DDoS Protection

Filtered in Frankfurt am Main, from Equinix FR7

Layer 3 and 4 scrubbing runs on every protected IP by default. What happens next is yours to tune in the panel.

How mitigation works

Two stages. Only clean traffic moves on.

The upstream takes the volume off, our shield checks whatever is left.

1

Upstream scrubbing

Smartnet Germany GmbH

Layer 3 and 4 scrubbing on a cluster of Intel Xeon and AMD EPYC systems with Mellanox network cards. Three steps run here:

  • Pre filter. New TCP clients complete the handshake twice, once with the filters, which then re-forward the session transparently. Spoofed SYN floods die here. UDP for supported games runs through the filters permanently.
  • Generic filter. SYN cookies, ACK, spoof and DNS authentication, anomalous TCP flags, SYN-ACK amplification, malicious IP options, packet size validation and per connection traffic control.
  • ZAPR. Machine learning picks up novel attack patterns that have no known signature, with TCP progression tracking for abnormal sessions. No configuration, no manual intervention.
2

Our shield

PacketsDecreaser

What survives the upstream hits our own filters, where everything is tuned per target IP. Three things run here:

  • Protocol filters. Game and application filters check that traffic on a port really speaks that protocol, on the documented port ranges. Whatever does not is dropped.
  • Your panel rules. Rules per target IP, geoblocking and AS blocking as a blocklist or an allowlist, the IP blacklist and the SYN flood shield. Every change takes effect on the filter node right away.
  • Layer 7 validation. For supported games the shield goes past packet level and validates the session itself with active bot checks, so a client has to behave like a real player.
Mitigation takes Up to 5 seconds, depending on the type and the size of the attack.
Attack typeTypical time to mitigate
Standard attacksUp to 5 seconds
Large scale attacksUp to 10 seconds
Carpet bombing, subnet levelTypically within 10 seconds

Larger attacks are often mitigated faster, because the sudden spike makes the anomaly easier to detect. More sophisticated or multi vector attacks can take longer while ZAPR refines its pattern recognition.

DDoS Protection Filters

These go beyond general packet filtering: they verify traffic with a challenge response mechanism, which blocks attack traffic that would look legitimate to a generic filter. Pick a category and a filter to see the protocol, the ports it covers by default and what to watch out for.

FiveM

Protocol
TCP / UDP
Default ports
30000 – 32000

Our DDoS filter runs at Layer 4 by default. Layer 7 validation on our Layer 7 cluster is optional on top, available on request.

Every filter above is enabled by default on the listed port range, nothing to configure. Traffic that does not match the expected protocol signature is dropped on those ports.

Your service is not in the list?

Tell us the protocol and the ports and we build a profile for it. That is how most of the profiles above started.

Request a filter

Our filter, your rules

Every protected IP comes with full access to our filter panel: live traffic insights, per-target rules and one click bans.

Live status of every protected target

Allowed vs. blocked packets, current packet rate and bandwidth and where the traffic actually comes from.

  • Packets allowed, blocked and block rate at a glance
  • Live pps and bit/s
  • Packet rate & bandwidth history from live view up to 30 days
  • Top blocked and allowed countries and ASNs
  • Per filter breakdown: Geoblocking, AS-Blocking, blacklist, SYN flood, FiveM & Minecraft filters and more

Click the screenshot to view it in full size.

What the filter does

Geo and AS blocking

Block or allow whole countries and autonomous systems per target IP, as a blocklist or an allowlist. Ban the top talkers with one click.

Packet level filters

Global SYN flood shield, IP fragment handling, protocol validation and a per target IP blacklist.

Game and application filters

Game and application filters check that traffic on their default ports really speaks that protocol. Whatever does not is dropped, and new filters keep coming.

Layer 7 validation

Sometimes Layer 4 is not enough, and a bot that speaks the protocol correctly gets through. For supported games the shield validates the session itself, so a client has to behave like a real player.

Up to 5 seconds

Time to mitigate, depending on the type and the size of the attack. It runs automatically, so there is nothing for you to switch on mid attack.

On by default

Filters are active on every protected IP with no configuration, and rate limits only apply while an attack of that type is actually running.

Where it applies

Four ways to get protected

The filtering described above is the same in all four cases.

On a server you rent from us

Included

Every protected IP sits behind the filters by default. Nothing to order, nothing to configure, no tunnel to build.

Remote, over a tunnel

From €29,95 / month

Keep the host you already have. You get protected IPs from our pool and route them to your server over a GRE or WireGuard tunnel. No BGP, no ASN, no address space of your own.

On your own network, over BGP

From €129 / month

You own an ASN and prefixes and want to keep announcing them yourself. From a 250 Mbit/s commit with up to three protected prefixes, handed over on a dualstack BGP session. Your addresses stay your addresses.

Layer 7 Website Protection

From €24,95 / month In work

HTTP and HTTPS is a different problem and a separate product. You point a CNAME at our Layer 7 cluster and requests escalate through a cookie challenge, a proof of work challenge and a captcha, depending on the request rate.

What our customers say

Our customers are very satisfied with our services. Here are some reviews from our customers.

View more reviews on Trustpilot

Highly recommend!

PacketsDecreaser have 10/10 customer service. Very helpful, direct and to the point when helping us setup their GRE tunnel. We were getting smashed by syn floods and massive congestion with a botnet to our game server and they mitigated it like it was another Tuesday afternoon.

Node

Ataraxia.gg

Excellent DDoS Protection and Support

Before switching to Packets Decreaser, my VPS would constantly go offline due to DDoS attacks. Now, thanks to their protection, my VPS stays online even during ongoing attacks. Their support team is fast and helpful I would definitely recommend them.

Shadow

PaperNodes LTD

Great DDoS Protection

Good DDoS protection, uptime was not entirely reliable in the past, but has improved significantly in recent weeks. and good server performance.

Thomas U.

ProPacketHost

Great Performance

One of the best Layer-7 DDoS protection services! Layer-7 DDoS protection from packets-decreaser.net is one of the best and most affordable options to make our website stable and secure for our customers.

Auroa Online

Auroa Online

Auroa.online

Emergency help

Under attack right now?

Send us the IP or hostname that is being hit, what runs on it and what you are seeing. That is enough for us to start looking. The same people who configure the filters answer.

Payment Methods

Visa
Mastercard
Paypal
SEPA
Klarna Sofort
Apple Pay

Frequently Asked Questions