combines two mitigation layers that each fail in the opposite direction on their own: an on-premise WanGuard deployment that detects and filters attacks locally in seconds, and upstream cloud scrubbing that absorbs floods larger than your uplinks can physically carry. ITORO designs the division of labour between them so everyday attacks are handled at your edge and only genuine terabit-scale events are escalated upstream.

Why one layer is never enough

A pure on-premise appliance is fast and cheap to run, but it can only clean traffic that reaches it — once an attack exceeds your uplink capacity, the congestion happens at your provider’s border, upstream of any box you own. A pure-cloud service solves the capacity problem but adds always-on redirection, per-event or per-clean-gigabit billing, and detection latency measured in tens of seconds while traffic reroutes. Hybrid keeps normal traffic local and on-net, and reaches for cloud capacity only when the physics of the attack demand it.

The division of labour

On-premise: WanGuard does detection and surgical filtering

WanGuard ingests NetFlow/sFlow/IPFIX from your Juniper MX or other edge routers and builds a live baseline of what normal looks like per prefix, per host, per protocol. When an anomaly crosses threshold it drops the offending traffic with WanFilter granular filters or pushes a BGP FlowSpec rule to the router itself — matching on source, destination, ports, protocol, packet length or TCP flags. This is surgical: a single NTP-amplification signature or one attacked /32 can be filtered while the rest of the subnet keeps serving. Reaction time is seconds, and it costs nothing per-gigabit because it runs on your own iron.

Upstream: cloud and provider scrubbing for the volumetric ceiling

Some floods are simply bigger than your pipes. For those, WanGuard signals the next layer automatically. RTBH (Remotely Triggered Black Hole) is the blunt, universally supported tool — it null-routes the attacked destination at your upstream’s edge, sacrificing one target to protect everything else. Where your transit provider or a scrubbing centre supports it, BGP FlowSpec can be propagated upstream instead, dropping only the malicious flows and keeping the target online. The cloud layer is dimensioned for the traffic your own uplinks never could be.

When each layer engages

  • Normal operations: everything stays local. No redirection, no added latency, no metered egress.
  • Typical attack (fits within your uplinks): WanGuard filters at the edge with WanFilter or FlowSpec in seconds. The cloud is never touched.
  • Uplinks approaching saturation: WanGuard escalates automatically — FlowSpec or RTBH signalled upstream, or diversion to a scrubbing centre — before congestion degrades legitimate traffic.

Cost predictability versus pure-cloud

Always-on cloud scrubbing bills you for capacity and clean traffic every month, whether or not you are under attack, and large events can produce unpredictable overage. A hybrid model inverts that: your fixed cost is the on-premise WanGuard platform, which handles the overwhelming majority of incidents at zero marginal cost, and you only draw on — and pay for — upstream capacity during the rare events that actually need it. For ISPs, telecoms and data centres with steady traffic and occasional spikes, this is usually both cheaper and more predictable. See transparent pricing.

A realistic scenario: carpet-bomb versus targeted flood

The two layers earn their keep in different attacks. A targeted flood — say 8 Gbit/s of DNS reflection aimed at one customer IP — is meat for the on-premise layer: WanGuard fingerprints it, drops it with a FlowSpec rule at the MX, and no one else notices. A carpet-bomb is harder: the same total volume is smeared across hundreds of destinations in a /22, each individual flow too small to trip a per-host threshold, but the aggregate saturating your border. Here WanGuard’s subnet-level and aggregate detection matters, and if the total still exceeds your uplinks the honest answer is upstream scrubbing — a per-/32 RTBH would black-hole half your customers. We design thresholds and escalation for both cases rather than assuming every attack looks the same.

Frequently asked questions

On-premise vs cloud DDoS protection — which is better?

Neither, alone. On-premise wins on speed and cost for the attacks you see most; cloud wins on raw capacity for the rare largest floods. Hybrid uses each where it is strongest.

Does hybrid protection add latency?

No. Normal traffic stays local and unredirected. Upstream capacity is engaged only during exceptional volumetric events, not in steady state.

Can you guarantee no attack ever gets through?

No, and we will not claim it. We design layered mitigation to keep services available across the realistic threat range, and we are explicit about the point where an attack must be absorbed upstream rather than at your edge.

Do we need to replace our Juniper MX or existing routers?

Usually not. WanGuard works alongside your existing edge, consuming NetFlow/sFlow/IPFIX for detection and using BGP FlowSpec and RTBH to program mitigation on the routers you already run.

Is Your Business Safe from DDoS?

DDoS attacks can strike at any time. Don't wait—be proactive in your defense.

See Plans & Pricing