Protection you can verify.
Every location lists exactly which layers are filtered. No vague badges, no "enterprise-grade" without a definition.
Floods of packets aimed at your server's IP: UDP floods, SYN floods, amplification. Absorbed at the network edge before they reach the node.
Traffic that looks like real players but is not: fake join spam, query floods, protocol abuse. Filtered per game protocol where L7 is listed.
What each location filters
| Location | Network edge (L3/L4) | Application (L7) | Hardware | Availability |
|---|---|---|---|---|
| via Cloudflare Magic Transit | Per protocolvia XDP | Ryzen 9 9950X or equivalent · DDR5 · NVMe | Available | |
| Basic | Ryzen 9 9950X or equivalent · DDR5 · NVMe | Sold out | ||
| via CosmicGuard | Per protocolvia CosmicGuard | Ryzen 9 9950X or equivalent · DDR5 · NVMe | Low stock |
L7 rules are written per protocol. Where a location publishes its list, every protocol on it is named below. If the game you run is not there, ask before you buy and we will confirm in writing rather than guess.
Named, not implied.
Application-layer filtering only works when a rule understands the protocol it is reading. That means there is a list, and a list can be published. Here is ours, per location.
- Arma Reforger
- Counter-Strike / Source (v1)
- DDNet
- FiveM / RedM
- Hytale
- Minecraft Java
- Minecraft Bedrock/PE
- Minecraft PlasmoVoice
- Minecraft SimpleVoiceChat
- MTA:SA
- Realitymod BF2
- Rust
- SA-MP
- SCP:SL
- SCUM
- UT99
- Amplification (NTP/DNS/etc)
- OpenVPN
- RDP
- SIP
- SSH
- TeamSpeak 3
- WireGuard
- Arma Reforger
- Counter-Strike / Source (v1)
- DDNet
- FiveM / RedM
- Hytale
- Minecraft Java
- Minecraft Bedrock/PE
- Minecraft PlasmoVoice
- Minecraft SimpleVoiceChat
- MTA:SA
- Realitymod BF2
- Rust
- SA-MP
- SCP:SL
- SCUM
- UT99
- Amplification (NTP/DNS/etc)
- OpenVPN
- RDP
- SIP
- SSH
- TeamSpeak 3
- WireGuard
Three things people mean when they say "DDoS"
Bandwidth floods
Hundreds of megabits to several gigabits of junk aimed at one IP, trying to saturate the link. Only a network with spare capacity can absorb it.
Filtered at the edge · every locationSYN and state attacks
Half-open connections and malformed packets that exhaust connection tables instead of bandwidth. Smaller in size, just as effective without filtering.
Filtered at the edge · every locationFake-player floods
Bots that speak the game's protocol: join spam, query floods, abusive handshakes. They look legitimate at the network layer and need per-protocol rules.
Filtered at L7 · Virginia, Miami, DallasWhat we do when an attack hits
- 1
Detect at the edge
Traffic anomalies on the node's IP are flagged within seconds at the network edge, before the node feels them.
- 2
Filter per IP
Only the targeted IP is scrubbed or null-routed. Every other customer on the node keeps playing.
- 3
Isolate the targeted server
If a flood saturates the link, the affected server is moved behind a proxy or to another IP, never at the expense of its neighbors.
- 4
Report on the status page
Incidents appear on status.tridentsky.net with a timeline and resolution. You are never left guessing.