DDoS Protection
Filtered in Frankfurt am Main, from Equinix FR7
Layer 3 and 4 scrubbing runs on every protected IP by default. What happens next is yours to tune in the panel.

Two stages. Only clean traffic moves on.
The upstream takes the volume off, our shield checks whatever is left.
Upstream scrubbing
Smartnet Germany GmbH
Layer 3 and 4 scrubbing on a cluster of Intel Xeon and AMD EPYC systems with Mellanox network cards. Three steps run here:
- Pre filter. New TCP clients complete the handshake twice, once with the filters, which then re-forward the session transparently. Spoofed SYN floods die here. UDP for supported games runs through the filters permanently.
- Generic filter. SYN cookies, ACK, spoof and DNS authentication, anomalous TCP flags, SYN-ACK amplification, malicious IP options, packet size validation and per connection traffic control.
- ZAPR. Machine learning picks up novel attack patterns that have no known signature, with TCP progression tracking for abnormal sessions. No configuration, no manual intervention.
Our shield
PacketsDecreaser
What survives the upstream hits our own filters, where everything is tuned per target IP. Three things run here:
- Protocol filters. Game and application filters check that traffic on a port really speaks that protocol, on the documented port ranges. Whatever does not is dropped.
- Your panel rules. Rules per target IP, geoblocking and AS blocking as a blocklist or an allowlist, the IP blacklist and the SYN flood shield. Every change takes effect on the filter node right away.
- Layer 7 validation. For supported games the shield goes past packet level and validates the session itself with active bot checks, so a client has to behave like a real player.
| Attack type | Typical time to mitigate |
|---|---|
| Standard attacks | Up to 5 seconds |
| Large scale attacks | Up to 10 seconds |
| Carpet bombing, subnet level | Typically within 10 seconds |
Larger attacks are often mitigated faster, because the sudden spike makes the anomaly easier to detect. More sophisticated or multi vector attacks can take longer while ZAPR refines its pattern recognition.
DDoS Protection Filters
These go beyond general packet filtering: they verify traffic with a challenge response mechanism, which blocks attack traffic that would look legitimate to a generic filter. Pick a category and a filter to see the protocol, the ports it covers by default and what to watch out for.
FiveM
- Protocol
- TCP / UDP
- Default ports
- 30000 – 32000
Our DDoS filter runs at Layer 4 by default. Layer 7 validation on our Layer 7 cluster is optional on top, available on request.
Every filter above is enabled by default on the listed port range, nothing to configure. Traffic that does not match the expected protocol signature is dropped on those ports.
Your service is not in the list?
Tell us the protocol and the ports and we build a profile for it. That is how most of the profiles above started.
Our filter, your rules
Every protected IP comes with full access to our filter panel: live traffic insights, per-target rules and one click bans.
Live status of every protected target
Allowed vs. blocked packets, current packet rate and bandwidth and where the traffic actually comes from.
- ✓ Packets allowed, blocked and block rate at a glance
- ✓ Live pps and bit/s
- ✓ Packet rate & bandwidth history from live view up to 30 days
- ✓ Top blocked and allowed countries and ASNs
- ✓ Per filter breakdown: Geoblocking, AS-Blocking, blacklist, SYN flood, FiveM & Minecraft filters and more
Click the screenshot to view it in full size.
What the filter does
Geo and AS blocking
Block or allow whole countries and autonomous systems per target IP, as a blocklist or an allowlist. Ban the top talkers with one click.
Packet level filters
Global SYN flood shield, IP fragment handling, protocol validation and a per target IP blacklist.
Game and application filters
Game and application filters check that traffic on their default ports really speaks that protocol. Whatever does not is dropped, and new filters keep coming.
Layer 7 validation
Sometimes Layer 4 is not enough, and a bot that speaks the protocol correctly gets through. For supported games the shield validates the session itself, so a client has to behave like a real player.
Up to 5 seconds
Time to mitigate, depending on the type and the size of the attack. It runs automatically, so there is nothing for you to switch on mid attack.
On by default
Filters are active on every protected IP with no configuration, and rate limits only apply while an attack of that type is actually running.
Four ways to get protected
The filtering described above is the same in all four cases.
On a server you rent from us
Included
Every protected IP sits behind the filters by default. Nothing to order, nothing to configure, no tunnel to build.
Remote, over a tunnel
From €29,95 / month
Keep the host you already have. You get protected IPs from our pool and route them to your server over a GRE or WireGuard tunnel. No BGP, no ASN, no address space of your own.
