Under Attack?
Поиск

On-Premises DDoS Protection

StormWall Appliance

The top-tier StormWall cloud protection — now inside your perimeter

13 years of Cloud
DDoS Experience

Built on technologies proven by 13 years of StormWall cloud DDoS protection on real clients all over the world.

Single License —
All Included

L3–L5 OSI protection, specialized filters, clustering, dashboards, API — all in one license, no add-ons required.

Fully Outsourced Protection

StormWall SOC engineers take over solution — writing rules and mitigating attacks (Support tier — Private).

What Is StormWall Appliance

StormWall Appliance is a software solution for protecting network infrastructure and services from DDoS attacks. It is installed on your own hardware and processes traffic locally — without sending it to external networks.

At its core is StormWall’s proprietary technology: low-level packet processing based on DPDK and optimized high-speed filtering algorithms.

The system handles substantial traffic volumes with minimal latency — even under intensive DDoS attacks.

Available from a Single License

All protection features, filters
and tools — in one license

L3–L5 OSI DDoS Protection

Enterprise Service Protection (VPN, SIP, etc.)

Protocol-Aware Filters for DNS, QUIC, and TLS JA3

Traffic Capture
and Analysis (PCAP)

Customizable Dashboards and Metrics

Operation in Isolated Networks

Filtering Node

Basic Support Included in Year 1

REST API for
External
Integrations

Gaming Protocol Protection (RakNet,
SA-MP, CS, Steam)

How It Works

Per-packet real-time DDoS filtering

Legitimate Users

Regular Traffic

DDoS Attack

Malicious Traffic

StormWall Appliance

Multi-Layer DDoS Filtering
at L3–L5 OSI

Your Infrastructure

Applications and Services

Filtered-Out DDoS Attack

What You Get

Additional benefits of StormWall Appliance

Simple, Fast Integration

Fits into your existing network architecture with no significant changes required.

Flexible Licensing

Billed by active port capacity. Perpetual license or annual Subscription — no hidden fees.

Clustering and Scaling

Protects infrastructure at any scale — from individual services to large carrier networks.

In-House Developed

Full control over roadmap, updates and support — no third-party dependencies.

Book a Demo

First Name
Last Name
Phone
Email

Attacks It Protects Against

The solution covers all modern
DDoS attack vectors, including:

Volumetric
DDoS Attacks

Protection against floods
and bandwidth exhaustion

Attacks on Enterprise
Services

Protection for VPN, SIP and other enterprise services

Reflection and Amplification Attacks

Filtering of IP fragmentation
and MTU anomalies

Fragmentation
Attacks

Protection against SYN and TCP floods and connection-table exhaustion

Attacks in Encrypted
Traffic

Filtering of attacks
in TLS/QUIC traffic without decrypting it

TCP Floods and DNS Attacks

Protection from all TCP floods and DNS attack vectors

Attacks on Gaming
and VOIP Services

Specialized filters for gaming
and VoIP protocols

Attacks
From Specific Networks

Traffic filtering by ASN, IP prefixes, and network policies

Licensing Models

Choose a model that fits your
planning horizon

Subscription

Recurring subscription, per year

  • Right of use for the subscription term
  • Basic support included for year 1
  • Optimal for project-based work (OpEx); low entry threshold

Perpetual

One-time purchase, one-off payment

  • Perpetual right of use
  • Basic support included for year 1
  • Optimal for long-term use (CapEx)

Pricing starts at the minimum configuration (10 Gbps). Final pricing is calculated individually based on active port capacity, number of installations and support tier.

