Plans & Pricing

Choose the Perfect DDoS Protection Plan

STEP 1 · TRAFFIC COLLECTION

First, choose how WanGuard will see traffic in your network

Choose between port-mirror (DPDK), which is the fastest and most accurate (sees everything), and flow (NetFlow / sFlow / IPFIX), which is easier to deploy in distributed or very high-bandwidth networks (400 Gbps+) and reaches Terabit visibility at a much lower cost to start. Port-mirror servers require far more expensive components and top CPU performance.

STEP 2 · SENSOR & FILTER

Pick your sensor: pricing scales with port speed

One-time deployment (first server includes install, training and a month of fine-tuning). 2×100GE is today’s default; 1-2×400GE is the premium tier.

Sensor and filter options by port speed, with detection speed and one-time price
SelectSensor (2 ports)Approx. CPU coresDetectionOne-time deployBest fit
Flow (NetFlow/sFlow/IPFIX) · 2 routers minimal Slower · 35–95s €4,000 Reporting · gov · Terabit sFlow
2 × 10GE Sensor (RTBH only) ~8–12 Fastest · <5s (RTBH) €2,500 Cheapest entry · blackhole only
2 × 10GE Sensor & Filter ~12–16 Fastest · <5s €3,000 Small / edge
2 × 40GE Sensor & Filter ~16–24 Fastest · <5s €4,500 Mid-size ISP
2 × 100GE Sensor & Filter ~24–32 Fastest · <5s €6,000 Most ISPs today
1 × 400GE Sensor & Filter ~64 Fastest · <5s €12,000 400G uplinks
2 × 400GE Sensor & Filter ~128 Fastest · <5s €24,000 400G core / growth

The first server includes installation, training and a free onboarding month; licenses are loaded only after the deployment is complete and everything works. Same price worldwide.

OPTIONAL · ADD-ONS

Optional services

Extra sensors (one-time payment)
WanGuard licenses: auto-selected (per year)

Licenses follow your choices automatically: port-mirror = 1× Sensor + 1× Filter + 1× DPDK per server; flow = 2× Sensor + 1× Filter (no DPDK, assumes 2 routers or 2 switches as this is 99% of ISP/DC setups); NetFlow archiving adds 2× WanSight (also assumes 2 sFlow/NetFlow/IPFIX exporting devices).

STEP 3 · TECHNICAL SUPPORT

A healthy deployment. Protection under continuous care.

We keep your WanGuard deployment technically healthy and help adapt it to changing load. In SILVER your team runs the protection configuration. From GOLD we also review the configuration regularly and implement agreed corrections, to reduce the risk of an ineffective response and of unnecessary blocking.

Support tiers and the tasks each one covers
Support tasks SILVEREntry GOLDSystem care GOLD +Weekends & holidays PLATINUMFull handover
Support availability Business daysMon–Fri Business daysMon–Fri 7 days a weekweekends and holidays too 7 days a weekweekends and holidays too
Response to a request Next business day Same business day Same day Same day
Help with WanGuard and Linux operation, plus updates We answer questions about operating and running the deployment. We carry out updates twice a year and critical (CVE) updates, with changes agreed beforehand. We remind you of important dates, including the end of the WanGuard licence and of technical support. ✓ ✓ ✓ ✓
Threshold recommendations, backups and help with false positives We help choose detection settings and identify the causes of unwanted alarms. We maintain system backups. In SILVER, applying recommendations to the protection configuration stays with your team; from GOLD we carry out the agreed corrections. ✓ ✓ ✓ ✓
Process monitoring and automatic recovery of sensors and filters We monitor the state of WanGuard processes. In the cases covered by the mechanisms in place, sensors and filters are restored automatically. Problems that require an engineer are handled within the package you choose. ✓ ✓ ✓ ✓
Deployment supervision and tuning, more than 400 parameters We monitor more than 400 parameters of the deployment components: CPU, memory, disks, network cards, databases, BGP, DPDK and Flow and SNMP sensors, depending on the configuration. We react to problems we find and tune resources and databases to the load. This helps keep the deployment healthy also when the number of anomalies grows during attacks. ✓ ✓ ✓ ✓
Event analysis and detection tuning We analyse recorded anomalies and attacks together with how the protection rules behaved, and prepare corrections that improve detection and reduce false positives. In GOLD and GOLD+ the day-to-day watching of alarms stays with your team; the scope of incident handling is set out in the offer. ✕ ✓ ✓ ✓
Technical consultations and configuration review In Zoom sessions we go through anomalies, detection thresholds, planned changes and questions from your administrators. We agree how protection should behave, taking into account the role of each subnet and service. ✕ ✓ ✓ ✓
ITORO implements the agreed protection changes We prepare and implement agreed thresholds, list assignments and WanGuard response settings, once you approve them, and we check the effect. Your administrator receives a summary of the work done instead of translating a multi-page audit into console settings. ✕ ✓ ✓ ✓
We find gaps and errors in the protection configuration Our program checks the whole configuration under audit: prefixes defined in WanGuard, list assignments, required decoders, units and threshold values, and response settings. We point out which corrections to make first and carry them out as part of the agreed work. Once the deployment is prepared, reviews run every two weeks. We also check the effect of the changes. ✕ ✓ ✓ ✓
Traffic profiling tailored to your network We use traffic history stored in ClickHouse and the profiling capabilities of WanGuard 9.0. ITORO configures and tunes profiles for IP addresses and subnets, taking account of their purpose and normal traffic patterns. We define acceptable deviations, minimum trigger levels and the response: notification or activation of protection. These profiles complement threshold lists and help detect events that may remain below fixed thresholds. We introduce changes in stages and check their impact on legitimate traffic. ✕ ✓ ✓ ✓
We show the board the scale of threats and the state of protection We present the number and scale of confirmed attacks, the periods of highest activity and an assessment of how protection performed, based on the data available. The board gets an understandable summary of the situation in the network. The cadence of these summaries is agreed with you. ✕ ✓ ✓ ✓
We point out the threats an administrator should deal with first We passively analyse available external data on open services, vulnerable versions and reported threats, and combine it with WanGuard events. Your administrator receives ordered recommendations with an urgency rating, in particular for hosts that show both vulnerability signals and attack activity. Changes outside WanGuard stay with you unless agreed otherwise. ✕ ✓ ✓ ✓
We take over WanGuard administration We administer the deployment and watch alarms day to day, within the agreed scope and service hours. You tell us about changes in the network and service needs, and ITORO prepares and carries out the agreed work. Your team does not have to operate the WanGuard console day to day. ✕ ✕ ✕ ✓
Scope of care 4 of 12 items 11 of 12 items 11 of 12 items 12 of 12 items
Pricing
Choose the work you want to hand over to ITORO

