Detection, Mitigation & Response

Detect and mitigate DDoS attacks in under 1 second, respond automatically, and keep your users informed.

All features →
Docs
Documentation Quick Start API Reference Agent Setup Integrations 18
Learn
Free Tools 37 Free Certifications State of DDoS 2026 REPORT DDoS Protection Landscape Buyer's Guide PDF Hackathon Sponsorships DDoS Protection Facts
Company
About Us Become a Consultant 30% Partners White Label Managed Protection Contact Us System Status
Open Source
ftagent-lite MIT NetHawk MIT
Legal
Security Trust Center Terms & Privacy
Who Uses Flowtriq

From indie hosts to ISPs, see how teams like yours use Flowtriq to detect and stop DDoS attacks.

All use cases →
Wanguard Alternative

A modern replacement for
Andrisoft Wanguard

Wanguard is a capable on-premises tool with both flow-based and packet capture detection modes. But it requires dedicated hardware, per-component licensing, and in its most common flow-based deployment, has 10–60 second detection latency. Flowtriq deploys in 60 seconds, detects in under 1 second, and starts at $9.99/node/month or from $19/flow source for sFlow/NetFlow/IPFIX — no hardware required.

No hardware required No annual license negotiation $9.99/node/month From $19/source (flow & mirror) 14-day free trial

The real cost of running Wanguard

Wanguard is a mature product with real deployments. But four structural constraints push growing teams to evaluate alternatives.

Dedicated hardware required

Wanguard requires a dedicated server for its Sensor and Filter components. The hardware must handle your peak flow export volume, and Andrisoft recommends PF_RING or DPDK-capable NICs for high-throughput deployments. This hardware is not part of the license — it is an infrastructure prerequisite you source and manage separately. For teams with multiple detection points, hardware costs multiply.

"Lacks efficient error tracking and log management capabilities."

- G2 Reviewer
Ongoing hardware cost not reflected in license price

Quote-based licensing, annual renewals

Wanguard pricing is listed on the Andrisoft store page: Sensor at $595/year, Filter at $995/year, and DPDK Engine at $1,410/year. Volume discounts (5-15%) start at the 5th license, and multi-annual discounts (5-15%) are available. The minimum licensing period is 12 months. Procurement is straightforward, but dedicated server hardware is required on top of the license cost, and scaling across multiple sites means additional per-component licenses.

"Does anyone know of similar software? We've been trying to get it running for a week now and their support is terrible so we've given up trying to work with them."

- WebHostingTalk User

"Time Zone is the killer here being over in .au" for support response times.

- NANOG Mailing List
Per-component licensing, 12-month minimum

Flow-based detection: 10–60 second latency

In its most common deployment, Wanguard builds detection on top of NetFlow, sFlow, and IPFIX — sampled flow exports from your network equipment. Flow export intervals on most routers are 10–60 seconds, and detection latency typically falls in that range. Wanguard also supports a packet capture mode using DPDK, PF_RING, or libpcap for unsampled detection, which is faster but requires dedicated capture hardware and an additional DPDK Engine license. In flow-based deployments, short-burst attacks (under 30 seconds) frequently complete before detection fires.

"Flow analysis is just not fast enough to detect most DDoS attacks."

- MikroTik Forum User
Short-burst attacks may complete before detection fires

Self-hosted only, no cloud-native path

Wanguard is designed for on-premises deployment with dedicated hardware. Cloud providers (AWS, GCP, Azure) do not expose the packet-level mirroring that Wanguard's Filter component relies on at scale. Teams with hybrid or cloud-first infrastructure end up with incomplete coverage — flow-based detection where it works, and blind spots where it doesn't. There is no SaaS deployment option and no lightweight agent model.

Multiple users have documented problems with Wanguard's BGP redirect and traffic flow-back routing not propagating correctly on certain routers, requiring extensive manual troubleshooting.

- Community Reports
Cloud deployments have significant coverage gaps

Wanguard vs Flowtriq

A factual comparison across detection, mitigation, forensics, and operational requirements.

