Andrisoft WanGuard favicon

Andrisoft WanGuard

FULL NETWORK VISIBILITY – Supports all IP traffic monitoring technologies: packet sniffing, NetFlow version 5,7 and 9; sFlow version 4 and 5; IPFIX and SNMP. COMPREHENSIVE DDOS DETECTION – Leverages an innovative traffic anomaly detection engine that quickly detects volumetric attacks. ON-PREMISE DDOS MITIGATION – Protects networks by using BGP blackhole routing or FlowSpec; protects services by detecting and cleaning malicious traffic on packet-scrubbing servers deployed in-line or out-of-line. FAST, SCALABLE & ROBUST – The software was designed to run on commodity hardware by leveraging high-speed packet capturing technologies such as Myricom Sniffer10G, PF_RING Vanilla, PF_RING ZC and Netmap. Can run as a cluster with its software components distributed across multiple servers. POWERFUL REACTION TOOLS – Executes predefined actions that automate the responses to attacks: sends notification emails, announces prefixes in BGP, generates SNMP traps, modifies ACLs, and runs scripts that have access to an easy-to-use API. DETAILED FORENSICS – Samples of packets and flows are captured for forensic investigation during each attack. Detailed attack reports can be emailed to you, affected customers or the attacker's ISP. ADVANCED WEB CONSOLE – Consolidated management and reporting through an interactive and highly-configurable HTML5 web portal with customizable dashboards, user roles, and remote authentication. PACKET SNIFFER – A distributed packet sniffer that saves packet dumps from different network entry points. View packet details in a Wireshark-like web interface. FLOW COLLECTOR – A fully featured NetFlow, sFlow, and IPFIX Analyzer and Collector that saves flows in a compressed format for long term storage. Flows can easily be searched, filtered, sorted, and exported. COMPLEX ANALYTICS – Generates complex reports with aggregated data for hosts, departments, interfaces, applications, ports, protocols, countries, autonomous systems, and more.