Sari la conținutul principal
DDoS protection

Under attack? Mitigation is already on.

Every EUGameHost service sits behind always-on filtering. There is no activation step, no ticket to raise and no window in which attack traffic reaches your server.

Filtering capacity
30Tbps
Mitigation mode
Always on
Attack layers covered
L3, L4, L7
UK support
24/7
30TbpsEdgeProt anycast backbone
Up to 6TbpsCosmic Guard, game platform
L3, L4, L7Every layer inspected
Always onNo activation step
A2S cachingQueries answered at the edge
No add-onIncluded with every service
How it works

Absorb, filter, deliver

Traffic for your service reaches an edge location before it reaches your server. Attack traffic is dropped there. Clean traffic carries on to you, at the same rate it always did.

Volumetric attack, mitigated Inbound at the edge Delivered to your server Always on
3.5 Tbps 3 Tbps 2 Tbps 1 Tbps 0 0s 25s 60s 95s 120s Peak 3.1 Tbps

Scroll the chart sideways to see the full two minutes

Absorbed at the edge 3.1 Tbps Passed to your server 0 Tbps Time to mitigate None, always on Network capacity 30 Tbps

Illustration of how a volumetric attack is handled, drawn to scale against our 30 Tbps capacity. It is not a live traffic feed. For real figures from our network use the Looking Glass and SmokePing.
  1. 01

    Absorbed at the edge

    Our anycast network announces your address from multiple edge locations, so a flood is spread across the network and soaked up close to its source instead of arriving at one machine in one rack.

  2. 02

    Filtered by protocol

    Every packet is inspected against Layer 3, Layer 4 and Layer 7 rules, plus the game-specific filters below. Malformed, spoofed and flood traffic is dropped; genuine player traffic is not.

  3. 03

    Delivered clean

    What is left is forwarded to your server. Because the filtering runs constantly rather than switching on when an alarm fires, your players stay connected through the attack instead of reconnecting after it.

We do not null-route customers under attack. Null-routing takes your service offline to protect the network, which is exactly the outcome the attacker wanted. Our approach is to keep filtering and keep you online.

The network

Filtering happens where the attack lands

EdgeProt announces your address from every location on this map. An attack is split across the whole footprint and dropped at the nearest edge rather than being dragged across the world to your rack.

  • Core scrubbing site
  • Edge location
  • Fibre run
Protocol coverage

Game-specific DDoS filters

Generic scrubbing does not understand a game protocol, so it either lets crafted packets through or drops real players. These filters are written per protocol and are constantly updated to match new exploits and evolving attacks.

  • Minecraft Bedrock

    Specialised protection for Minecraft Bedrock Edition servers.

    Protects: Minecraft Bedrock
  • CSGO filter

    Tailored to prevent known CSGO-specific exploits and flooding.

    Protects: CSGO, CS 1.6, CS: Source
  • RakNet V2

    Mitigation for attacks targeting the RakNet V2 protocol.

    Protects: Rust, Unturned, Hurtworld, SCP:SL, Scum
  • OpenVPN and WireGuard

    Keeps tunnels stable under load or attack.

    Protects: VPN hosting, proxy servers, private cloud access
  • Steam Query

    Protects A2S query traffic from floods and spoofing.

    Protects: Rust, Ark SA, Ark SE, DayZ, Squad, 7 Days to Die, Scum
  • Garry's Mod

    Stops Lua exploit floods and other custom protocol attacks.

    Protects: Garry's Mod
  • SCP: Secret Laboratory

    Targeted protection for SCP:SL traffic and RakNet abuse.

    Protects: SCP: Secret Laboratory
  • Hurtworld

    Advanced filtering for Hurtworld's protocol layer.

    Protects: Hurtworld
  • SteamNet

    Filters attacks on Steam networking sockets.

    Protects: Rust, Palworld, Squad
  • San Andreas

    Protocol inspection for SA-MP flooding and exploits.

    Protects: GTA SA, SA-MP
  • DDNet

    Custom protections for the DDRace mod networking stack.

    Protects: DDNet
  • SYN cookies

    Generic TCP SYN flood protection across every title.

    Protects: All listed titles and more
A2S caching

Query protection that also grows your server

Server browsers hammer your A2S query port, and attackers know it. Our A2S caching answers those queries from the edge, which blocks query-based attacks and improves how your server looks in Steam and other listings at the same time.

Query sources Steam browser Server listings Monitoring bots Player clients A2S query flood Edge cache Answered at the edge dropped 1 refresh Your game server Query port stays quiet

Scroll the diagram sideways to follow the whole path

Illustration of the query path. Browsers, listing services and monitoring bots are answered from the edge cache. Your server sees one refresh instead of thousands of lookups, and a query flood is discarded before it gets near the origin.
  • Lower query latency

    Global caching reduces query response times, improving server browser performance worldwide.

  • Blocks A2S-based DDoS

    Prevents A2S query floods that crash or lag servers, maintaining stability.

  • Better player acquisition

    Faster server listing responses increase visibility and attract more players.

  • Higher player averages

    Improved query performance feeds through to higher 24h player averages and total counts.

  • Transparent fallback

    An automatic fallback handles A2S anomalies without interrupting the service.

