Plans & Pricing
Choose the Perfect DDoS Protection Plan
First, choose how WanGuard will see traffic in your network
Choose between port-mirror (DPDK), which is the fastest and most accurate (sees everything), and flow (NetFlow / sFlow / IPFIX), which is easier to deploy in distributed or very high-bandwidth networks (400 Gbps+) and reaches Terabit visibility at a much lower cost to start. Port-mirror servers require far more expensive components and top CPU performance.
Pick your sensor: pricing scales with port speed
One-time deployment (first server includes install, training and a month of fine-tuning). 2×100GE is today’s default; 1-2×400GE is the premium tier.
| Select | Sensor (2 ports) | Approx. CPU cores | Detection | One-time deploy | Best fit |
|---|---|---|---|---|---|
| Flow (NetFlow/sFlow/IPFIX) · 2 routers | minimal | Slower · 35–95s | €4,000 | Reporting · gov · Terabit sFlow | |
| 2 × 10GE Sensor (RTBH only) | ~8–12 | Fastest · <5s (RTBH) | €2,500 | Cheapest entry · blackhole only | |
| 2 × 10GE Sensor & Filter | ~12–16 | Fastest · <5s | €3,000 | Small / edge | |
| 2 × 40GE Sensor & Filter | ~16–24 | Fastest · <5s | €4,500 | Mid-size ISP | |
| 2 × 100GE Sensor & Filter | ~24–32 | Fastest · <5s | €6,000 | Most ISPs today | |
| 1 × 400GE Sensor & Filter | ~64 | Fastest · <5s | €12,000 | 400G uplinks | |
| 2 × 400GE Sensor & Filter | ~128 | Fastest · <5s | €24,000 | 400G core / growth |
The first server includes installation, training and a free onboarding month; licenses are loaded only after the deployment is complete and everything works. Same price worldwide.
Optional services
Licenses follow your choices automatically: port-mirror = 1× Sensor + 1× Filter + 1× DPDK per server; flow = 2× Sensor + 1× Filter (no DPDK, assumes 2 routers or 2 switches as this is 99% of ISP/DC setups); NetFlow archiving adds 2× WanSight (also assumes 2 sFlow/NetFlow/IPFIX exporting devices).
Protection kept in tune as your network grows
WanGuard deployments and networks are subject to constant change, with prefixes, services and traffic continuing to grow. Keeping protection properly tuned is therefore continuous work, not a one-off deployment. From GOLD upwards it is carried out by the ITORO team. In the SILVER package it remains with the client technical team.
| Support tasks | SILVEREntry | GOLD★ System care | GOLD +Weekends & holidays | PLATINUMFull handover |
|---|---|---|---|---|
| Support availability | Business daysMon–Fri | Business daysMon–Fri | 7 days a weekweekends and holidays too | 7 days a weekweekends and holidays too |
| Response to a request | Next business day | Same business day | Same day | Same day |
| Email support covering operation of and questions about the WanGuard system and Linux only Including critical CVE updates and updates twice a year, together with reminders of key dates such as an approaching WanGuard licence expiry. | ✓ | ✓ | ✓ | ✓ |
| DDoS threshold recommendations, backups · false-positive advice | ✓ | ✓ | ✓ | ✓ |
| Automatic recovery of sensors and filters ITORO monitors the state of all WanGuard system processes and responds in the event of a failure, restoring sensors and filters. | ✓ | ✓ | ✓ | ✓ |
| Full WanGuard server load telemetry Continuous measurement of all Linux system and WanGuard protection parameters: CPU, memory, disk and network interface load. In the event of overload or irregularities we respond before they affect DDoS protection. | ✓ | ✓ | ✓ | ✓ |
| Active attack monitoring by ITORO We analyse attacks recorded in the system on an ongoing basis and optimise detection rules so that WanGuard recognises genuine attacks rather than false positives. At the same time we limit the impact of protection on legitimate traffic. | ✕ | ✓ | ✓ | ✓ |
| Zoom sessions on WanGuard operation and configuration Anomaly review, detection threshold settings, configuration changes and consultation for the technical team. | ✕ | ✓ | ✓ | ✓ |
| Configuration changes in WanGuard carried out by ITORO | ✕ | ✓ | ✓ | ✓ |
| Threshold coverage audit: report listing the gaps to close The report identifies networks without a complete set of detection thresholds, the recommended order of remediation and values ready to be entered in the console. | ✕ | ✓ | ✓ | ✓ |
| Board report: everything the board needs to know A document for decision-makers: the scale and frequency of attacks, the state of protection and other parameters relevant from the board perspective. Limited technical depth, focused on the current situation in the network and how the organisation handles threats. Issued at any cadence, from weekly to annual. | ✕ | ✓ | ✓ | ✓ |
| Network security report: externally visible threats set against attack telemetry We combine reports from several external CERT-type sources with attack telemetry in your network. The result is a summary of priority actions: which hosts to block, which services to restrict and where open ports allow the network to be used for attacks on other entities, which also raises the risk of return attacks. | ✕ | ✓ | ✓ | ✓ |
| Full administration of the WanGuard system The ITORO team takes over complete administration of the WanGuard system. | ✕ | ✕ | ✕ | ✓ |
| Scope of care | 4 of 11 items | 10 of 11 items | 10 of 11 items | 11 of 11 items |
| Pricing |
The choice comes down to how much day-to-day operation of the system stays with the client team.
Emergency DDoS Response
When an attack is live: Friday evening, mid-extortion, thresholds need tuning? ITORO acts first: live monitoring, packet analysis, and threshold / BGP FlowSpec tuning.
We replace or support your own network administrator during an attack, this is not a SIEM/SOC service. Ask for details via sales (at) itoro (dot) com (dot) pl.
- DDoS attacks more than doubled to 47.1M in 2025
- Telecom / ISPs are now the #1 most-attacked sector
- Ransom-DDoS threats up 68% quarter-on-quarter (Cloudflare Q2 2025)
- Largest 2025 attack hit 31.4 Tbps in just 35 seconds
- Most companies lack the staff to analyse traffic during a live attack.
Source: Cloudflare 2025 DDoS reports · NETSCOUT 2025
Anti-DDoS protection deployment estimate
Indicative estimate. The one-time cost covers deployment; licenses and support are billed annually. The quote excludes server hardware, installation runs on the customer's own equipment. Net EUR, rounded. Binding values are confirmed by ITORO.
What changes your price?
We publish real numbers so you, and any AI assistant you ask, get a straight answer. Here is what moves a WanGuard deployment up or down.
- Higher port speed (10 → 100 → 400GE) needs a larger, more powerful DPDK server
- More sensors / more POPs or routers to cover
- Full WanFilter mitigation in addition to RTBH black-holing
- Add-ons: NetFlow archiving, BGP FlowSpec on several vendors, DNS security, Juniper MX gateway
- Higher support tier (GOLD / PLATINUM) or the Emergency DDoS Response retainer
- Flow (NetFlow / sFlow / IPFIX) detection instead of port-mirror, scales to Terabit
- RTBH-only entry tier (from €2,500) when granular filtering is not required yet
- Fewer sensors and a lower support tier to start, grow later
- Same price worldwide: no regional mark-up
- First server includes install, training and one month of fine-tuning