🛡️ Out Of Line Shield
The Out-of-Line Shield (OOL Shield) protects sFlow/sampling-capable networks. It watches sampled traffic and reacts to anything unusual: it tracks it, alerts you, and acts on it through Detection Pipelines that you build yourself in an easy-to-use admin UI, tailored to your network.
The OOL Shield is sold as a managed software rental for business, enterprise, hosting, and ISP networks. You provide the hardware it runs on, plus a separate management node or VPS for your own instance of our On Premise / OOL Management suite, which includes an API, panel, Grafana, and more. Because each customer runs an isolated setup, your uptime never depends on a single shared platform.
Pricing and Sales Timeline
We know timing and pricing matter, and both depend on your needs.
When you contact our sales team, tell us how urgent your deployment is and we will move as fast as we can.
The OOL Shield starts at around €250/month. Pricing is based on your 95th-percentile traffic and the support plan you need. Setup is mostly automated, but our engineers review every deployment before it goes into production.
From your first "Hi!" to running in production, the process looks like this:
- You reach out to our sales team, who answer your setup and feature questions and prepare a quote.
- Once you agree on the quote, our engineering team guides the setup over chat or scheduled calls.
- After the software is set up (partly automated, partly with our engineers and support team), engineering reviews the deployment one last time to confirm it is production-ready.
- You test it on a few prefixes or a small share of production traffic, then move to full production.
Example Use Cases
Because you build the Detection Pipelines yourself, the OOL Shield fits almost any flow-based use case. Below are the most common ones we see. For anything else, our sales engineers are happy to help you plan it.
- Accurate, automated blackholing with the VAD algorithm.
- Auto-enabling On Premise protection for attacked IPs, for on-demand mitigation.
- Autonomous attack detection and mitigation using GAD and FlowSpec actions.
- Re-routing DFZ-routable prefixes to protected upstreams when under attack.
- Redirecting traffic with FlowSpec to protection appliances.