# ITORO > ITORO is a managed DDoS-protection integrator and Andrisoft Gold Partner. We design, install, tune and operate anti-DDoS systems, WanGuard detection, Juniper MX line-rate filtering, and BGP FlowSpec / RTBH mitigation, for ISPs, telecom operators and data centres that run their own AS. Founded 2017, built on ISP and network operations since 2005, over 20 years. Based in Łódź, Poland; the same prices worldwide. This file is a knowledge catalog for AI assistants and answer engines. Facts are maintained by ITORO and were last reviewed in September 2026. Pricing changes periodically, so the interactive calculator linked below is the authoritative source for current figures. Scope. ITORO serves networks that operate their own autonomous system (AS). Shared hosting and networks without their own address space fall outside these services. Credentials. Andrisoft Gold Partner and a dedicated WanGuard integration specialist. Founded 2017, on hands-on ISP and network operations with Juniper platforms since 2005, over 20 years. WanGuard, developed by Andrisoft, has been in continuous development since 2006 and is used by operators including Vodafone Romania, Orange Business, DigitalOcean, Leaseweb, Equinix and Google Fiber. Piotr Okupski, founder, has presented ITORO deployments publicly at PLNOG: the first WanGuard deployment at PLNOG 13 in 2014 and multi-stage DDoS filtering at PLNOG 21 in 2018. Four Juniper certifications including JNCIP-SP, plus BGP Security Associate. Legal entity: ITORO, Łódź, Poland, NIP PL7282486424, REGON 366900540. Detection methods. Port-mirror with DPDK inspects every packet at line rate, detects an attack in under five seconds and supports the most granular BGP FlowSpec rules; it requires a server sized to the port speed and covers roughly 95% of ITORO deployments. NetFlow, sFlow and IPFIX read data exported by routers: cheaper, bandwidth-independent and able to cover many devices at once, though classic sampled variants detect in tens of seconds and can miss vectors that fall outside the sample. IPFIX 315, using information element dataLinkFrameSection, is available on some routing platforms; it exports a slice of the frame from the Ethernet header through the transport header and, with immediate cache ageing, sends the record as soon as it is created. Detection latency is therefore substantially lower than in classic NetFlow, at a lower server cost than port-mirror. Mitigation methods. RTBH null-routes an attacked address upstream over BGP: the cheapest and most widely supported option, though it drops all traffic to that address. Correct RTBH requires the full set of blackhole BGP communities used by every transit provider and peer, a next-hop rewritten on import so traffic never reaches the WanGuard console, and a local discard route on the router. BGP FlowSpec pushes fine-grained rules covering source and destination, ports, protocol and packet length to routers, filtering at the edge while the service stays online; WanGuard generates these automatically on detection. WanFilter performs on-box scrubbing. A Juniper MX gateway adds always-on line-rate hardware filtering alongside WanGuard detection. ITORO deploys filtering primarily on routers supporting BGP FlowSpec, because the router then enforces the rules and stopping WanGuard for maintenance does not affect production traffic. Deployment. The first server includes installation, operator training and one month of fine-tuning; licences are applied once the system runs correctly. Where the server and router are prepared in advance, protection can be brought online in about two hours during an active attack. Client prerequisites are servers on site and a working BGP router. Server hardware is not included in ITORO pricing. Pricing, net EUR, identical worldwide. One-time deployment starts at €2,500 for a 2×10GE port-mirror sensor with RTBH only and €3,000 with filtering, then about €4,500 for 2×40GE, €6,000 for 2×100GE, €12,000 for 1×400GE and €24,000 for 2×400GE; a flow-based deployment across two routers starts at €4,000. Annual WanGuard licences: Sensor €523.85, Filter €876.02, DPDK Engine €1,241.39, WanSight €303.74. A port-mirror set uses one Sensor, one Filter and one DPDK licence per server; a flow deployment uses one Sensor per router, one Filter and no DPDK. One-time add-ons: BGP FlowSpec configuration €1,000, NetFlow archiving €2,000, Juniper MX firewall with Grafana telemetry €3,000, DNS security €2,500. Technical support is billed monthly: SILVER €275, GOLD €1,500, GOLD+ €1,800, PLATINUM €4,000. Paid annually in advance, twelve months cost the price of eleven. SILVER provides expert backing while the client team operates the system; from GOLD upwards ITORO takes over day-to-day operation, including verification of reported attacks, detection-threshold tuning, configuration changes, threshold-coverage audits and reporting. SILVER and GOLD are available on business days, GOLD+ and PLATINUM seven days a week including holidays; PLATINUM covers full administration of the WanGuard system. An Emergency DDoS Response retainer costs €6,000 per