How It Works
NetGuard places a distributed protection network between the app and its origin. The app connects through dynamically assigned gateways, while Shield servers relay traffic to the origin. If a node is attacked or a path degrades, NetGuard selects another route and reconnects seamlessly.
Traffic Path
Node counts are illustrative; each deployment is sized for its traffic and protection requirements.
Gateways distribute app ingress, while Shield servers connect to the origin. The same architecture can forward TCP or UDP traffic from any integrated app and its embedded web traffic.
Node Assignment
NetGuard assigns gateways by country, region, and ISP, then selects the fastest stable path based on live connection quality. The configuration endpoint can use CDN or WAF services to keep node-IP distribution available, while NetGuard nodes continue to carry application traffic. Gateways and Shield servers can be added to distribute ingress and expand overall defense capacity.
Failover
If the current node becomes unavailable, the client switches to another available node and reconnects seamlessly, reducing disconnects and repeated logins. Validate the experience with your app during the one-week trial.
Origin Protection
The origin is never published to clients and accepts connections only from approved Shield servers, preventing direct attacks that bypass the protection path.
Learn More
- Read the Product Overview for capabilities and platform support;
- Check Free Trial for regional restrictions and prerequisites;
- Follow the Developer Guide for synchronous client initialization.