DDoS protection, per game and application
47 games, voice servers, web and remote-access protocols that have their own protocol-aware filter on our network — not a generic rate limit. Everything else falls back to stateful TCP or UDP filtering, so nothing is left unprotected.
Dropped in the network driver, before the kernel sees it
XDP at the edge
Our mitigation runs in XDP (eXpress Data Path), inside the network driver — the earliest point a packet can be examined. Dropping an attack packet there costs a fraction of what it costs once the kernel networking stack has processed it, which is what makes filtering at line rate possible without adding latency your players can feel.
Filters that read the protocol
A generic filter can only count packets, so under attack it guesses — and drops real players along with the flood. Each filter below parses the application's own traffic: it knows what a genuine Minecraft handshake, A2S query or FiveM connection looks like, and discards what is malformed or forged.
Strictness that matches the attack
The busier titles have several tiers — light, strict, ultra-strict and a connection challenge. A light profile is friendlier to unusual but legitimate clients; a challenge asks more of every connection, which is what you want mid-attack and more than you need on a quiet day.
A2S query caching
Source engine servers answer A2S queries so they appear in the server browser — and the reply is bigger than the request, which makes it an amplification target. We cache that answer at the edge, so the flood never reaches your server and your listing stays up.
SYN proxy for web traffic
HTTP and HTTPS get a SYN proxy in front: the handshake is completed at the edge and only a real, established connection is passed through. Floods that never finish the handshake never reach your application.
On our own network
Everything above happens in Frankfurt on AS214918, our own autonomous system, on the path your traffic already takes. There is no separate scrubbing detour to add a hop. How the mitigation works in detail.
Game servers
Each of these has a filter that understands the game's own handshake and packet shapes, rather than a generic rate limit that would drop real players along with the attack.
Three strictness levels plus a connection challenge, for servers that get hit during events.
Hosting for thisCovers both halves of Bedrock's newer transport — the signaling channel and the WebRTC media path.
Hosting for thisSource 2 A2S filtering, including a strict mode for servers under sustained query floods.
Hosting for thisIts own CS:GO profile alongside the generic Source engine filter.
GoldSrc answers A2S queries like Source does, so it is covered by the A2S query filter alongside the generic UDP profile.
Hosting for thisThe shared filter behind TF2, Garry's Mod, L4D2, Insurgency and every other Source title, with A2S query caching so the server browser never becomes the attack surface.
Light, strict and ultra-strict tiers, a connection challenge, and a separate profile for the voice channel.
Hosting for thisShares the Cfx.re transport with FiveM, so the same filtering applies.
Hosting for thisThe SA-MP protocol filter, which open.mp servers use too.
Hosting for thisFiltered through the RakNet profile, which parses the protocol rather than guessing at it.
Hosting for thisA dedicated ASA profile, separate from the older Evolved one.
Hosting for thisA UE5 transport filter, which covers newer titles built on the engine.
Voice servers
Voice is usually the first thing to break under an attack, because it is latency-sensitive and runs on its own ports.
A dedicated TeamSpeak protocol filter on the voice port.
A separate filter for the query and file-transfer ports, with a strict mode.
Filtered on the UDP application profile, for Minecraft proximity voice.
Hosting for thisWeb & applications
Web traffic gets a different treatment: a SYN proxy in front of the connection, and a browser challenge for floods that look like real requests.
Stateful filtering with an optional SYN proxy that completes the handshake before anything reaches your server.
A TLS-aware filter with a strict mode.
The FiveM and RedM admin panel gets its own filter and an access challenge.
Hosting for thisA dedicated FTP profile.
A DNS protocol filter — DNS is both a target and a favourite amplification source.
An NTP filter, for the other classic amplification vector.
Remote access & VPN
The ways you reach the box are worth protecting too — losing SSH during an attack is how a small incident becomes a long one.
A dedicated SSH filter.
Separate TCP and UDP profiles for RDP.
A WireGuard protocol filter — the same one behind our Anti-DDoS VPN.
Standard and strict profiles, including one for configurations without tls-crypt.
Anything else
A protocol with no dedicated profile still gets filtered — it falls back to the generic ones rather than being passed through.
Stateful TCP filtering for anything without its own profile.
Generic UDP filtering for anything without its own profile.
About the filtering
My game is not on the list. Am I unprotected?
No. Anything without its own profile falls back to the generic stateful TCP or UDP filter, so it is still filtered — just with rules that are not tuned to that specific protocol. If you are running something popular that deserves its own profile, tell us and we will look at adding one.
What does a "protocol-aware" filter actually do differently?
A generic filter can only count packets, so under attack it has to guess, and it drops real players along with the flood. A protocol-aware filter parses the traffic: it knows what a real Minecraft handshake or an A2S query looks like, so it can throw away what is malformed or forged and keep what is genuine.
What is XDP and why does it matter here?
XDP (eXpress Data Path) runs the filtering in the network driver, before the packet reaches the normal kernel networking stack. That is the cheapest possible point to drop traffic, which is what makes line-rate filtering possible without adding meaningful latency for real players.
Does filtering add ping?
Not in a way players notice. Filtering happens at the edge in Frankfurt on the path your traffic already takes, and dropping a packet in XDP costs a fraction of what it costs once the kernel has processed it.
Why do some games have several strictness levels?
Because the right trade-off changes with the attack. A light profile is friendlier to unusual but legitimate clients; a strict or challenge profile asks more of every connection, which is what you want mid-attack and more than you need on a quiet Tuesday.
What is A2S query caching?
Source engine servers answer A2S queries to appear in the server browser, and that reply is larger than the request — which makes it an amplification target. Caching the answer at the edge means the flood never reaches your server and your listing stays up.
Is this included or an add-on?
Included. Anti-DDoS filtering comes with the game servers, web hosting, VDS and dedicated servers at no extra cost. Layer 7 filtering and extra IP transit are separate products under Networking.
Can I see the protection working?
Yes — the client area shows your traffic and any mitigation events on your IPs, and live service status is on status.esagames.ro.