Skip to content
Anti-DDoS coverage

DDoS protection, per game and application

47 games, voice servers, web and remote-access protocols that have their own protocol-aware filter on our network — not a generic rate limit. Everything else falls back to stateful TCP or UDP filtering, so nothing is left unprotected.

How the filtering works

Dropped in the network driver, before the kernel sees it

XDP at the edge

Our mitigation runs in XDP (eXpress Data Path), inside the network driver — the earliest point a packet can be examined. Dropping an attack packet there costs a fraction of what it costs once the kernel networking stack has processed it, which is what makes filtering at line rate possible without adding latency your players can feel.

Filters that read the protocol

A generic filter can only count packets, so under attack it guesses — and drops real players along with the flood. Each filter below parses the application's own traffic: it knows what a genuine Minecraft handshake, A2S query or FiveM connection looks like, and discards what is malformed or forged.

Strictness that matches the attack

The busier titles have several tiers — light, strict, ultra-strict and a connection challenge. A light profile is friendlier to unusual but legitimate clients; a challenge asks more of every connection, which is what you want mid-attack and more than you need on a quiet day.

A2S query caching

Source engine servers answer A2S queries so they appear in the server browser — and the reply is bigger than the request, which makes it an amplification target. We cache that answer at the edge, so the flood never reaches your server and your listing stays up.

SYN proxy for web traffic

HTTP and HTTPS get a SYN proxy in front: the handshake is completed at the edge and only a real, established connection is passed through. Floods that never finish the handshake never reach your application.

On our own network

Everything above happens in Frankfurt on AS214918, our own autonomous system, on the path your traffic already takes. There is no separate scrubbing detour to add a hop. How the mitigation works in detail.

Coverage

Game servers

Each of these has a filter that understands the game's own handshake and packet shapes, rather than a generic rate limit that would drop real players along with the attack.

Minecraft (Java) TCP

Three strictness levels plus a connection challenge, for servers that get hit during events.

Hosting for this
Minecraft (Bedrock / NetherNet) TCP + UDP

Covers both halves of Bedrock's newer transport — the signaling channel and the WebRTC media path.

Hosting for this
Counter-Strike 2 UDP

Source 2 A2S filtering, including a strict mode for servers under sustained query floods.

Hosting for this
Counter-Strike: Global Offensive UDP

Its own CS:GO profile alongside the generic Source engine filter.

Counter-Strike 1.6 UDP

GoldSrc answers A2S queries like Source does, so it is covered by the A2S query filter alongside the generic UDP profile.

Hosting for this
Source engine (A2S) UDP

The shared filter behind TF2, Garry's Mod, L4D2, Insurgency and every other Source title, with A2S query caching so the server browser never becomes the attack surface.

FiveM TCP + UDP

Light, strict and ultra-strict tiers, a connection challenge, and a separate profile for the voice channel.

Hosting for this
RedM TCP + UDP

Shares the Cfx.re transport with FiveM, so the same filtering applies.

Hosting for this
alt:V TCP + UDP

Separate TCP and UDP profiles, plus a strict UDP mode.

Hosting for this
San Andreas Multiplayer / open.mp UDP

The SA-MP protocol filter, which open.mp servers use too.

Hosting for this
Multi Theft Auto UDP

Its own MTA protocol profile.

Hosting for this
Rust UDP

Filtered through the RakNet profile, which parses the protocol rather than guessing at it.

Hosting for this
ARK: Survival Ascended UDP

A dedicated ASA profile, separate from the older Evolved one.

Hosting for this
ARK: Survival Evolved UDP

Its own filter plus the ASE query profile.

Hosting for this
Palworld UDP

A dedicated Palworld profile.

Hosting for this
DayZ UDP

A dedicated DayZ profile.

Hosting for this
Arma 3 UDP

A dedicated Arma 3 profile.

Hosting for this
SCP: Secret Laboratory UDP

Its own SCP:SL protocol filter.

Hosting for this
Squad UDP

Filtered on the UDP application profile.

Hosting for this
Left 4 Dead 2 UDP

A dedicated L4D2 profile on top of the Source engine filter.

Hosting for this
Garry's Mod TCP + UDP

Stateful TCP plus the Source engine A2S filter.

Hosting for this
Terraria UDP

Covered by the RakNet protocol filter.

Hosting for this
7 Days to Die UDP

Covered by the RakNet protocol filter.

Hosting for this
Factorio UDP

A dedicated Factorio profile.

