Satcore On-Premise Shield

Protection, inside your network.

With On-Premise Shield, the protection appliance sits right in your network. Traffic is inspected and attacks are filtered inside your own network, with no rerouting — you run Satcore Shield from your own infrastructure.

In every on-premise deployment

Protection appliance

Runs inside your network, right where your traffic flows.

NetOps control panel

See what your appliance sees: monitor traffic, analyze attacks and manage your rules.

Take a closer look at the panel

Why on-premise?

Protection in your network. Control in your hands.

Filtering happens in your network

Inspection and filtering happen inside your network — no need to reroute your traffic anywhere else.

No tunnels, no detours

No GRE tunnel or external path: protection runs where your traffic already flows.

Sized to your network

The appliance and its configuration are matched to your uplink capacity and traffic profile.

Full visibility with NetOps

The same panel as Remote Shield: monitor traffic, analyze attacks and manage rules.

The same protection engine On-Premise Shield runs the same engine as Remote Shield: protection against every known L3/L4 attack type, right inside your network. Volumetric floods5 Reflection & amplification15 Protocol & state exhaustion8 Multi-vector & evasive4 All attack types and mitigation methods Hide the list

Volumetric floods

Try to fill your line with sheer volume.

  • UDP flood
  • ICMP flood
  • GRE flood
  • IP fragment flood
  • Spoofed-source floods

Reflection & amplification

Abuse open servers to multiply traffic and bounce it at you.

  • DNS
  • NTP
  • SSDP
  • Memcached
  • CLDAP
  • SNMP
  • Chargen
  • WS-Discovery
  • ARMS
  • CoAP
  • NetBIOS
  • Portmap
  • TFTP
  • mDNS
  • RIPv1

Protocol & state exhaustion

Try to exhaust the resources of your servers and devices.

  • TCP SYN flood
  • SYN-ACK flood
  • ACK & ACK-PSH flood
  • RST & FIN flood
  • Invalid TCP flags (XMAS, NULL)
  • Connection floods
  • Teardrop & Ping of Death
  • LAND attack

Multi-vector & evasive

Combine methods and keep changing to slip past defenses.

  • Carpet bombing
  • Pulse-wave (hit-and-run)
  • Multi-vector attacks
  • Game & VoIP UDP floods

How Shield stops them

  • Stateful inspection

    Connection state is tracked, so packets that don’t belong to a valid session — ACK, RST or FIN floods — never reach you.

  • SYN protection

    The TCP handshake is validated before a connection is passed on, so SYN floods can’t exhaust your servers.

  • Protocol validation

    Malformed headers, invalid flag combinations and broken fragments are dropped on sight.

  • Reflection filtering

    Unsolicited responses from reflector protocols are recognized by source port and signature and filtered out.

  • Adaptive thresholds

    Shield learns your normal traffic profile and applies dynamic rate limits as soon as traffic turns anomalous.

  • Line-rate filtering

    A hardware-accelerated, distributed datapath filters at line rate, with 4 Tbps+ of mitigation capacity.

How it works

From first call to protection. In four steps.

  1. Discovery

    Together we review your network, traffic profile and the services you want to protect.

  2. Sizing

    We define the right appliance and configuration and prepare a custom quote.

  3. Deployment

    The appliance is positioned in your network, where your traffic flows.

  4. Protect & monitor

    Shield goes live — and you watch and manage everything in NetOps.

Built for

  • Internet service providers
  • Hosting & cloud providers
  • Data center operators
  • Organizations with their own ASN

Satcore Shield · NetOps Panel

Your protection. In full view.

Every Satcore Shield service comes with the NetOps panel. Watch your protected network’s traffic live, analyze every attack in detail and take action instantly. All included with Shield.

Already a Shield customer? Sign in to NetOps

NetOps Traffic Flow view with clean and blocked traffic charts

01Monitor

Don’t guess. See.

The Traffic Flow view splits everything reaching your network in two: clean traffic and the attacks Shield blocks. The ports and countries an attack comes from are right there on the same page.

  • Switch between Mbit/s and pps in one click
  • Breakdown by protocol and TCP flag
  • Top attacking source ports and countries
  • IP filtering and auto-refresh
Top attacking source ports and the countries attacks come from

02Analyze

Every attack, on record. Every record, the full story.

Every attack Shield detects is recorded in NetOps: target IP, duration, peak traffic and packet rate. Carpet-bombing attacks spread across a whole block are flagged separately. One click takes you into the details.

NetOps Attack Records list
Attack detail view with traffic chart, source countries and carrier networks
Blocked attack 9 min 20 s · Ended
873Gbit/s
Peak traffic
326M pps
Peak packet rate
35.4TB
Traffic blocked
105.9billion
Packets blocked

03In depth

Know your attacker.

See which countries and carrier networks an attack comes from, which ports it targets and which protocol it uses. Then drill down to raw packet samples.

Attack connection flow and raw packet samples
  • Country & ASN

    Where traffic originates, down to the carrier network.

  • Port analysis

    Destination and source ports, by volume and share.

  • Protocol & flags

    UDP and TCP SYN, ACK and RST, broken out.

  • Raw packet samples

    Each one with source IP, VLAN, MAC and ASN.

04Control

Take action. Yourself.

No ticket, no waiting. Set rules and limits and edit PTR records yourself, right in the panel.

Add traffic limit dialog

The right speed for every IP.

Set download and upload limits for a single IP or an entire block. Presets from 1 Mbps to 1 Gbps — or type in any higher value.

IP Management with blackhole, whitelist and international blocking

Blackhole, whitelist and more.

Blackhole any IP or CIDR range, whitelist addresses that should bypass filtering, keep custom IP lists and shut off international traffic in one click.

RDNS PTR record management view

PTR records, on one screen.

Edit the hostname record of every address in your IP blocks — one by one or in bulk.

05Get notified

When there’s an attack, be the first to know.

When Shield detects an attack — and again when it ends — NetOps alerts your team, with target IP, peak values, duration and flow samples right in the message.

  • Webhook support (e.g. Discord)
  • Start and end notifications
  • Total blocked volume and flow samples
NetOps attack notifications delivered to Discord

Included with Shield

Everything you need. In one panel.

Traffic Flow

Clean and blocked traffic, as it happens.

Attack Records

Automatic detection, complete history.

Attack Analysis

Country, ASN, port and packet detail.

Firewall Log

See exactly what your rules are doing.

IP Management

Blackhole, whitelist and custom IP lists.

Block International

Cut off traffic from abroad in one click.

Traffic Limiting

Rate limits per IP and prefix.

RDNS

Edit PTR records one by one or in bulk.

ARP Usage

Keep track of ARP usage on your network.

Sub-users

Give your team access with their own accounts.

Recent Activity

A record of every action taken in the panel.

Webhook Alerts

Alerts your team when an attack is detected.

Already a Shield customer? Sign in to NetOps

Pricing

Priced for your network. A quote made for you.

On-premise deployments have no fixed price — they are priced by the size of your network and your needs. Share a few details and we’ll prepare your custom quote.

Prefer to write directly? [email protected]

This opens a ready-to-send message in your email app.

Our customers

Companies that choose Satcore.