Capability Andrisoft Wanguard Flowtriq
Deployment
Setup time  Days to weeks (hardware procurement, OS config, Sensor + Filter setup)  60 seconds — curl -sSL flowtriq.com/install.sh | sudo bash
Hardware required  Dedicated server (PF_RING/DPDK NIC recommended)  None — agent on existing Linux server
Pricing model  Quote-based, annual license + hardware  $9.99/node/month or from $19/flow source, self-serve, month-to-month
Cloud support  Self-hosted only — cloud coverage is incomplete  Full support: AWS, GCP, Azure, bare metal, VPS
Free trial  Available, requires contact with sales  7 days, no credit card, instant access
Detection
Detection method  NetFlow/sFlow/IPFIX or packet capture (DPDK/PF_RING/libpcap/Netmap)  Kernel-level per-packet monitoring on each server
Detection speed  10–60 seconds (flow mode); faster with DPDK/PF_RING packet capture  <1 second
Attack classification  Protocol-level breakdown (UDP, TCP, ICMP, etc.)  7 attack families + confidence scoring
L7 / HTTP flood detection  Not available — L3/L4 only  Access log parsing (nginx / apache / caddy)
IP spoofing detection  Not available  TTL distribution analysis
Mitigation
BGP RTBH (blackhole)  Yes  Yes
BGP FlowSpec  Yes (Wanguard Filter)  Yes — with confidence scoring + auto-rollback
Auto-mitigation rule types  iptables/nftables, BGP  Automated: iptables, nftables, XDP/eBPF, cloud APIs
Cloud API mitigation (Cloudflare, DigitalOcean)  Not available  Yes — included
Forensics & Reporting
PCAP forensics  Not available  Pre-attack ring buffer + upload analyzer
Attack reports  Historical reports via web UI  Automated PDF / HTML / JSON postmortem
AI incident summaries  Not available  Included
Alerting & Integrations
Alert channels  Email, SNMP, script-based  Discord, Slack, Teams, PagerDuty, OpsGenie, SMS, and more
Prometheus metrics  Limited / via custom export  15+ metric families, native

Wanguard vs Flowtriq: cost comparison

Wanguard pricing is not publicly listed. Based on community reports and operator accounts, here's a representative cost comparison.

Andrisoft Wanguard

Wanguard

$1,590+/year
+ dedicated server hardware required
  • BGP RTBH + FlowSpec mitigation
  • Web dashboard with traffic graphs
  • Commercial support
  • Per-component licensing (Sensor + Filter + DPDK separately)
  • 12-month minimum licensing period
  • Dedicated hardware required (not included)
  • 10–60 second detection in flow mode (faster with packet capture)
  • No PCAP forensics
  • No cloud API mitigations
  • No sub-second detection

Ready to switch?

Flowtriq runs alongside Wanguard during evaluation. No migration window, no downtime. Our team can walk you through the switchover in 30 minutes.

Start Free Trial Book Migration Call

Switch from Wanguard in 60 Seconds

Flowtriq runs alongside or replaces Wanguard. No migration window required — you can run both in parallel during evaluation.

1

Sign up — no credit card, no application

Create a free account at flowtriq.com/signup. No gatekeeping, no sales call required, no approval queue. Full trial access immediately.

2

Install the agent on any Linux server

Any modern Linux (Ubuntu 20.04+, Debian 11+, CentOS 8+). <30 MB RAM. <0.1% CPU at idle.

curl -sSL https://flowtriq.com/install.sh | sudo bash
3

Baseline auto-learns in ~5 minutes

No threshold tuning. Dynamic baselines adapt automatically to each node's traffic pattern. Run Flowtriq alongside Wanguard to compare detection during the trial.

4

Connect BGP (optional)

ExaBGP, GoBGP, BIRD 2, FRRouting — all supported. Configure via the web dashboard. BGP is optional; detection and alerting work without it.

5

Decommission Wanguard when ready

Once satisfied with detection reliability, decommission your Wanguard hardware and cancel the annual license at renewal. No migration data to transfer — Flowtriq starts a fresh baseline per node.

