Bring your server over

Migrate your existing server to InstantNode in minutes.

Try the Server Importer
Log in Create server
DDoS Protection · always on

Attacks stop at the edge.
Your server keeps running.

Every IP in our network sits behind always-on Pletx filtering. Floods are dropped in the network before they reach your server, on every product, at no extra cost and with nothing to configure.

Included on every service L3, L4 and L7 No activation delay
111 Gbit/sLargest attack filtered on our network
1,300+Attacks filtered so far
13Attack types seen and dropped
0 sActivation time, the filter never switches off
How it works

Every packet passes
the filter first.

Traffic to our network runs inline through the filter, in both directions. Attack traffic is dropped there, real players and visitors get through, and your server only sees what it should.

#Attack traffic +Real players and visitors :Dropped in the network
  1. Everything goes through the filter

    All traffic to our IP range runs inline through Pletx, incoming and outgoing. There is no switch-over and no rerouting when an attack starts.

  2. Attacks are dropped at the edge

    The filter follows every connection from its first packet. Floods, spoofed packets and fake handshakes are dropped in the network, long before they reach a server.

  3. Your traffic arrives

    Real players and visitors get through without noticeable delay, and your server only has to deal with clean traffic.

From our network

Real attacks,
real numbers.

The five largest attacks on our network since February 2026, all of them filtered in the network. For scale: the biggest one was more than a hundred times what a 1 Gbit/s server port can take.

  1. 21.08.2026111 Gbit/s8 vectors · 13 min
  2. 03.09.2026110 Gbit/s8 vectors · 5 min
  3. 20.02.2026105 Gbit/s6 vectors · 4 min
  4. 16.07.202699 Gbit/s7 vectors · 1 min
  5. 23.08.202698 Gbit/s9 vectors · 7 min
  6. For scale1 Gbit/sa typical server port
What gets filtered

Every common attack,
handled for you.

These are the attack types we have seen against our own network since February 2026. Most attacks combine several of them at once.

SYN, ACK and RST floods

Masses of fake TCP packets, including FIN, PSH and SYN-ACK floods. The filter knows which connections really exist and drops the rest.

UDP floods

Raw volume against game and voice ports. Dropped in the network, so the uplink of your server stays free for your players.

Amplification

DNS, NTP and other reflection attacks that multiply traffic through open servers on the internet.

Handshake attacks

Connections that are opened and never used, built to tie up the resources of your server.

ICMP floods

Ping floods and other ICMP noise, dropped long before they reach your server.

Application layer (L7)

Floods that imitate real requests are filtered too. For websites under heavy, targeted attacks we recommend Cloudflare in front, it works with every product.

Protocol filters

Filters that know
your game.

For common games and services there are filter profiles that understand what normal traffic looks like, so real players keep getting through even while a flood is running.

Your server gets hit on the same port again and again? Open a ticket and we set the matching profile for your IP and port.

  • Minecraft25565/tcp
  • FiveM30120/tcp+udp
  • Source engine games27015/udp
  • TeamSpeak9987/udp
  • SSH22/tcp
  • RDP3389/tcp
  • WireGuard51820/udp
  • OpenVPN1194/udp

Included on every product, from the smallest game server to a dedicated VDS, from the first minute.

Your server is somewhere else?

With IP forwarding you get a protected IPv4 from our network and forward it over WireGuard to your machine, at home or at another host. Attacks end with us, your real address stays hidden.

IP forwarding, €3.99/month
FAQ

Questions,
answered.

Does DDoS protection cost extra?
No. It is included on every service, from the smallest game server to a VDS, and there is nothing to book or switch on.
Do I have to configure anything?
No. Filtering is always on for every IP in our network. If your server keeps getting hit on one port, open a ticket and we add a filter profile for its protocol.
What happens to my server during an attack?
The attack is dropped in the network and your players and visitors keep getting through. Very small floods can stay below the detection thresholds and reach your server, where the normal limits of your software deal with them.
Are websites protected?
Yes, against volumetric and application-layer floods. HTTPS requests that look exactly like real visitors can only be told apart by your web server or by a proxy that holds your certificate, so for sites under heavy, targeted attacks we recommend Cloudflare in front.
Can I protect a server that is not hosted with you?
Yes, with IP forwarding: a protected IPv4 from our network, forwarded over WireGuard to your server wherever it runs. €3.99 a month.
Can I test the protection with my own attack?
Please open a ticket first and tell us when and what you want to test, so we can watch it with you. Unannounced attacks against our network are handled like real ones, and our Fair Use Policy applies.
Where does the filtering happen?
Inline, in the network our servers in Eygelshoven (NL) are connected to. Traffic is not sent on a detour to a distant scrubbing center when an attack starts.

Attacks are our problem.
Not yours.

DDoS protection on every server, included from the first minute.

Get started

Game servers, VPS, web hosting and more, all in our network in the Netherlands.