On-Premises anti-DDoS
for hosting providers
and enterprises.

DamWall runs inside your own datacenter, mitigating attacks where your traffic already lives. No proxy, no third-party network, and none of the latency that comes from routing through someone else's cloud.

Mitigation that lives inside your network.

One filtering pipeline, four capabilities, all running on hardware you own and control.

Runs on your hardware, in your datacenter

DamWall deploys as dedicated mitigation nodes inside your own network, not in a remote scrubbing center. Each node filters up to 200 Gbps of attack traffic, and you add capacity simply by adding nodes. Effective throughput scales with your hardware and NIC.

Bare metal on your own equipment and your own ASN
Inline on inbound traffic, with egress untouched
Per-node licensing, with no traffic-based or per-attack billing

What a single attack costs your fleet.

Set your monthly revenue below. The figure above is what one major DDoS attack typically costs you: direct downtime, SLA credits to affected customers, and the churn that follows over the next 30 days.

$6,000 per major attack

Estimate: about 6% of monthly revenue per major incident.

Or enter exact:
$ /mo

Monthly revenue

Sources: Gartner, $5,600/min average enterprise downtime cost. Kaspersky DDoS Intelligence Report, a typical mitigated incident leaves services degraded for 4-6 hours. Hosting-industry post-incident churn, 5-8% of affected customers within 30 days. IBM/Ponemon 2024, average incident cost $4.88M.

Questions buyers ask before they sign.

Can't find your answer?

Book your walkthrough

We use these details only to schedule and prepare your call. No marketing email, ever.

Get in Touch

DamWall is deployed inline on inbound traffic only. Ingress packets traverse the scrubbing pipeline on your mitigation nodes; egress returns directly from your origin to the client over your existing routing, with no proxy, no TCP termination, and no PoP hop. Because the return path is never diverted, application latency is identical to your datacenter's native egress. The only added cost is sub-millisecond inspection on the inbound leg.

DamWall sits in front of your origin as an inline filtering layer, so onboarding is a routing change rather than a migration. For a single server you redirect its inbound traffic through a mitigation node; for a fleet you place nodes at your ingress points and scale horizontally as throughput grows (up to 200 Gbps per node, subject to hardware and NIC). No agent runs on protected machines and no application changes are required. During the walkthrough we size node count against your peak inbound pps/bps and map it to your existing topology and ASN.

Per-protocol filters, all controllable through the API. Full set:

TCP
  • Generic TCP
  • Botnet TCP
  • Web SYN-ACK
  • Minecraft generic
  • Minecraft anti-bot
  • TeamSpeak
  • FiveM
  • FiveM HTTP
  • FiveM txAdmin
  • RDP
  • SSH
UDP
  • Generic amplification
  • Source (Source Engine Query, Source 1, Source 2, Steamworks)
  • Unreal Engine 4 & 5
  • FiveM/RedM
  • Teeworlds 0.7 / DDNet
  • SCP:SL
  • TeamSpeak
  • Unreal Tournament 99
  • Arma Reforger
  • OpenVPN
  • WireGuard
  • Battlefield 2 Reality Mod
  • Minecraft Bedrock
  • Mordhau
  • Hytale
  • Scum
  • Rust
  • Discord
  • Simple Voice Chat (Minecraft proximity chat)
  • Plasmo Voice (Minecraft proximity chat)
  • SIP
  • ICMP

Contractually: 99.99% scrubbing-plane availability and time-to-mitigation under three seconds for known attack classes. Breaches are credited automatically against your next invoice, with no ticket required. The SLA covers the mitigation layer; origin and upstream-transit availability remain your responsibility.

Per-node licensing, decoupled from traffic volume. Each node mitigates up to 200 Gbps of attack traffic depending on hardware and NIC, and you scale by adding nodes. Cost is therefore a function of provisioned capacity, not of monthly bandwidth or per-attack scrubbing, so there are no overage or surge charges during an incident. Contact us for node sizing and a quote.

A 20-minute call.
Your network topology.
A real mitigation plan.

What to expect on the call

  • A walk through your current topology and any prior attacks
  • A live mitigation demo under a synthetic L7 game-protocol flood
  • Node sizing, so you know how many nodes you actually need
  • Per-node licensing and an SLA aligned to your fleet

Run by network engineers who have built mitigation pipelines for game-hosting providers and high-risk, DDoS-prone networks.

Book your walkthrough

We use these details only to schedule and prepare your call. No marketing email, ever.