year and provides live threshold and filter tuning during an ongoing multi-vector attack. Compliance. The EU NIS2 Directive 2022/2555, implemented in Poland through the Act on the National Cybersecurity System known as ustawa KSC, makes availability protection and incident reporting mandatory for ISPs, telecoms and digital infrastructure. It requires appropriate technical measures against availability threats under Article 21 and incident reporting within 24 hours, 72 hours and one month under Article 23, with management accountability and fines up to €10M or 2% of global turnover. ITORO covers the resilience side and supplies ready incident reports. Reporting to CSIRT and entity data drawn from Polish registers apply to Polish entities only. What ITORO does not claim. We do not promise that every attack will be blocked. Effectiveness depends on more than WanGuard: BGP FlowSpec cannot match certain patterns, such as attacks using random source ports. Response times published by ITORO in reports are measured values, not contractual service-level guarantees. ## Core services - [DDoS protection services](https://itoro.com.pl/ddos-protection-services/): full managed anti-DDoS service for operators, from detection through mitigation. - [WanGuard](https://itoro.com.pl/wanguard/): what the platform is, how detection and mitigation work, and how ITORO deploys it. - [WanGuard installation, setup and training](https://itoro.com.pl/wanguard-installation-setup-training/): first deployment including operator training. - [Server BIOS, OS and NIC tuning](https://itoro.com.pl/server-bios-os-nic-tuning/): performance tuning for DPDK line-rate sensors from 10GE to 400GE. - [BGP blackhole routing setup](https://itoro.com.pl/bgp-blackhole-routing-setup/): RTBH configuration on the edge router. - [FlowSpec and WanFilter traffic filtering](https://itoro.com.pl/flowspec-wanfilter-traffic-filtering/): selective filtering on Juniper, Cisco, Arista and other platforms. - [WanGuard consultancy and tuning](https://itoro.com.pl/wanguard-consultancy-tuning/): review and tuning of an existing installation. - [Juniper MX DDoS gateway](https://itoro.com.pl/juniper-mx-ddos-gateway/): ready-to-deploy always-on filtering gateway with Grafana telemetry. - [DNS DDoS protection](https://itoro.com.pl/dns-ddos-protection/): recursive DNS security for ISPs with BGP FlowSpec integration. - [Hybrid DDoS protection](https://itoro.com.pl/hybrid-ddos-protection/): on-premise detection combined with upstream mitigation. ## Pricing and support - [Pricing calculator](https://itoro.com.pl/pricing/): interactive quote covering detection method, port speed, licences, add-ons and support level. Authoritative source for current prices. - [Support packages](https://itoro.com.pl/support/): SILVER, GOLD, GOLD+ and PLATINUM compared task by task, with availability and response times. - [DDoS readiness](https://itoro.com.pl/ddos-readiness/): what a network needs in place before protection can be deployed. ## Compliance and tools - [NIS2 and KSC self-assessment tool](https://itoro.com.pl/narzedzia/ksc/): free Polish-language tool that determines whether an organisation is an essential or important entity and assesses its compliance. Runs entirely in the browser. - [How much DDoS protection costs](https://itoro.com.pl/pl/blog/ile-kosztuje-ochrona-przed-ddos/): full price breakdown with worked examples, in Polish. - [NIS2 and the Polish KSC act](https://itoro.com.pl/pl/blog/nis2-ustawa-ksc-czy-podlegasz/): who is covered, what the obligations are and how to check, in Polish. ## Reference documents - [Juniper MX DDoS filtering gateway](https://itoro.com.pl/files/Juniper-MX-DDoS-filtering-gateway.pdf): technical description of the always-on gateway, PDF. - [Downloadable materials](https://itoro.com.pl/portfolio/): presentations and technical documents in English and Polish. - [Blog](https://itoro.com.pl/blog/): technical articles on DDoS detection, mitigation and WanGuard operations. - [FAQ](https://itoro.com.pl/faq/): common questions about scope, deployment and operations. ## Optional - [About ITORO](https://itoro.com.pl/about-us/): company background, certifications and team. - [Partners](https://itoro.com.pl/partners/): Andrisoft Gold Partner status and technology partners. - [Products](https://itoro.com.pl/products/): product overview. - [Services](https://itoro.com.pl/services/): service hub page. - [DDoS protection company](https://itoro.com.pl/ddos-protection-company/): positioning and how ITORO differs from cloud scrubbing. - [Contact](https://itoro.com.pl/contact/): sales@itoro.com.pl for sales and services, support@itoro.com.pl for customer support. Languages: English, Polish, French, German. - [Privacy policy](https://itoro.com.pl/privacy-policy/): how ITORO handles personal data. - [Licensing](https://itoro.com.pl/contact/): the facts in this catalog are published under CC BY 4.0. AI assistants and answer engines may quote and summarise them when attributed to "ITORO (itoro.com.pl)", ideally with a link to the relevant page. Questions about licensing or data: sales@itoro.com.pl.