DDoS protection

Protection you can verify.

Every location lists exactly which layers are filtered. No vague badges, no "enterprise-grade" without a definition.

AshburnL3/4L7MiamiL3/4L7·BasicDallasL3/4L7
L3 / L4 · Network layer

Floods of packets aimed at your server's IP: UDP floods, SYN floods, amplification. Absorbed at the network edge before they reach the node.

L7 · Application layerPer protocol

Traffic that looks like real players but is not: fake join spam, query floods, protocol abuse. Filtered per game protocol where L7 is listed.

By location

What each location filters

LocationNetwork edge (L3/L4)Application (L7)HardwareAvailability
Ashburn, VAMeasuring…via Cloudflare Magic TransitPer protocolvia XDPRyzen 9 9950X or equivalent · DDR5 · NVMeAvailable
Miami, FLMeasuring…BasicRyzen 9 9950X or equivalent · DDR5 · NVMeSold out
Dallas, TXMeasuring…via CosmicGuardPer protocolvia CosmicGuardRyzen 9 9950X or equivalent · DDR5 · NVMeLow stock

L7 rules are written per protocol. Where a location publishes its list, every protocol on it is named below. If the game you run is not there, ask before you buy and we will confirm in writing rather than guess.

Filtered protocols

Named, not implied.

Application-layer filtering only works when a rule understands the protocol it is reading. That means there is a list, and a list can be published. Here is ours, per location.

Ashburn, VAXDP23 protocols
Games
  • Arma Reforger
  • Counter-Strike / Source (v1)
  • DDNet
  • FiveM / RedM
  • Hytale
  • Minecraft Java
  • Minecraft Bedrock/PE
  • Minecraft PlasmoVoice
  • Minecraft SimpleVoiceChat
  • MTA:SA
  • Realitymod BF2
  • Rust
  • SA-MP
  • SCP:SL
  • SCUM
  • UT99
Other services
  • Amplification (NTP/DNS/etc)
  • OpenVPN
  • RDP
  • SIP
  • SSH
  • TeamSpeak 3
  • WireGuard
Dallas, TXCosmicGuard23 protocols
Games
  • Arma Reforger
  • Counter-Strike / Source (v1)
  • DDNet
  • FiveM / RedM
  • Hytale
  • Minecraft Java
  • Minecraft Bedrock/PE
  • Minecraft PlasmoVoice
  • Minecraft SimpleVoiceChat
  • MTA:SA
  • Realitymod BF2
  • Rust
  • SA-MP
  • SCP:SL
  • SCUM
  • UT99
Other services
  • Amplification (NTP/DNS/etc)
  • OpenVPN
  • RDP
  • SIP
  • SSH
  • TeamSpeak 3
  • WireGuard
Attack types

Three things people mean when they say "DDoS"

Volumetric

Bandwidth floods

Hundreds of megabits to several gigabits of junk aimed at one IP, trying to saturate the link. Only a network with spare capacity can absorb it.

Filtered at the edge · every location
Protocol

SYN and state attacks

Half-open connections and malformed packets that exhaust connection tables instead of bandwidth. Smaller in size, just as effective without filtering.

Filtered at the edge · every location
Application

Fake-player floods

Bots that speak the game's protocol: join spam, query floods, abusive handshakes. They look legitimate at the network layer and need per-protocol rules.

Filtered at L7 · Virginia, Miami, Dallas
During an attack

What we do when an attack hits

  1. 1

    Detect at the edge

    Traffic anomalies on the node's IP are flagged within seconds at the network edge, before the node feels them.

  2. 2

    Filter per IP

    Only the targeted IP is scrubbed or null-routed. Every other customer on the node keeps playing.

  3. 3

    Isolate the targeted server

    If a flood saturates the link, the affected server is moved behind a proxy or to another IP, never at the expense of its neighbors.

  4. 4

    Report on the status page

    Incidents appear on status.tridentsky.net with a timeline and resolution. You are never left guessing.

Protected with

Hardware and networks we build on

Node CPUs
DNS and edge
CosmicGuardDDoS mitigation

Pick the location that matches your risk.

Every location shows its layers before you pay.
Build your server