DDoS attacks, dropped at the NIC. Watched from here.

The xdp.network console is the window into your OpenShield-XDP servers — live traffic, attack reports, geo breakdowns and the adaptive baseline, streaming from your infrastructure in real time.

filtering path
Sub-ms
filtering path
on one core, at the NIC driver
10M+ pps
on one core, at the NIC driver
XDP/eBPF verdicts before sockets
Kernel-level
XDP/eBPF verdicts before sockets
profiles for UDP + voice fleets
Game-tuned
profiles for UDP + voice fleets
console.pingless.org — production-eu-1 LIVE
UNDER ATTACK — UDP_FLOOD
Packets/sec
48.2k
Bandwidth
412 Mbps
Active bans
128
Packets/sec
incoming passed trigger

Everything the firewall sees, in one console

OpenShield-XDP mitigates at line rate inside the NIC driver. The console streams its metrics endpoint into a single pane of glass — per server, per attack, per packet path.

Live traffic

Per-second PPS and bandwidth with incoming vs passed series — mitigation you can watch, not trust.

Proof of mitigation

Bans, drop paths, per-attack forensics. The passed line collapses; the graph proves it.

Geo analytics

Per-country attack breakdowns with flags, rates and share — plus one-click country blocking.

Adaptive baseline

A 30-day baseline memory that learns your traffic and can't be poisoned by a single bad day.

XDP line rate

Drops happen in the NIC driver, before the kernel sees a packet. 10M+ pps on one core.

HWID-bound licensing

Keys bound to hardware, verified online, graceful offline. Your servers stay yours.

Five stages between the flood and your server

Every packet crosses a fixed pipeline inside the NIC driver. Each stage is a verdict measured in nanoseconds — and each one is visible in the console while it happens.

  • 01Ban checkKnown offenders never get a second lookup.
  • 02Rate limitPer-source floors learned from your own baseline.
  • 03Connection trackBogus TCP dies before a socket exists.
  • 04Amplification guardDNS/NTP/CLDAP reflection filtered by shape.
  • 05L7 filterPattern rules match payload, not just headers.
Attack reportUDP FLOOD
Peak
92.4k pps
Bandwidth
812 Mbps
Sources
1,204 IPs
Mitigated in
3.2s
Duration
44s
Dropped
3.9M pkts
Top origins
🇩🇪Germany
38%
🇨🇳China
24%
🇧🇷Brazil
15%
🇳🇱Netherlands
9%
All 1,204 sources banned at the driver. Server never noticed.

Two products, one console

Kernel-level filtering for your own servers, or a managed edge WAF for sites and APIs — watched from the same dashboard.

OpenShield-XDP

An eBPF firewall agent that drops L3/L4 floods inside the NIC driver — before the kernel sees a packet.

  • Line-rate drop, sub-millisecond overhead
  • Game & Game Pro editions: per-player token buckets, A2S/RCON shielding, engine presets
  • One-time license, lifetime updates
OpenShield-XDP docs

PingLess WAF

A managed edge WAF in front of your site — layer-7 attacks stopped upstream with a single DNS change.

  • HTTP flood absorption and bot filtering at the edge
  • WAF Pro: per-route rate shaping, API schema protection, SLA
  • Five-minute setup, monthly plan
PingLess WAF docs

Protected in three steps

  1. 01

    Connect your server

    Install the agent, enable metrics, paste the URL and key into the console. Two minutes, one config line.

    Details
  2. 02

    Traffic filtered at the kernel

    The XDP pipeline learns your baseline and drops floods at the driver — legit traffic never notices.

    Details
  3. 03

    Watch it in the dashboard

    Per-second graphs, per-attack forensics, geo breakdowns and bans — proof, live.

    Details

Your next attack report will look different

Register, connect a server with its metrics URL and key, and the next flood arrives as a live graph — not a mystery.

Get started