Skip to content
NeoProtect
NeoProtect

Your network. Your hardware. Your data.

The On-Premise Platform is a self-hosted, single-tenant DDoS detection and mitigation system you deploy on your own servers. It handles in-line scrubbing via our On Premise Shield Plans and reactive mitigation via our OOL Shield.

The whole platform, in one console

Every part of the platform runs from a single self-hosted console on your own infrastructure. It's shown here capturing live packet samples, down to per-packet verdicts and one-click PCAP export.

The NeoProtect on-prem console showing the Samples view capturing live packet samples with per-packet verdicts for export to Wireshark
Live packet samples with per-packet verdicts. One click from a PCAP export to Wireshark. Know exactly what happens, and why.

Run the whole fleet from one panel

From the first one-line installer to fleet-wide release rollouts, every node is deployed, configured and monitored from the same control plane, with updates that never drop protection.

  1. 01
    Create the node in the panel
  2. 02
    Run the installer it generates
  3. 03
    It registers and comes up Active
  4. 04
    An engineer verifies your setup
The on-prem console's Nodes view listing two enterprise filter nodes and a management node, all awaiting verification, with the node limit reached

Panel-driven node install

Define a node in the panel and run the one-line installer it hands back. It registers over a setup token and self-configures.

One control plane for the fleet

Management, filter, OOL and internal nodes all connect to each other. Push filter, VLAN, BGP and domain config without having to login to SSH all the time.

Software releases from the panel

Pin a node to an exact version or auto-track a major line, read the release notes, and roll an upgrade across the fleet with compatibility checks.

Built-in monitoring

Prometheus scraping and a prebuilt Grafana DDoS dashboard provision with the control node and come up on first boot.

Two shields, one platform

Every deployment builds on two complementary planes: On-Premise Shield filters in-line on your hardware, while OOL Shield watches your network out-of-line and reacts at the edge. Run one or both, managed from the same panel.

On-Premise Shield

Rented software on your own hardware that filters attacks in-line: invalid traffic is dropped at line rate and only legitimate traffic reaches your servers.

  • In-line filtering at line rate on your own hardware
  • Application-aware Profile system with IP lists & limits
  • TCP mitigation and protocol challenge-response
  • Business & Enterprise filter nodes, priced on 95th-percentile traffic
Explore On-Premise Shield

OOL Shield

Reactive detection with no inline tap: it watches the sFlow / sampling telemetry your routers already export and acts the moment something is off.

  • Detection Pipelines you compose yourself, no code
  • VAD & GAD algorithms for volume and header anomalies
  • Mitigates via BGP & FlowSpec at the router edge
  • Alerts, logs or enables in-line filtering automatically
Explore OOL Shield

Not sure which shield you need?

Answer a few quick questions about your network and we'll point you at the right protection.

Get protected

An engineer in your channel, more than a ticket in a queue

Every deployment comes with a shared channel to the team that builds and operates the platform. We watch sessions and BGP health alongside you, flag what we see, often first, and give planning questions a straight answer. The exchanges below are real, redacted only for privacy.

V
Vinneoprotect09:14

Hey, there's an issue on your R02 side. Your Egress sessions on both and are up and passing traffic, but the Ingress and Clean sessions to the same peers are stuck at 0 packets. They run over the same link that Egress is working fine on, so the connection is good, the sessions just aren't coming up on your end. Can you check the config for those two on your R02 router?

09:16

I will check 🙂

09:31

I see the sessions are all up, can you check if all is fine now at your side?

V
Vinneoprotect09:33

Yup, all fine now on my side!

16:02

Is it also possible for us to deploy the control panel off-site? I'm guessing the control panel will be the same one that's in , used for all locations we deploy in the future?

K
Kilianneoprotect16:03

Yes and yes

16:05

Awesome - we might talk to you about this next week.

1
01

A channel, not a ticket queue

Every deployment comes with a shared Slack channel. The people who answer are the engineers who build and operate the platform.

02

We often spot it first

Our engineers watch session and BGP health alongside you and reach out the moment something on either side looks off.

03

Straight answers, fast

New locations, off-site panels, topology changes: planning questions get a direct answer in minutes, not a discovery call.

Control you can't get from a scrubbing cloud

A dedicated deployment that hands you the controls and adapts the moment you turn them: no shared infrastructure, no opaque defaults, no ticket queue between you and your mitigation.

01

Single-tenant, on your metal

Your deployment is exactly that: yours. It runs on your hardware, inside your perimeter, with your data and your Keycloak realm. No shared scrubbing cloud, no third party in your traffic path.

02

Mitigation you reshape live

Profiles, limits and IP lists are yours to change at runtime, from the panel or the API, and they take effect immediately. Protection adapts with your traffic, not with a support queue.

03

API-first, automation-native

Every control in the panel is a call in the API: provision nodes, rewrite profiles, toggle mitigation from your own tooling. Detection pipelines and webhooks close the loop, so responses run without a human in the path.

04

In-line and out-of-line, one control plane

Line-rate scrubbing on your filter nodes plus flow-telemetry detection with BGP / FlowSpec actioning at the edge, composed as one platform and driven from a single panel.

05

Gaming-native protection

A2S and RakNet query caching and FiveM/GTA attack signatures ship built in, so game fleets get protection that understands their traffic instead of treating it as noise.

Protect every layer of your network

Everything above ships as one self-hosted suite: On-Premise Shield filters in-line on your hardware, OOL Shield watches your network out-of-line, and the panel installs, configures and updates the whole fleet.

  • In-line filtering and out-of-line detection, one platform
  • Single-tenant on your own hardware; nothing leaves your perimeter
  • Install, configure and update the whole fleet from one panel
  • Engineers in a shared channel, from planning to go-live

Let's scope your deployment

Answer a few questions about your network and we'll point you at the right setup, or talk to sales directly and we'll scope it together.

Get protected Talk to sales