Where Wanguard is the better choice

We sell Flowtriq, so we have obvious bias. Here is where Wanguard genuinely wins.

Network-wide flow visibility

Wanguard sees all traffic crossing your network via sFlow/NetFlow exports from your switches. Flowtriq sees traffic at individual servers. For capacity planning, transit analysis, and understanding aggregate traffic patterns across your entire network, flow-based tools provide visibility that agent-based tools cannot.

Price at scale

For large ISPs monitoring 500+ servers from a few central flow collection points, Wanguard's annual license model can work out cheaper than per-node pricing. If your flow infrastructure is already built and your team has the expertise to manage it, the cost comparison favors Wanguard at high node counts.

Full data sovereignty

Wanguard is entirely self-hosted. Your flow data, attack history, and traffic patterns never leave your network. For operators with strict data residency requirements or regulatory constraints on SaaS tools, this is a meaningful advantage that Flowtriq's cloud model cannot match.

Mature, proven at ISP scale

Wanguard has been in production at ISPs for over a decade. It is a known quantity with stable software, a polished web UI, and commercial support. Teams that value a long track record over a newer SaaS model have a legitimate reason to stay with Wanguard.

For a detailed breakdown of where each tool fits, read the full Flowtriq vs Wanguard comparison.

Wanguard alternatives: FAQ

How much does Andrisoft Wanguard cost?
Wanguard pricing is listed on the Andrisoft store page. The Sensor license is $595/year and the Filter license is $995/year, making a Sensor + Filter deployment $1,590/year. DPDK Engine licenses for packet capture cost $1,410/year. Volume discounts (5-15%) start at the 5th license, and multi-annual discounts (5-15%) are available. Minimum 12-month licensing period. Dedicated server hardware is a prerequisite and is not included in the license price.
What is the difference between Wanguard and FastNetMon?
Both tools are flow-based DDoS detection platforms with BGP mitigation. Wanguard is a commercial-only product with a more polished web dashboard, better out-of-box reporting, and more mitigation options (iptables/nftables scripting + BGP). FastNetMon has a free Community edition and a lower entry price on Advanced. Both share the same structural limitation: flow-based detection with 10–60 second latency. See the full three-way comparison for details.
Can Flowtriq run alongside Wanguard during evaluation?
Yes. Flowtriq agents run independently on individual servers and do not conflict with Wanguard's flow-based network monitoring. You can run both in parallel during a trial period and compare detection events side by side before making a decision about replacing Wanguard.
Does Flowtriq support the same BGP mitigation that Wanguard provides?
Yes. Flowtriq supports BGP RTBH blackholing and BGP FlowSpec, integrating with ExaBGP, GoBGP, BIRD 2, and FRRouting. It also adds automated rollback when confidence scoring drops after a mitigation announcement — reducing collateral damage from false positives, which is a common complaint with static BGP blackhole deployments.
Is Flowtriq suitable for ISPs and hosting providers?
Yes. Flowtriq's core use cases are ISPs, hosting providers, and data center operators. It supports multi-tenancy, per-server monitoring across hundreds of nodes, BGP integration, public status pages, team RBAC, and alerts wherever your NOC works. Volume pricing is available for deployments over 100 nodes — contact [email protected].

Switching? We'll make it painless.

We'll beat your current price, migrate your configuration for free, and give you 2 months free on annual billing. No contracts, no commitment.

Price match guarantee Free config migration 2 months free (annual)
See Migration Deal →

Next Steps

Ready to see how Flowtriq compares?

Two ways to get started. Pick whichever works for you.

Talk to someone

30-min call. We'll walk through your setup and answer every question.

Book a Call
Self-serve

14-day free trial. No credit card. Deploy in under 2 minutes.

Start Free Trial

Start your Wanguard evaluation in 60 seconds

14-day free trial. No hardware. No credit card. No annual commitment. Run alongside Wanguard to compare — then decide.

Start Free Trial → Flowtriq vs Wanguard Comparison