The choice comes down to how much of the day-to-day work stays with your team and how much ITORO takes over.

scope covered by ITOROstays with the client team
SILVER ITORO keeps the deployment technically healthy; your team runs the protection configuration and watches the alarms.
GOLD In addition, we take over regular review of the configuration and implementation of the agreed corrections.
GOLD + The GOLD scope with support also at weekends and on public holidays.
PLATINUM We take over administration and the day-to-day watching of alarms during service hours.
Package scope and the number of protected networks. Standard packages cover care of the client network. If protection is to cover multiple networks or multiple entities, for example where an operator provides protection to its own customers, the workload grows with the number and nature of the protected networks and requires assessment in each case. In such cases we prepare an individual quotation.
STEP 4 · INCIDENT RESPONSE

Emergency DDoS Response

When an attack is live: Friday evening, mid-extortion, thresholds need tuning? ITORO acts first: live monitoring, packet analysis, and threshold / BGP FlowSpec tuning.

Annual
€6,000per year

We replace or support your own network administrator during an attack, this is not a SIEM/SOC service. Ask for details via sales (at) itoro (dot) com (dot) pl.

Why it matters now
  • DDoS attacks more than doubled to 47.1M in 2025
  • Telecom / ISPs are now the #1 most-attacked sector
  • Ransom-DDoS threats up 68% quarter-on-quarter (Cloudflare Q2 2025)
  • Largest 2025 attack hit 31.4 Tbps in just 35 seconds
  • Most companies lack the staff to analyse traffic during a live attack.

Source: Cloudflare 2025 DDoS reports · NETSCOUT 2025

Anti-DDoS protection deployment estimate

One-time cost
€0
Annual costs
€0
Total cost€0

Indicative estimate. The one-time cost covers deployment; licenses and support are billed annually. The quote excludes server hardware, installation runs on the customer's own equipment. Net EUR, rounded. Binding values are confirmed by ITORO.

Transparent pricing

What changes your price?

We publish real numbers so you, and any AI assistant you ask, get a straight answer. Here is what moves a WanGuard deployment up or down.

What raises the price
  • Higher port speed (10 → 100 → 400GE) needs a larger, more powerful DPDK server
  • More sensors / more POPs or routers to cover
  • Full WanFilter mitigation in addition to RTBH black-holing
  • Add-ons: NetFlow archiving, BGP FlowSpec on several vendors, DNS security, Juniper MX gateway
  • Higher support tier (GOLD / PLATINUM) or the Emergency DDoS Response retainer
What lowers the price
  • Flow (NetFlow / sFlow / IPFIX) detection instead of port-mirror, scales to Terabit
  • RTBH-only entry tier (from €2,500) when granular filtering is not required yet
  • Fewer sensors and a lower support tier to start, grow later
  • Same price worldwide: no regional mark-up
  • First server includes install, training and one month of fine-tuning