Skip to content
RyzenHosting

Virtual servers

Attack protection

Standard protection is on from the moment your server is created. Here is what it filters, and what the advanced switches on the Security tab are for.

Last reviewed 2026-10-04

The Attack protection card sits at the top of the Security tab. It is included with every service at no extra cost, and it is on from the moment the server is created.

Filtering happens on the network before traffic reaches your server, so it costs you no processor time.

Standard protection

This is the one that matters, and the one that is doing work on your server right now. Leave it on.

It drops malformed and out of state packets, refuses impossible TCP flag combinations, rate limits connection floods with a large burst allowance, caps how much of the connection table a single address can occupy, drops spoofed and unroutable source addresses, and limits how fast one address can ping you.

The limits are set high enough that a busy website or a full game server never reaches them. There is no downside to this one, which is why it is on by default and why we recommend leaving it alone.

Turning it off

You can switch it off. The panel asks you to confirm, and afterwards a warning stays on the page for as long as it is off.

The only reason to do it is if you are running something unusual that the filtering gets in the way of, and you have confirmed that is what is happening. Everything it filters is already invalid traffic, so switching it off exposes the server for no benefit.

The advanced switches

Below Standard protection is a list of nine more filters, all off by default. Each one trades something away, which is why none of them is on from the start.

Each row has a How it works and settings link that opens two short sections: What it does and When to leave it off. Read both before you switch anything on.

FilterWhat it is for
Handshake validationDefeats spoofed connection floods, the cheapest way to exhaust a server. Needs the list of TCP ports you serve.
Connection rate limitSlows down a single source opening connections faster than a real client would. Default 30 per second with a burst of 60.
Concurrent connection capStops one address holding thousands of connections open. Default 200 per address.
Reflection filterBlocks amplified UDP floods, where someone forges your address to aim a much larger reply at you.
Scan blockingTemporarily shuts out addresses probing your server. Needs the list of TCP ports you serve.
Known attacker blocklistRefuses traffic from networks documented as sources of attacks, and from addresses that cannot legitimately exist.
Country filterLimits who can reach your server by country. Blunt, but effective when your audience is regional.
Strict ICMPRemoves ping and the diagnostic traffic that can be used to probe or flood you.
Outbound abuse guardStops your server being used to attack somebody else if it is ever compromised.

The two that need ports

Handshake validation and Scan blocking need to know which TCP ports you actually serve. When you switch one on, the panel fills the list in from your firewall rules. If no rule allows a TCP port yet, it cannot work it out and asks you to list the ports yourself. Up to 64 ports.

The country filter

Two modes. Block listed refuses the countries you name. Allow only listed refuses everything except the countries you name.

Allow mode is the dangerous one. Put your own country in the list before you save, or you will not reach the server yourself. Up to 60 two letter country codes, comma separated, such as HU, DE, AT.

With no countries chosen the filter does nothing at all.