Communities switching to our A2S caching see up to 50% more players on average, from a mix of lower global query latency and better discoverability in server listings.

Your controls

You get the firewall, not just the promise

The platform filters everything by default. On top of that you get the EdgeProt rule editor, so you can whitelist, blacklist and shape traffic on your own addresses.

The EdgeProt firewall rules screen, adding a TCP rule with a source IP, destination port and filter profile.
  • Rules per protocol and port

    Add TCP or UDP rules against a source address and destination port, with the filter profile that matches the service behind it.

  • Cachers and filters

    Turn A2S caching and the protocol filters on per address, so a query cache sits in front of the port that needs it.

  • Whitelists and blacklists

    Pin known-good sources through and shut out anything you never want to hear from again, without raising a ticket.

  • IP selector and API keys

    Switch between the addresses on your account, and drive the same rules from your own tooling with an API key.

Capacity

Built for the size of attacks game servers actually get

The filtering backbone is shared across every EUGameHost service, so a small community server sits behind the same capacity as the largest network we host.

Anycast backbone
30Tbps

EdgeProt

Filtering capacity across the whole footprint

Game platform
6Tbps

Cosmic Guard

Up to, per protected service

L7 L4 L3
Inspection
L3, L4, L7

Every layer

Volumetric, transport and application

The numbers, written down

Filtering capacity
30Tbps
Attack layers covered
Layer 3, Layer 4 and Layer 7
Mitigation mode
Always on, no activation step
Game server platform
Cosmic Guard, up to 6Tbps per service
Anycast filtering backbone
EdgeProt
A2S query caching
Included
Cost
Included, no add-on

We mitigate attacks up to 2Tbps daily. Figures above are platform capacity, not a per-customer allowance.

If you are under attack right now

Do not panic. Mitigation is already in place.

There is nothing you need to enable. These are the only steps worth taking while an attack is in progress.

  1. Step 1

    Leave the service running

    Filtering is already applied to your address. Rebooting or moving the service does not help and costs you players.

  2. Step 2

    Check your panel

    Your panel shows the active mitigation notice and the attack detail, so you can see what is being filtered.

  3. Step 3

    Contact us if it still hurts

    If gameplay is still affected, open a ticket or ping us on Discord. We analyse the pattern and apply a custom filter.

  4. Step 4

    Keep gaming

    The mitigation keeps your players online, which is the whole point. You should not have to manage it.

Ask us after onboarding and we will carry out a free DDoS vulnerability audit, so your services run with the best application-specific filters for what you actually host.

Racked servers in the UK data centre that hosts the protected Ark clusters. 8 Ark clusters, still online
Case study

A 700 player Ark network that stopped collapsing

"My Ark cluster was facing devastating DDoS attacks that brought down our entire 700 player network during peak hours. Traditional protection services either caused too much latency or let attacks through.

EUGameHost changed that. The moment we switched, attacks stopped reaching our servers. The A2S caching actually improved our server browser performance, and we saw a 15% increase in player retention.

What impressed us most was the custom filter they deployed for our specific Ark protocol vulnerabilities within 20 minutes of reporting an issue. Now we host 8 Ark clusters with zero downtime."

Ark server network administrator

We also host large Ark clusters including Mesa and INX, alongside major Rust servers and FiveM communities such as Hive and BESTRUST.

Beyond game servers

Websites, APIs, VPNs and everything else you run

The gaming filters are the specialist part. The rest of the platform protects any internet-facing service you host with us.

Websites and APIs

Layer 7 filtering for HTTP floods and application-layer abuse, on top of the volumetric filtering.

VPN and proxy

OpenVPN and WireGuard filters keep tunnels stable when the tunnel endpoint is the target.

Hosting infrastructure

Protection covers whole ranges, so resellers and hosts can put their own customers behind it.

DDoS protection

DDoS protection questions

Our filtering covers all Layer 3/4 and Layer 7 DDoS attacks including SYN floods, UDP floods, HTTP floods, and game-specific attacks targeting protocols like Minecraft, CSGO, and other gaming services.

No, our global anycast network actually reduces latency by routing traffic through the nearest edge location. Most users experience improved or unchanged ping times.

No. Filtering is always on, so there is no activation step, no ticket to raise and no window in which attack traffic reaches your server. Custom filters for a specific attack pattern can be deployed within 30 minutes.

Yes, we protect websites, APIs, VPNs, and any internet-facing service. We offer specialised filters for gaming but provide comprehensive protection for all applications.

A2S caching stores and serves game server queries from edge locations, reducing query latency globally and blocking A2S-based DDoS attacks that target server browsers and listing services.

Legitimate traffic passes through unimpeded while an attack is being filtered, so your players are not dropped, challenged or queued because someone else is attacking you.

Our global anycast network has 30Tbps of filtering capacity with multiple edge locations worldwide. We successfully mitigate attacks up to 2Tbps daily with 99.997% uptime SLA.

Yes, we can deploy custom filters for niche games or specific attack patterns within 30 minutes. Our team specialises in reverse-engineering new attack vectors and creating targeted defences.

Stop losing players. Get protected.

Talk to our team about what you host and we will tell you exactly which filters apply, what the audit covers, and what it costs.

  • Included on every service
  • Always-on filtering
  • Free vulnerability audit
  • 24/7 UK support