* For 2- and 4-socket servers, 2 or 4 software instances are deployed with capacity divided equally among them.
The license price is determined by the total active port capacity and does not depend on the number of sockets

Support Tiers

From basic maintenance to fully
outsourced protection

Basic

17% of annual cost

  • Ticket-based support, no guaranteed SLA
  • Regular patches and updates
  • Documentation and knowledge base
  • Client handles attack response and rule configuration independently

For teams with information-security expertise

Recommended

Advanced

30% of annual cost (+13% in year 1)

  • 24/7 ticket intake with guaranteed SLA
  • Out-of-cycle patches for non-critical bugs
  • Active implementation support
  • Response time: from 1 hour

For mid-sized teams and growing clients

Private

Custom, on request

  • StormWall SOC takes over protection 24/7
  • Dedicated technical account manager
  • Rule configuration and attack mitigation handled by our team
  • Regular incident reports
  • Response time: 15 minutes

Fully outsourced protection —
for teams without in-house DDoS expertise

Downloadable Materials

Everything you need to get started
with the product

How to Get Started

We support you at every step —
from request to full implementation

01

Qualification

Submit a request, fill out the intake form or request a demo from the sales team

02

Compatibility Check

Send us your server configuration — we’ll verify compatibility

03

License Issuance

Tailored to your active port capacity, support tier and number of installations

04

Deployment

Installation from a private repository. Deployment — from 1 day

05

Free 30-Day Trial

Run it on your own traffic at no cost. Move to commercial terms when ready.

Frequently Asked Questions

How does StormWall Appliance differ from StormWall’s cloud protection?

Both share the same StormWall filtering technology, delivered in two formats. In the cloud, traffic first passes through our filtering network and reaches you already cleaned. With Appliance, the solution is deployed inside your own infrastructure: traffic is processed on your servers and data does not leave your perimeter.

The cloud is quicker and easier to enable, while Appliance gives you full control over your traffic and data. The attack profile also matters: steady attacks within your channel capacity are effectively filtered by Appliance, while high-volume peak attacks that exceed the channel’s bandwidth are handled by our cloud protection.

Which fits your case depends on your security team requirements, industry regulator and attack profile — we’ll help you decide during the first project discussion.

Does StormWall Appliance work on its own, or together with the cloud?

Both modes are supported — your choice.

Standalone.
Appliance is deployed within your perimeter as a full-fledged on-premises DDoS protection at L3–L5 OSI: volumetric floods, TCP stack attacks, DNS, gaming protocols and attacks in encrypted traffic.

In tandem with StormWall cloud protection.
Adds application-layer (L7) protection — HTTP Flood, Slow HTTP, WAF. For high-volume attacks exceeding your channel bandwidth, StormWall cloud protection may be used. The specific integration scenario is discussed on a case-by-case basis.

Do we need to buy hardware from you?

No. StormWall Appliance is delivered as software and runs on your servers — physical or virtual. Standard x86 platforms that meet the system requirements are sufficient.

We recommend using hardware platforms that have passed StormWall internal testing. Deployment on other platforms is allowed — in that case compatibility is assessed individually. The license is bound to active port capacity, not to specific hardware — you can replace a server without re-issuing the license.

We don’t have a dedicated DDoS team. Who will tune rules and mitigate attacks?

It depends on the support tier. On Basic you manage the solution yourself; we provide updates, documentation and ticket responses — suitable for teams with in-house InfoSec expertise.

On Advanced you get guaranteed SLA by incident priorities and active hands-on assistance from our engineers during deployment.

If you have no in-house team at all, there is the Private tier: StormWall specialists take over the solution completely — our engineers configure rules, mitigate attacks, investigate incidents and send reports, and you get a dedicated technical account manager. In effect, you get an on-premises solution managed like a cloud service — a rare offering in the on-premises market.

Is the solution suitable for the public sector, critical infrastructure operators and isolated networks?

Yes. Traffic is processed locally and never leaves your perimeter. For isolated networks without internet access, an offline licensing option with a hardware key is available — the solution operates without connecting to StormWall servers.

On-site deployment support (available on request).

Can we test the solution before purchasing?

Yes. After deployment, a free trial begins — running on real traffic, in your own infrastructure and, if needed, alongside the solution you currently use. The deployment itself takes as little as one day — including setup and starting filtering.

The demo has no strings attached: if the result doesn’t suit you, you simply don’t move on to commercial operation.

Why StormWall Appliance

Consultation on architecture and deployment options

Product demo based on real-world scenarios

Pilot testing within your infrastructure

Right-sized configuration and licensing model

Fast commercial proposal

On-site support (for public sector and CII)

Book a Demo

First Name
Last Name
Phone
Email
Comment (optional)