40Gbps DDoS protection. Included free.
Every server ships with Anycast DDoS protection active from the moment it deploys — no setup, no cost. Facing sophisticated Layer 7 attacks that need more headroom? Upgrade to 12Tbps of protection for $15/mo, anytime.
What is a DDoS attack, and why do game servers get targeted?
A Distributed Denial-of-Service (DDoS) attack floods a server with more traffic than it — or the network in front of it — can handle, with the goal of knocking it offline. Instead of one machine sending traffic, an attacker typically coordinates thousands of devices at once, which is what makes these attacks hard to block with simple filtering: the traffic is coming from everywhere, not one obvious source.
Game servers are targeted more than almost any other type of hosting. A rival clan wants your Rust server down before a raid. A banned player wants revenge on your Minecraft community. A competitor wants your FiveM roleplay city offline during peak hours. These attacks are usually personal, timed, and repeated — not a one-off event you can just wait out.
That's a different threat model than most hosting providers are built for. A lot of general-purpose web hosts treat DDoS protection as an enterprise add-on for e-commerce sites. Game server hosting needs it built in from day one, because the attacks aren't hypothetical — they're a predictable part of running a competitive or public-facing community.
Why this matters for your server specifically
- Downtime costs you playersA server that goes offline during peak hours loses active players to competing communities — often permanently.
- Attacks are often repeatedUnlike a random outage, a targeted attacker will try again — protection needs to be permanent, not reactive.
- Game traffic is a specific targetUDP-heavy game protocols are especially vulnerable to amplification attacks that plain web hosts aren't built to filter.
Always-on protection, not a reactive scramble.
Some hosts only start mitigating an attack after it's already knocked you offline. Ours is active before the first packet of an attack ever arrives.
Anycast network routing
Traffic to your server is distributed across our network at the routing level, so a flood aimed at your IP gets absorbed across capacity — not funneled through a single choke point.
Layer 3 & 4 filtering
Network- and transport-level floods — UDP amplification, SYN floods, ICMP floods — are filtered inline before they ever reach your game process.
Layer 7 filtering
Application-level attacks that mimic real player connection attempts are identified and dropped, without blocking your actual players in the process.
No latency penalty
Because filtering happens inline rather than through an off-path scrubbing detour, legitimate traffic isn't rerouted — your ping doesn't change when protection is doing its job.
Three layers, working together.
Different attacks call for different responses. Rather than one blunt filter for everything, protection is split across purpose-built layers that each handle what they're best at — the first two included free on every server, the third an optional upgrade.
Hardware Mitigation Layer
Dedicated anti-DDoS hardware runs inside each of our data centers, intercepting Layer 4 protocol attacks — TCP SYN floods included — and filtering malicious packets with purpose-built mitigation techniques. Included free, active the moment your server deploys.
Edge Router Filtering
This layer deploys automatically across our edge routers, detecting and filtering attacks at the network perimeter through firewall-level rules. Especially effective against amplification floods like NTP, DNS, and Memcached reflection. Included free, no setup required.
Layer 7 Protection Upgrade $15/mo
Application-layer attacks that mimic real player connections are the hardest to filter without blocking legitimate traffic. This optional upgrade routes your traffic through Cosmic Guard's terabit-scale, engine-aware mitigation network, scaling your Layer 7 filtering capacity up to 12Tbps for servers facing sustained or sophisticated attacks.
The Layer 7 upgrade runs on Cosmic Guard's network.
Rather than build generic Layer 7 filtering from scratch, the 12Tbps upgrade routes through Cosmic Guard, a terabit-scale mitigation network built specifically around how individual game engines actually get attacked — not just generic traffic filtering.
Rust — Wipe-Day Floods
The hours after a wipe are the busiest and loudest. Cosmic Guard fingerprints the Rust query protocol (A2S) and drops spoofed handshakes upstream of your box, keeping the server list queue moving for real players.
FiveM/RedM — Slot-Flood & Endpoint Spam
The txAdmin API is a common target. Per-slot fingerprinting separates real join attempts from scripted slot-holds, and rate-limits the txAdmin surface without touching your server's ACL.
