We don't detect attacks, we allow legitimate traffic.
On-Premise Shield is rented software that runs on your own hardware and filters DDoS attacks accurately, in-line. It's built on a single principle: allow only legitimate traffic rather than chasing attack patterns. The result is predictable, near-zero time-to-mitigation, without harming real users.
Allow legitimate traffic, instead of guessing at attacks
Most filtering tries to recognise and block attack patterns. On-Premise Shield inverts that: it establishes what legitimate traffic looks like for each service and lets only that through. Nothing to recognise means nothing to miss; mitigation stays predictable and near-instant.
Never allow invalid traffic
No L3/L4 invalid packet gets through filtering, and as far as state tracking can physically reach in your setup, no state-invalid packet passes either.
Work in every routing scenario
Symmetric or asymmetric routing, on-demand or always in-line: the Shield is configurable to behave as expected for the way your network actually forwards.
Even a few PPS can cause harm
Precision matters as much as volume. Low-rate, targeted attacks are treated as seriously as volumetric floods, while still dropping major packet volumes.
Six layers, one verdict on every packet
A packet only reaches your server after it clears each layer. They stack so that classification, connection state and protocol-level challenges all contribute to one verdict, customisable and API-first throughout.
In-line filtering on your hardware
Filter nodes drop invalid and state-invalid packets at line rate, before they reach a server, and pass only legitimate traffic. No L3/L4-invalid packet gets through; RFC compliance is enforced throughout.
Profile system
Profiles classify legitimate traffic per destination IP and port; Profile Presets group one classification across many IP/port pairs, for application-aware filtering applied dynamically at scale.
TCP mitigation
Ongoing connections are never disrupted: state-invalid packets are dropped, in-session packets are validated for RFC compliance, and SYN floods are challenged via a scalable SYN-proxy or a reconnect challenge.
Protocol challenge-response
Challenge-response invalidates spoofed or incapable sources across many L7 and UDP protocols, including RakNet Connect, A2S queries, TeamSpeak 3 and GoldSource / Source Engine.
IP lists & limits
White-, black- and trust-list IP ranges at scale, with per-connection and per-source limits applied dynamically per profile.
Advanced algorithms
Transmission-principle validation, known-anomaly checks, rate limits and symmetrically retrieved connection information keep pushing accuracy past conventional filtering.
Two filter nodes, sized to your network
Business filter nodes hand clean traffic to the node's kernel, ideal for game hosts and smaller setups adding protection to existing machines. Enterprise filter nodes run as a transparent L2 bridge across multi-VRF networks. Both are rented software for businesses and enterprises, priced on your 95th-percentile traffic and node count.
Business Filter
The Business filter hands clean packets to the node's own kernel. Your host forwards or consumes them, with your full control and responsibility as to how.
- Data plane
- Clean packets delivered to the node kernel
- Forwarding
- Your host forwards or consumes them
- Topology
- Single path for single-homed setups
- VLANs
- Optional clean / dirty VLAN tagging
Enterprise Filter
A transparent L2 bridge separating clean and dirty traffic via VLANs and VRFs. Built for networks with router hardware that supports multi-VRF routing.
- Data plane
- Transparent L2 bridge, clean ↔ dirty
- Forwarding
- L2-forwarded between VLANs by the filter
- Topology
- Multi-VRF, VLAN-segmented
- VLANs
- Dedicated clean & dirty ingress + egress VLANs
See which plan works for your case
Answer two quick questions about your traffic and topology and we'll point you at the right filter node.
From the first “Hi!” to production
Setup is largely automated, but expert engineers check every deployment before it carries production traffic, so onboarding is fast without cutting corners.
- 01
Reach out to sales
Tell us your urgency, setup and feature questions. We clarify the basics and work up a quote for you.
- 02
Engineering implements with you
Once the quote is agreed, our engineers ensure a smooth rollout over chat or scheduled calls. Setup is largely automated.
- 03
Production-readiness review
Engineering goes over the deployment one last time to confirm it is ready for production traffic.
- 04
Staged go-live
You test on single prefixes or a slice of production traffic, then move to full production once you are confident.
One plane of a bigger platform
On-Premise Shield is the in-line plane of the On-Premise Platform. Pair it with OOL Shield for reactive, out-of-line detection driven by the flow telemetry your routers already export. Both run on your own hardware and are managed from the same self-hosted suite.
- Rented software, running on your own hardware
- Allow-legitimate filtering for near-zero time-to-mitigation
- Business & Enterprise plans, priced on traffic and nodes
Let's scope your deployment
Tell us about your IP space, traffic profile and routing, and we'll map it to the right plan and configuration. Mention your urgency and we'll move fast.
Get protected Talk to sales