DDoS attacks, dropped at the NIC. Watched from here.
The xdp.network console is the window into your OpenShield-XDP servers — live traffic, attack reports, geo breakdowns and the adaptive baseline, streaming from your infrastructure in real time.
- filtering path
- Sub-ms
- filtering path
- on one core, at the NIC driver
- 10M+ pps
- on one core, at the NIC driver
- XDP/eBPF verdicts before sockets
- Kernel-level
- XDP/eBPF verdicts before sockets
- profiles for UDP + voice fleets
- Game-tuned
- profiles for UDP + voice fleets
Everything the firewall sees, in one console
OpenShield-XDP mitigates at line rate inside the NIC driver. The console streams its metrics endpoint into a single pane of glass — per server, per attack, per packet path.
Live traffic
Per-second PPS and bandwidth with incoming vs passed series — mitigation you can watch, not trust.
Proof of mitigation
Bans, drop paths, per-attack forensics. The passed line collapses; the graph proves it.
Geo analytics
Per-country attack breakdowns with flags, rates and share — plus one-click country blocking.
Adaptive baseline
A 30-day baseline memory that learns your traffic and can't be poisoned by a single bad day.
XDP line rate
Drops happen in the NIC driver, before the kernel sees a packet. 10M+ pps on one core.
HWID-bound licensing
Keys bound to hardware, verified online, graceful offline. Your servers stay yours.
Five stages between the flood and your server
Every packet crosses a fixed pipeline inside the NIC driver. Each stage is a verdict measured in nanoseconds — and each one is visible in the console while it happens.
- 01Ban checkKnown offenders never get a second lookup.
- 02Rate limitPer-source floors learned from your own baseline.
- 03Connection trackBogus TCP dies before a socket exists.
- 04Amplification guardDNS/NTP/CLDAP reflection filtered by shape.
- 05L7 filterPattern rules match payload, not just headers.
Two products, one console
Kernel-level filtering for your own servers, or a managed edge WAF for sites and APIs — watched from the same dashboard.
OpenShield-XDP
An eBPF firewall agent that drops L3/L4 floods inside the NIC driver — before the kernel sees a packet.
- Line-rate drop, sub-millisecond overhead
- Game & Game Pro editions: per-player token buckets, A2S/RCON shielding, engine presets
- One-time license, lifetime updates
PingLess WAF
A managed edge WAF in front of your site — layer-7 attacks stopped upstream with a single DNS change.
- HTTP flood absorption and bot filtering at the edge
- WAF Pro: per-route rate shaping, API schema protection, SLA
- Five-minute setup, monthly plan
Protected in three steps
- 01
Connect your server
Install the agent, enable metrics, paste the URL and key into the console. Two minutes, one config line.
Details - 02
Traffic filtered at the kernel
The XDP pipeline learns your baseline and drops floods at the driver — legit traffic never notices.
Details - 03
Watch it in the dashboard
Per-second graphs, per-attack forensics, geo breakdowns and bans — proof, live.
Details
Your next attack report will look different
Register, connect a server with its metrics URL and key, and the next flood arrives as a live graph — not a mystery.
Get started