Attacks stop at the edge.
Your server keeps running.
Every IP in our network sits behind always-on Pletx filtering. Floods are dropped in the network before they reach your server, on every product, at no extra cost and with nothing to configure.
Every packet passes
the filter first.
Traffic to our network runs inline through the filter, in both directions. Attack traffic is dropped there, real players and visitors get through, and your server only sees what it should.
Everything goes through the filter
All traffic to our IP range runs inline through Pletx, incoming and outgoing. There is no switch-over and no rerouting when an attack starts.
Attacks are dropped at the edge
The filter follows every connection from its first packet. Floods, spoofed packets and fake handshakes are dropped in the network, long before they reach a server.
Your traffic arrives
Real players and visitors get through without noticeable delay, and your server only has to deal with clean traffic.
Real attacks,
real numbers.
The five largest attacks on our network since February 2026, all of them filtered in the network. For scale: the biggest one was more than a hundred times what a 1 Gbit/s server port can take.
Every common attack,
handled for you.
These are the attack types we have seen against our own network since February 2026. Most attacks combine several of them at once.
SYN, ACK and RST floods
Masses of fake TCP packets, including FIN, PSH and SYN-ACK floods. The filter knows which connections really exist and drops the rest.
UDP floods
Raw volume against game and voice ports. Dropped in the network, so the uplink of your server stays free for your players.
Amplification
DNS, NTP and other reflection attacks that multiply traffic through open servers on the internet.
Handshake attacks
Connections that are opened and never used, built to tie up the resources of your server.
ICMP floods
Ping floods and other ICMP noise, dropped long before they reach your server.
Application layer (L7)
Floods that imitate real requests are filtered too. For websites under heavy, targeted attacks we recommend Cloudflare in front, it works with every product.
Filters that know
your game.
For common games and services there are filter profiles that understand what normal traffic looks like, so real players keep getting through even while a flood is running.
Your server gets hit on the same port again and again? Open a ticket and we set the matching profile for your IP and port.
- Minecraft
25565/tcp - FiveM
30120/tcp+udp - Source engine games
27015/udp - TeamSpeak
9987/udp - SSH
22/tcp - RDP
3389/tcp - WireGuard
51820/udp - OpenVPN
1194/udp
Included on every product, from the smallest game server to a dedicated VDS, from the first minute.
Your server is somewhere else?
With IP forwarding you get a protected IPv4 from our network and forward it over WireGuard to your machine, at home or at another host. Attacks end with us, your real address stays hidden.
Questions,
answered.
Does DDoS protection cost extra?
Do I have to configure anything?
What happens to my server during an attack?
Are websites protected?
Can I protect a server that is not hosted with you?
Can I test the protection with my own attack?
Where does the filtering happen?
Attacks are our problem.
Not yours.
DDoS protection on every server, included from the first minute.
Get startedGame servers, VPS, web hosting and more, all in our network in the Netherlands.