Tailored to Keep
Your Business Safe
Our Services
What We Do
The ITORO team specializes in implementing the WanGuard anti-DDoS system and offering networking consultancy to ensure complete DDoS protection.
Complete WanGuard Installation, Setup & Training
With numerous installations worldwide, we drastically reduce the time needed to deploy your protection and ensure it's done properly.
Setup & Tuning of BIOS, OS, & Network Cards
Against short, pulse-type DDoS attacks, precise WanGuard tuning is crucial for an effective and fast system response.
Border Gateway Protocol (BGP) Setup for Black Hole Routing
Configuring BGP communities with upstream routers enables RTBH (Remotely Triggered Black Hole) to block attacks. As this can also block legitimate traffic, we take special precautions before deploying it.
Traffic Filtering with WanFilter or BGP FlowSpec
Filtering is complex to set up, but is essential for protecting content providers from DDoS. Our network engineers will assist you in preparing your network.
Consultancy, Review & Tuning for Any WanGuard Installation
If WanGuard is already in your network, we can assist during staff changes, or check whether all settings and WanGuard components are set up correctly.
DNS security & hardening
Beyond WanGuard: we harden your BIND and DNSdist resolvers to NIST SP 800-81r3 and add DNSdist rate-limiting for application-layer DNS floods — NIS2-aligned.
Our Approach & Process
Every installation and customer is unique. At ITORO, we provide tailored, cost-effective DDoS protection plans and solutions.
Choosing the Right Plan for Your Needs
Learn about our plans and pick the one that fits. Contact us directly if you need help.
Network Audit & System Recommendation
After an initial audit, we recommend the network and server setup required to deploy the WanGuard system.
WanGuard Software Installation & Optimization
Once your server is prepared and connected, we install and optimize the WanGuard software.
Providing a Fully Secured Network
We deliver final documentation and a remote training schedule. Your system is then ready to mitigate DDoS attacks.
Rapid deployment in 2 hours
If your server and router — with RTBH / BGP FlowSpec ready — are prepared in advance, ITORO can bring WanGuard protection online in as little as 2 hours during an active attack. Not prepared yet? Follow our readiness checklist so you're covered if it ever happens.
DDoS Protection Plans Overview
Learn about DDoS scenarios and choose the plan that fits your needs.
Remotely Triggered Black Hole (RTBH)
Recommended for network operators (ISPs) or data centers, where blocking a single IP address does not disrupt the entire network.
- A DDoS attack begins, threatening to saturate your uplink capacity, impacting latency and service availability.
- WanGuard detects the attack in 5 seconds and sends a BGP update to initiate RTBH protection, blocking traffic to the targeted IP.
- Your router propagates the BGP update to upstream ISPs. Attack traffic is blocked before entering your network.
- Normal network traffic and latency are restored.
The limitation is that all traffic to the attacked IP is blocked.
RTBH & FlowSpec Filtering
The highest level of DDoS protection, ensuring network resilience during multiple, simultaneous volumetric and layer-based attacks.
- If a DDoS attack requires traffic filtering, we trigger WanFilter for BGP FlowSpec filtering, then monitor whether traffic stays within our uplink limits.
- If a DDoS attack is close to saturating uplinks, WanGuard triggers BGP black-hole RTBH (Scenario 1).
- To ensure fully automatic protection, we set up additional checks and notifications for your network team.