On your own network, over BGP
From €129 / month
You own an ASN and prefixes and want to keep announcing them yourself. From a 250 Mbit/s commit with up to three protected prefixes, handed over on a dualstack BGP session. Your addresses stay your addresses.
Layer 7 Website Protection
From €24,95 / month In work
HTTP and HTTPS is a different problem and a separate product. You point a CNAME at our Layer 7 cluster and requests escalate through a cookie challenge, a proof of work challenge and a captcha, depending on the request rate.
What our customers say
Our customers are very satisfied with our services. Here are some reviews from our customers.
View more reviews on TrustpilotHighly recommend!
PacketsDecreaser have 10/10 customer service. Very helpful, direct and to the point when helping us setup their GRE tunnel. We were getting smashed by syn floods and massive congestion with a botnet to our game server and they mitigated it like it was another Tuesday afternoon.
Node
Ataraxia.gg
Excellent DDoS Protection and Support
Before switching to Packets Decreaser, my VPS would constantly go offline due to DDoS attacks. Now, thanks to their protection, my VPS stays online even during ongoing attacks. Their support team is fast and helpful I would definitely recommend them.
Shadow
PaperNodes LTD
Great DDoS Protection
Good DDoS protection, uptime was not entirely reliable in the past, but has improved significantly in recent weeks. and good server performance.
Thomas U.
ProPacketHost
Great Performance
One of the best Layer-7 DDoS protection services! Layer-7 DDoS protection from packets-decreaser.net is one of the best and most affordable options to make our website stable and secure for our customers.

Auroa Online
Auroa.online
Under attack right now?
Send us the IP or hostname that is being hit, what runs on it and what you are seeing. That is enough for us to start looking. The same people who configure the filters answer.
Payment Methods
Frequently Asked Questions
Up to 5 seconds, depending on the type and the size of the attack. Standard attacks are gone in the first few seconds, large scale attacks and subnet carpet bombing take up to 5. Detection and filtering run automatically, so there is nothing for you to switch on while an attack is running.
We do not publish a fixed mitigation capacity, because it depends on the attack type and the routing path. Scrubbing happens at our upstream and on our own shield, before traffic is ever handed to you, so an attack does not have to fit through your link.
Game filters for FiveM, Minecraft Java, Minecraft Bedrock, Valve Source Engine, Rust, SCP: Secret Laboratory, Palworld, Factorio and BeamNG.drive MP, plus application filters for WireGuard, OpenVPN, SSH and TeamSpeak 3. All of them are enabled by default on their documented port ranges, and the list keeps growing as we build new ones. If your game is not listed, send us the name, the protocol and the port range and we will assess whether a dedicated filter is feasible.
Rules per target IP, geoblocking and AS blocking as a blocklist or an allowlist, an IP blacklist, the SYN flood shield and the game checks. You also see the traffic history from live view up to 30 days and can ban a country or a whole top list straight out of the graph.
Not outside an attack. TCP and UDP are only rate limited while an attack of that same type is actively running, and ICMP is rate limited or blocked while one is. Two standing exceptions: UDP ports that are not covered by a game or application filter run against a default destination limit, so ask us for a dedicated filter if your UDP service uses a non standard port, and during a DNS attack queries are limited to the common public resolvers, which can break resolution for users on a private resolver.
Filtering works on protocol and behaviour level. The game filters read the handshake and the packet structure of that protocol, because that is what tells a real player apart from a bot. Nothing beyond that is inspected, and payloads are never stored. What the panel keeps is counters and the source country or ASN of the traffic, which is what the statistics are built from.
Not by these filters. Layer 3 and 4 scrubbing protects the network path, but HTTP and HTTPS floods are a separate problem and a separate product. For that you point a CNAME at our Layer 7 cluster, where requests escalate through a cookie challenge, a proof of work challenge and a captcha depending on the request rate.
Only if you want one. On a server rented from us the protection sits on the IP you already got. Remotely you get a protected IP from our pool and reach it over a tunnel, no BGP and no address space of your own. If you do own an ASN and prefixes and want to keep announcing them yourself, that is IP Transit.
For a software GRE or a WireGuard tunnel, yes: the endpoint on our side is an IPv6 address, so your server needs outbound IPv6 connectivity to bring the tunnel up. A hardware GRE tunnel runs over IPv4 instead and only needs outbound IPv4.
On a GRE tunnel, yes. Everyone reaches you on the protected IP and your server answers back through the tunnel, so the address your host gave you never shows up. On a WireGuard tunnel the inbound path is the same, but outbound traffic exits directly from your server, so pick GRE if hiding the origin on outbound connections matters to you.