Skip to content

How It Works

NetGuard places a distributed protection network between the app and its origin. The app connects through dynamically assigned gateways, while Shield servers relay traffic to the origin. If a node is attacked or a path degrades, NetGuard selects another route and reconnects seamlessly.

Traffic Path

Gateways distribute app ingress, while Shield servers connect to the origin. The same architecture can forward TCP or UDP traffic from any integrated app and its embedded web traffic.

Node Assignment

NetGuard assigns gateways by country, region, and ISP, then selects the fastest stable path based on live connection quality. The configuration endpoint can use CDN or WAF services to keep node-IP distribution available, while NetGuard nodes continue to carry application traffic. Gateways and Shield servers can be added to distribute ingress and expand overall defense capacity.

Failover

If the current node becomes unavailable, the client switches to another available node and reconnects seamlessly, reducing disconnects and repeated logins. Validate the experience with your app during the one-week trial.

Origin Protection

The origin is never published to clients and accepts connections only from approved Shield servers, preventing direct attacks that bypass the protection path.

Learn More

Keep Apps Online.