Wanguard 6.2 User Guide
Choosing a Method of DDoS Mitigation
The stateless operation of Wanguard Sensor and Wanguard Filter ensures detection and mitigation of
volumetric attacks that may cripple even the most powerful stateful devices such as firewalls, Intrusion Detection
Systems (IDS) or Intrusion Protection Systems (IPS). This is why in most cases the servers running Wanguard should
be installed near the network's entry points, before other stateful devices.
The single major disadvantage of the stateless operation is that neither Wanguard Sensor nor Wanguard
Filter can detect or block many low-volume application layer (OSI Layer 7) attacks, unlike traditional IPSes.
There are three Wanguard Filter “flavors” that differ only in the way they obtain traffic information:
●
Packet Filter
analyzes packets traveling through appliances (servers, firewalls, routers, bridges, IDSes,
load-balancers) deployed in-line, connected to a mirrored port, or that make use of BGP traffic
diversion. It needs to run on a powerful server to be able to do packet inspection on high-speed
interfaces. Each configuration option is covered on page 55.
●
Flow Filter
analyzes NetFlow® (jFlow, NetStream, cflowd), sFlow® or IPFIX flow data. It can work only in
cooperation with a Flow Sensor, so it is not able to generate filtering rules as fast as a Packet Filter.
Because flows contain limited traffic information, filtering rules are limited to IP addresses, IP protocols,
TCP and UDP ports, country and protocol. Each configuration option is covered on page 60.
●
Filter Cluster
aggregates traffic data collected by multiple Packet Filter and Flow Filter instances. It can
be used to create clusters of filtering servers. Each configuration option is covered on page 64.
Wanguard Filter Deployment Scenarios
Wanguard Filter can be deployed on servers configured for:
Side-filtering
– The Filter sends a BGP routing update to a border router (route reflector) that sets its
server as the next hop for the suspect traffic. The cleaned traffic is routed back into the network using
static or dynamic routing.
In-line routing
– The Filter runs on a server that resides in the main data path, configured as an OSI
Layer 3 Linux router.
- 11 -
Summary of Contents for wanguard 6.2
Page 1: ......