Hosting for this
Hurtworld UDP

A dedicated Hurtworld profile.

Hosting for this
The Isle UDP

A dedicated The Isle profile.

Hosting for this
Path of Titans UDP

A dedicated Path of Titans profile.

Hosting for this
Unreal Engine 5 titles UDP

A UE5 transport filter, which covers newer titles built on the engine.

Tibia / Open Tibia (OTS) TCP

A dedicated Tibia profile plus stateful TCP.

Hosting for this
Metin2 TCP

Filtered on the stateful TCP profile.

Hosting for this
RuneScape private servers (RSPS) TCP

A dedicated RSPS profile.

Hosting for this
Coverage

Voice servers

Voice is usually the first thing to break under an attack, because it is latency-sensitive and runs on its own ports.

TeamSpeak 3 (voice) UDP

A dedicated TeamSpeak protocol filter on the voice port.

TeamSpeak 3 (query & file transfer) TCP

A separate filter for the query and file-transfer ports, with a strict mode.

FiveM voice UDP

Its own profile, separate from the FiveM game channel.

Hosting for this
Plasma Voice UDP

Filtered on the UDP application profile, for Minecraft proximity voice.

Hosting for this
Coverage

Web & applications

Web traffic gets a different treatment: a SYN proxy in front of the connection, and a browser challenge for floods that look like real requests.

HTTP TCP

Stateful filtering with an optional SYN proxy that completes the handshake before anything reaches your server.

HTTPS / TLS TCP

A TLS-aware filter with a strict mode.

txAdmin TCP

The FiveM and RedM admin panel gets its own filter and an access challenge.

Hosting for this
FTP TCP

A dedicated FTP profile.

DNS UDP

A DNS protocol filter — DNS is both a target and a favourite amplification source.

NTP UDP

An NTP filter, for the other classic amplification vector.

Coverage

Remote access & VPN

The ways you reach the box are worth protecting too — losing SSH during an attack is how a small incident becomes a long one.

SSH TCP

A dedicated SSH filter.

Remote Desktop (RDP) TCP + UDP

Separate TCP and UDP profiles for RDP.

WireGuard UDP

A WireGuard protocol filter — the same one behind our Anti-DDoS VPN.

OpenVPN UDP

Standard and strict profiles, including one for configurations without tls-crypt.

Coverage

Anything else

A protocol with no dedicated profile still gets filtered — it falls back to the generic ones rather than being passed through.

Any TCP application TCP

Stateful TCP filtering for anything without its own profile.

Any UDP application UDP

Generic UDP filtering for anything without its own profile.

Questions

About the filtering

My game is not on the list. Am I unprotected?

No. Anything without its own profile falls back to the generic stateful TCP or UDP filter, so it is still filtered — just with rules that are not tuned to that specific protocol. If you are running something popular that deserves its own profile, tell us and we will look at adding one.

What does a "protocol-aware" filter actually do differently?

A generic filter can only count packets, so under attack it has to guess, and it drops real players along with the flood. A protocol-aware filter parses the traffic: it knows what a real Minecraft handshake or an A2S query looks like, so it can throw away what is malformed or forged and keep what is genuine.

What is XDP and why does it matter here?

XDP (eXpress Data Path) runs the filtering in the network driver, before the packet reaches the normal kernel networking stack. That is the cheapest possible point to drop traffic, which is what makes line-rate filtering possible without adding meaningful latency for real players.

Does filtering add ping?

Not in a way players notice. Filtering happens at the edge in Frankfurt on the path your traffic already takes, and dropping a packet in XDP costs a fraction of what it costs once the kernel has processed it.

Why do some games have several strictness levels?

Because the right trade-off changes with the attack. A light profile is friendlier to unusual but legitimate clients; a strict or challenge profile asks more of every connection, which is what you want mid-attack and more than you need on a quiet Tuesday.

What is A2S query caching?

Source engine servers answer A2S queries to appear in the server browser, and that reply is larger than the request — which makes it an amplification target. Caching the answer at the edge means the flood never reaches your server and your listing stays up.

Is this included or an add-on?

Included. Anti-DDoS filtering comes with the game servers, web hosting, VDS and dedicated servers at no extra cost. Layer 7 filtering and extra IP transit are separate products under Networking.

Can I see the protection working?

Yes — the client area shows your traffic and any mitigation events on your IPs, and live service status is on status.esagames.ro.

Protected from the first packet

Anti-DDoS is included on every game server, VDS and web hosting plan — nothing to enable, no extra cost.