Network Security

Attacks end at the edge,
not in your server.

Always-on DDoS mitigation included on every plan, at every location. No configuration, no premium tier, no extra cost.

L3–L7 Always-on ₹0 added Zero config

Process

Filtering happens before traffic reaches you.

When an attack starts, mitigation engages automatically — nothing to toggle, nothing to configure.

01

Detect

Traffic anomalies identified in real time across network-wide telemetry.

02

Engage

Filtering activates automatically on attack signatures — no human in the loop.

03

Filter

Malicious traffic dropped upstream, before it can touch your node.

04

Forward

Only verified flows reach your server — with zero added latency.

Coverage

Comprehensive coverage across the stack.

01

Layer 3 — Network

Volumetric floods (UDP, ICMP, fragmentation) absorbed at network edge via anycast scrubbing.

UDPICMPFrag
02

Layer 4 — Transport

SYN floods, ACK floods, connection exhaustion — stateful filtering with rate limiting.

SYNACKConn
03

Layer 7 — Application

HTTP floods, Slowloris, DNS amplification, game-specific vectors — signatures and behavioral analysis.

HTTPDNSSlowloris
04

Game protocol aware

Minecraft, FiveM, Rust, Valheim — legitimate player traffic preserved during mitigation.

255653012028015
05

No false positives

Legitimate players stay connected. We tune signatures per game to avoid blocking real traffic.

TunedPer game
06

Always included

Not an add-on. Not a higher tier. Every VPS and game server gets full protection automatically.

All plans₹0

Technology

Built on the kernel's fastest data paths.

We use purpose-built Linux packet processing, each layer dropping traffic as early as possible.

eBPF / XDP

XDP runs eBPF programs directly at the network driver hook — before the main kernel stack. Malicious packets dropped at NIC line-rate.

DPDK

For extreme packet-per-second loads, DPDK bypasses the kernel entirely — sustaining tens of millions of packets per second per node.

nftables rate control

Per-port rate limits, dynamic IP reputation blacklists and connection budgets. Rules expire automatically.

Anycast & BGP edge

Your IP range announced across multiple scrubbing centers. Traffic lands on the nearest edge node.

L3–L7 engine

Layer 3 absorbs volumetric floods, layer 4 handles stateful attacks, layer 7 applies game-aware signatures.

No permutation-lock

Both DPDK and XDP used where they fit. Drop junk early, keep heavy logic where it pays.

Capacity

Absorption capacity that scales.

3+ Tbps

Global scrubbing capacity across all locations.

15+

Scrubbing centers in major transit hubs worldwide.

< 5 s

Typical time from detection to full mitigation engagement.

Anycast routing

Traffic routed to the nearest scrubbing center automatically.

No latency penalty

Clean traffic passes through without added latency.

Continuous adaptation

Signatures updated in real time from global threat intelligence.

Post-attack reports

Detailed breakdown of vectors, volume, and mitigation actions.

Straight answers

What protection can and cannot promise.

We would rather set the expectation up front than let you find the edge cases during an incident.

01

Cloudflare is not 100% of the answer

Using Cloudflare protection does not mean you are 100% protected from DDoS attacks. In some cases, when an attack occurs, around 5–10% of the attack traffic may still pass through Cloudflare, and there is also a possibility that even 1% of the attack traffic could still have an impact on your services.

02

We null-route at the network level too

That is why we also handle DDoS attacks at the network level using our own automated protection software. We configure specific thresholds — when traffic exceeds the defined level, the system automatically null-routes the affected IP address for a set period, protecting the server and the wider network.

03

Attacks can reach you indirectly

A DDoS attack does not necessarily have to target your specific IP address to affect your services. An attack targeting another IP address within the same network or infrastructure can potentially impact your services too, depending on the attack size and overall network conditions.

While we run multiple layers of protection, no DDoS protection can guarantee 100% protection or zero impact in every situation. What we commit to is layered mitigation, honest thresholds, and a team that will tell you exactly what happened after an attack — see our SLA for the specifics.

FAQ

Common questions.

Is DDoS protection really free on every plan?

Yes. Every VPS and game server plan includes full L3–L7 mitigation at no additional cost. There is no "premium protection" tier.

Do I need to configure anything?

No. Protection is active by default. Mitigation engages automatically when attack patterns are detected. Zero configuration required.

Will legitimate players be blocked during an attack?

Our game-aware signatures are tuned to preserve legitimate player connections while dropping attack traffic. False positives are rare.

Can I see attack details after the fact?

Yes. Contact support and we will provide a breakdown of attack vectors, peak volume, duration, and mitigation actions taken.

What if the attack exceeds your capacity?

Our global anycast network provides 3+ Tbps aggregate scrubbing capacity. Attacks exceeding local capacity are distributed across multiple scrubbing centers.

Does having Cloudflare mean I am 100% protected?

No. Some attack traffic can still pass through Cloudflare — roughly 5–10% during an attack, and in rare cases even 1% of it may have some impact. That is why we also run network-level protection with automatic null-routing above defined thresholds. Multiple layers reduce risk substantially, but no mitigation can promise zero impact in every situation.

Can an attack on someone else take my server down?

It can. An attack aimed at another IP on the same network or infrastructure can affect your services as well, depending on the attack size and current network conditions. This is one of the reasons we null-route aggressively and keep capacity headroom on every segment.

Does protection add latency to clean traffic?

No. Clean traffic passes through our edge without measurable latency overhead. Mitigation logic only engages on detected attacks.

Included

Protection that ships with your server.

No add-ons. No configuration. No extra cost. DDoS mitigation is simply part of the infrastructure.