Network Security
Attacks end at the edge,
not in your server.
Always-on DDoS mitigation included on every plan, at every location. No configuration, no premium tier, no extra cost.
Process
Filtering happens before traffic reaches you.
When an attack starts, mitigation engages automatically — nothing to toggle, nothing to configure.
Detect
Traffic anomalies identified in real time across network-wide telemetry.
Engage
Filtering activates automatically on attack signatures — no human in the loop.
Filter
Malicious traffic dropped upstream, before it can touch your node.
Forward
Only verified flows reach your server — with zero added latency.
Coverage
Comprehensive coverage across the stack.
Layer 3 — Network
Volumetric floods (UDP, ICMP, fragmentation) absorbed at network edge via anycast scrubbing.
Layer 4 — Transport
SYN floods, ACK floods, connection exhaustion — stateful filtering with rate limiting.
Layer 7 — Application
HTTP floods, Slowloris, DNS amplification, game-specific vectors — signatures and behavioral analysis.
Game protocol aware
Minecraft, FiveM, Rust, Valheim — legitimate player traffic preserved during mitigation.
No false positives
Legitimate players stay connected. We tune signatures per game to avoid blocking real traffic.
Always included
Not an add-on. Not a higher tier. Every VPS and game server gets full protection automatically.
Technology
Built on the kernel's fastest data paths.
We use purpose-built Linux packet processing, each layer dropping traffic as early as possible.
eBPF / XDP
XDP runs eBPF programs directly at the network driver hook — before the main kernel stack. Malicious packets dropped at NIC line-rate.
DPDK
For extreme packet-per-second loads, DPDK bypasses the kernel entirely — sustaining tens of millions of packets per second per node.
nftables rate control
Per-port rate limits, dynamic IP reputation blacklists and connection budgets. Rules expire automatically.
Anycast & BGP edge
Your IP range announced across multiple scrubbing centers. Traffic lands on the nearest edge node.
L3–L7 engine
Layer 3 absorbs volumetric floods, layer 4 handles stateful attacks, layer 7 applies game-aware signatures.
No permutation-lock
Both DPDK and XDP used where they fit. Drop junk early, keep heavy logic where it pays.
Capacity
Absorption capacity that scales.
Global scrubbing capacity across all locations.
Scrubbing centers in major transit hubs worldwide.
Typical time from detection to full mitigation engagement.
Anycast routing
Traffic routed to the nearest scrubbing center automatically.
No latency penalty
Clean traffic passes through without added latency.
Continuous adaptation
Signatures updated in real time from global threat intelligence.
Post-attack reports
Detailed breakdown of vectors, volume, and mitigation actions.
FAQ
Common questions.
Is DDoS protection really free on every plan?
Yes. Every VPS and game server plan includes full L3–L7 mitigation at no additional cost. There is no "premium protection" tier.
Do I need to configure anything?
No. Protection is active by default. Mitigation engages automatically when attack patterns are detected. Zero configuration required.
Will legitimate players be blocked during an attack?
Our game-aware signatures are tuned to preserve legitimate player connections while dropping attack traffic. False positives are rare.
Can I see attack details after the fact?
Yes. Contact support and we will provide a breakdown of attack vectors, peak volume, duration, and mitigation actions taken.
What if the attack exceeds your capacity?
Our global anycast network provides 3+ Tbps aggregate scrubbing capacity. Attacks exceeding local capacity are distributed across multiple scrubbing centers.
Does protection add latency to clean traffic?
No. Clean traffic passes through our edge without measurable latency overhead. Mitigation logic only engages on detected attacks.
Included
Protection that ships with your server.
No add-ons. No configuration. No extra cost. DDoS mitigation is simply part of the infrastructure.