Plans & Pricing
Choose the Perfect DDoS Protection Plan
First, choose how WanGuard will see traffic in your network
Choose between port-mirror (DPDK), which is the fastest and most accurate (sees everything), and flow (NetFlow / sFlow / IPFIX), which is easier to deploy in distributed or very high-bandwidth networks (400 Gbps+) and reaches Terabit visibility at a much lower cost to start. Port-mirror servers require far more expensive components and top CPU performance.
Pick your sensor: pricing scales with port speed
One-time deployment (first server includes install, training and a month of fine-tuning). 2×100GE is today’s default; 1-2×400GE is the premium tier.
| Select | Sensor (2 ports) | Approx. CPU cores | Detection | One-time deploy | Best fit |
|---|---|---|---|---|---|
| Flow (NetFlow/sFlow/IPFIX) · 2 routers | minimal | Slower · 35–95s | €4,000 | Reporting · gov · Terabit sFlow | |
| 2 × 10GE Sensor (RTBH only) | ~8–12 | Fastest · <5s (RTBH) | €2,500 | Cheapest entry · blackhole only | |
| 2 × 10GE Sensor & Filter | ~12–16 | Fastest · <5s | €3,000 | Small / edge | |
| 2 × 40GE Sensor & Filter | ~16–24 | Fastest · <5s | €4,500 | Mid-size ISP | |
| 2 × 100GE Sensor & Filter | ~24–32 | Fastest · <5s | €6,000 | Most ISPs today | |
| 1 × 400GE Sensor & Filter | ~64 | Fastest · <5s | €12,000 | 400G uplinks | |
| 2 × 400GE Sensor & Filter | ~128 | Fastest · <5s | €24,000 | 400G core / growth |
The first server includes installation, training and a free onboarding month; licenses are loaded only after the deployment is complete and everything works. Same price worldwide.
Optional services
Licenses follow your choices automatically: port-mirror = 1× Sensor + 1× Filter + 1× DPDK per server; flow = 2× Sensor + 1× Filter (no DPDK, assumes 2 routers or 2 switches as this is 99% of ISP/DC setups); NetFlow archiving adds 2× WanSight (also assumes 2 sFlow/NetFlow/IPFIX exporting devices).
A healthy deployment. Protection under continuous care.
We keep your WanGuard deployment technically healthy and help adapt it to changing load. In SILVER your team runs the protection configuration. From GOLD we also review the configuration regularly and implement agreed corrections, to reduce the risk of an ineffective response and of unnecessary blocking.
| Support tasks | SILVEREntry | GOLDSystem care | GOLD +Weekends & holidays | PLATINUMFull handover |
|---|---|---|---|---|
| Support availability | Business daysMon–Fri | Business daysMon–Fri | 7 days a weekweekends and holidays too | 7 days a weekweekends and holidays too |
| Response to a request | Next business day | Same business day | Same day | Same day |
| Help with WanGuard and Linux operation, plus updates We answer questions about operating and running the deployment. We carry out updates twice a year and critical (CVE) updates, with changes agreed beforehand. We remind you of important dates, including the end of the WanGuard licence and of technical support. | ✓ | ✓ | ✓ | ✓ |
| Threshold recommendations, backups and help with false positives We help choose detection settings and identify the causes of unwanted alarms. We maintain system backups. In SILVER, applying recommendations to the protection configuration stays with your team; from GOLD we carry out the agreed corrections. | ✓ | ✓ | ✓ | ✓ |
| Process monitoring and automatic recovery of sensors and filters We monitor the state of WanGuard processes. In the cases covered by the mechanisms in place, sensors and filters are restored automatically. Problems that require an engineer are handled within the package you choose. | ✓ | ✓ | ✓ | ✓ |
| Deployment supervision and tuning, more than 400 parameters We monitor more than 400 parameters of the deployment components: CPU, memory, disks, network cards, databases, BGP, DPDK and Flow and SNMP sensors, depending on the configuration. We react to problems we find and tune resources and databases to the load. This helps keep the deployment healthy also when the number of anomalies grows during attacks. | ✓ | ✓ | ✓ | ✓ |
| Event analysis and detection tuning We analyse recorded anomalies and attacks together with how the protection rules behaved, and prepare corrections that improve detection and reduce false positives. In GOLD and GOLD+ the day-to-day watching of alarms stays with your team; the scope of incident handling is set out in the offer. | ✕ | ✓ | ✓ | ✓ |
| Technical consultations and configuration review In Zoom sessions we go through anomalies, detection thresholds, planned changes and questions from your administrators. We agree how protection should behave, taking into account the role of each subnet and service. | ✕ | ✓ | ✓ | ✓ |
