Skip to content
NeoProtect
NeoProtect

We don't detect attacks, we allow legitimate traffic.

On-Premise Shield is rented software that runs on your own hardware and filters DDoS attacks accurately, in-line. It's built on a single principle: allow only legitimate traffic rather than chasing attack patterns. The result is predictable, near-zero time-to-mitigation, without harming real users.

Allow legitimate traffic, instead of guessing at attacks

Most filtering tries to recognise and block attack patterns. On-Premise Shield inverts that: it establishes what legitimate traffic looks like for each service and lets only that through. Nothing to recognise means nothing to miss; mitigation stays predictable and near-instant.

Never allow invalid traffic

No L3/L4 invalid packet gets through filtering, and as far as state tracking can physically reach in your setup, no state-invalid packet passes either.

Work in every routing scenario

Symmetric or asymmetric routing, on-demand or always in-line: the Shield is configurable to behave as expected for the way your network actually forwards.

Even a few PPS can cause harm

Precision matters as much as volume. Low-rate, targeted attacks are treated as seriously as volumetric floods, while still dropping major packet volumes.

Six layers, one verdict on every packet

A packet only reaches your server after it clears each layer. They stack so that classification, connection state and protocol-level challenges all contribute to one verdict, customisable and API-first throughout.

In-line filtering on your hardware

Filter nodes drop invalid and state-invalid packets at line rate, before they reach a server, and pass only legitimate traffic. No L3/L4-invalid packet gets through; RFC compliance is enforced throughout.

Profile system

Profiles classify legitimate traffic per destination IP and port; Profile Presets group one classification across many IP/port pairs, for application-aware filtering applied dynamically at scale.

TCP mitigation

Ongoing connections are never disrupted: state-invalid packets are dropped, in-session packets are validated for RFC compliance, and SYN floods are challenged via a scalable SYN-proxy or a reconnect challenge.

Protocol challenge-response

Challenge-response invalidates spoofed or incapable sources across many L7 and UDP protocols, including RakNet Connect, A2S queries, TeamSpeak 3 and GoldSource / Source Engine.

IP lists & limits

White-, black- and trust-list IP ranges at scale, with per-connection and per-source limits applied dynamically per profile.

Advanced algorithms

Transmission-principle validation, known-anomaly checks, rate limits and symmetrically retrieved connection information keep pushing accuracy past conventional filtering.

Two filter nodes, sized to your network

Business filter nodes hand clean traffic to the node's kernel, ideal for game hosts and smaller setups adding protection to existing machines. Enterprise filter nodes run as a transparent L2 bridge across multi-VRF networks. Both are rented software for businesses and enterprises, priced on your 95th-percentile traffic and node count.

Business Filter

~€600/ month

The Business filter hands clean packets to the node's own kernel. Your host forwards or consumes them, with your full control and responsibility as to how.

Mixed uplink
single path
Filter node · XDP/eBPF
clean → kernel
Your host
Data plane
Clean packets delivered to the node kernel
Forwarding
Your host forwards or consumes them
Topology
Single path for single-homed setups
VLANs
Optional clean / dirty VLAN tagging

Enterprise Filter

~€1000/ month

A transparent L2 bridge separating clean and dirty traffic via VLANs and VRFs. Built for networks with router hardware that supports multi-VRF routing.

Dirty VLAN
vlan · dirty
Filter node · L2 bridge
vlan · clean
Clean VLAN
Data plane
Transparent L2 bridge, clean ↔ dirty
Forwarding
L2-forwarded between VLANs by the filter
Topology
Multi-VRF, VLAN-segmented
VLANs
Dedicated clean & dirty ingress + egress VLANs

See which plan works for your case

Answer two quick questions about your traffic and topology and we'll point you at the right filter node.

Find your plan

From the first “Hi!” to production

Setup is largely automated, but expert engineers check every deployment before it carries production traffic, so onboarding is fast without cutting corners.

  1. 01

    Reach out to sales

    Tell us your urgency, setup and feature questions. We clarify the basics and work up a quote for you.

  2. 02

    Engineering implements with you

    Once the quote is agreed, our engineers ensure a smooth rollout over chat or scheduled calls. Setup is largely automated.

  3. 03

    Production-readiness review

    Engineering goes over the deployment one last time to confirm it is ready for production traffic.

  4. 04

    Staged go-live

    You test on single prefixes or a slice of production traffic, then move to full production once you are confident.

One plane of a bigger platform

On-Premise Shield is the in-line plane of the On-Premise Platform. Pair it with OOL Shield for reactive, out-of-line detection driven by the flow telemetry your routers already export. Both run on your own hardware and are managed from the same self-hosted suite.

  • Rented software, running on your own hardware
  • Allow-legitimate filtering for near-zero time-to-mitigation
  • Business & Enterprise plans, priced on traffic and nodes

Let's scope your deployment

Tell us about your IP space, traffic profile and routing, and we'll map it to the right plan and configuration. Mention your urgency and we'll move fast.

Get protected Talk to sales