Minecraft — Bot Pings & Legacy Floods
Bedrock's RakNet and Java's MOTD ping are both trivial to spoof. Filters built for both protocols absorb the flood at the edge, so your server's ping list stays clean either way.
ARK, Terraria & Custom UDP
Any public UDP port — ARK's RCON, Terraria's TShock, or a custom game daemon — gets every packet scrubbed against known and adaptive attack signatures, without touching your actual game protocol.
Built to stop more than one kind of attack.
"DDoS protection" covers a wide range of attack types, and hosts that only handle the simple ones leave you exposed to the rest. Ours covers the full spectrum, from raw volumetric floods to attacks that mimic real players.
SYN Floods
Millions of fake connection requests aimed at exhausting your server's connection table.
UDP / DNS / NTP Amplification
Small spoofed requests reflected off third-party servers into a flood many times their original size.
HTTP / Layer 7 Floods
Traffic that mimics real connection attempts, designed to blend in with legitimate players.
ICMP Floods
Oversized or excessive ping traffic aimed at saturating your available bandwidth.
Memcached Amplification
Abused caching servers turned into some of the highest-multiplier reflection attacks that exist.
Slowloris & Connection Exhaustion
Slow, low-bandwidth attacks that hold connections open to quietly starve your server of resources.
11 mitigation locations, worldwide.
Anycast only works as well as the network behind it. Ours filters traffic at 11 locations spread across the globe, so an attack gets absorbed at the point closest to where it originates — not routed all the way back to a single facility in Chicago first.
That same distributed footprint benefits your players, too. Legitimate connections route through the nearest point of presence by default, which means low latency for players worldwide, not just the ones near Chicago.
For high-profile servers, $15/mo is cheap insurance.
The free 40Gbps tier handles the vast majority of attacks game servers actually see. But a large, popular, or previously-targeted community can attract more sophisticated Layer 7 attacks — the kind designed specifically to blend in with real player traffic and exceed standard mitigation capacity.
When that happens, the cost isn't just downtime. It's the players who were online when it happened and don't come back, and the ones who hear about it secondhand and never try you in the first place. For a community you've spent months building, that's a much bigger loss than a $15/mo line item.
$15/mo is a predictable, budgetable cost. An outage isn't — you don't get to choose when it happens or how long it takes to recover the players it costs you.
When the free tier isn't enough
- Large or well-known communitiesBigger, more visible servers are more likely to draw sophisticated, sustained attacks.
- Repeat targetingAn attacker who's targeted you before, or knows your community, often tries again with a bigger attack.
- Your own timeRestarts, support tickets, and player questions during an outage all cost you hours you don't get back.
Upgrade to 12Tbps for $15/mo.
No commitment, no setup wait — your existing 40Gbps stays active free either way.
Common questions about our DDoS protection.
40Gbps of DDoS protection is included free on every server, automatically, with nothing to set up. If you want more headroom, a $15/mo upgrade increases your Layer 7 protection capacity up to 12Tbps — added when you order or anytime after from your control panel.
Every server includes 40Gbps+ of DDoS mitigation capacity free. For sophisticated Layer 7 (application-layer) attacks that need more headroom, the $15/mo upgrade scales your protection up to 12Tbps, backed by our total network capacity across our Chicago infrastructure.
No. Filtering happens inline at the network edge via Anycast routing, not through a reactive scrubbing center that adds a routing detour. Legitimate player traffic isn't rerouted or delayed — only attack traffic gets filtered out.
Layer 3 (network-level floods like UDP and ICMP amplification), Layer 4 (SYN floods and connection exhaustion), and Layer 7 (application-level attacks that mimic real player connections) are all filtered — the combination that matters most for game servers specifically, since game traffic patterns don't look like typical web traffic.
No configuration is required. Protection is active at the network level the moment your server is provisioned, regardless of game, mods, or server settings.
Stop worrying about who's mad at your server.
Every Chicago game server includes 40Gbps of DDoS protection free — upgrade to 12Tbps anytime for $15/mo if you need more.
Deploy Your Server