| ITORO implements the agreed protection changes We prepare and implement agreed thresholds, list assignments and WanGuard response settings, once you approve them, and we check the effect. Your administrator receives a summary of the work done instead of translating a multi-page audit into console settings. | ✕ | ✓ | ✓ | ✓ |
| We find gaps and errors in the protection configuration Our program checks the whole configuration under audit: prefixes defined in WanGuard, list assignments, required decoders, units and threshold values, and response settings. We point out which corrections to make first and carry them out as part of the agreed work. Once the deployment is prepared, reviews run every two weeks. We also check the effect of the changes. | ✕ | ✓ | ✓ | ✓ |
| Traffic profiling tailored to your network We use traffic history stored in ClickHouse and the profiling capabilities of WanGuard 9.0. ITORO configures and tunes profiles for IP addresses and subnets, taking account of their purpose and normal traffic patterns. We define acceptable deviations, minimum trigger levels and the response: notification or activation of protection. These profiles complement threshold lists and help detect events that may remain below fixed thresholds. We introduce changes in stages and check their impact on legitimate traffic. | ✕ | ✓ | ✓ | ✓ |
| We show the board the scale of threats and the state of protection We present the number and scale of confirmed attacks, the periods of highest activity and an assessment of how protection performed, based on the data available. The board gets an understandable summary of the situation in the network. The cadence of these summaries is agreed with you. | ✕ | ✓ | ✓ | ✓ |
| We point out the threats an administrator should deal with first We passively analyse available external data on open services, vulnerable versions and reported threats, and combine it with WanGuard events. Your administrator receives ordered recommendations with an urgency rating, in particular for hosts that show both vulnerability signals and attack activity. Changes outside WanGuard stay with you unless agreed otherwise. | ✕ | ✓ | ✓ | ✓ |
| We take over WanGuard administration We administer the deployment and watch alarms day to day, within the agreed scope and service hours. You tell us about changes in the network and service needs, and ITORO prepares and carries out the agreed work. Your team does not have to operate the WanGuard console day to day. | ✕ | ✕ | ✕ | ✓ |
| Scope of care | 4 of 12 items | 11 of 12 items | 11 of 12 items | 12 of 12 items |
| Pricing |
The choice comes down to how much of the day-to-day work stays with your team and how much ITORO takes over.
Emergency DDoS Response
When an attack is live: Friday evening, mid-extortion, thresholds need tuning? ITORO acts first: live monitoring, packet analysis, and threshold / BGP FlowSpec tuning.
We replace or support your own network administrator during an attack, this is not a SIEM/SOC service. Ask for details via sales (at) itoro (dot) com (dot) pl.
- DDoS attacks more than doubled to 47.1M in 2025
- Telecom / ISPs are now the #1 most-attacked sector
- Ransom-DDoS threats up 68% quarter-on-quarter (Cloudflare Q2 2025)
- Largest 2025 attack hit 31.4 Tbps in just 35 seconds
- Most companies lack the staff to analyse traffic during a live attack.
Source: Cloudflare 2025 DDoS reports · NETSCOUT 2025
Anti-DDoS protection deployment estimate
Indicative estimate. The one-time cost covers deployment; licenses and support are billed annually. The quote excludes server hardware, installation runs on the customer's own equipment. Net EUR, rounded. Binding values are confirmed by ITORO.
What changes your price?
We publish real numbers so you, and any AI assistant you ask, get a straight answer. Here is what moves a WanGuard deployment up or down.
- Higher port speed (10 → 100 → 400GE) needs a larger, more powerful DPDK server
- More sensors / more POPs or routers to cover
- Full WanFilter mitigation in addition to RTBH black-holing
- Add-ons: NetFlow archiving, BGP FlowSpec on several vendors, DNS security, Juniper MX gateway
- Higher support tier (GOLD / PLATINUM) or the Emergency DDoS Response retainer
- Flow (NetFlow / sFlow / IPFIX) detection instead of port-mirror, scales to Terabit
- RTBH-only entry tier (from €2,500) when granular filtering is not required yet
- Fewer sensors and a lower support tier to start, grow later
- Same price worldwide: no regional mark-up
- First server includes install, training and one month of fine-tuning