Virtual servers
Attack protection
Standard protection is on from the moment your server is created. Here is what it filters, and what the advanced switches on the Security tab are for.
Last reviewed 2026-10-04
The Attack protection card sits at the top of the Security tab. It is included with every service at no extra cost, and it is on from the moment the server is created.
Filtering happens on the network before traffic reaches your server, so it costs you no processor time.
Standard protection
This is the one that matters, and the one that is doing work on your server right now. Leave it on.
It drops malformed and out of state packets, refuses impossible TCP flag combinations, rate limits connection floods with a large burst allowance, caps how much of the connection table a single address can occupy, drops spoofed and unroutable source addresses, and limits how fast one address can ping you.
The limits are set high enough that a busy website or a full game server never reaches them. There is no downside to this one, which is why it is on by default and why we recommend leaving it alone.
Turning it off
You can switch it off. The panel asks you to confirm, and afterwards a warning stays on the page for as long as it is off.
The only reason to do it is if you are running something unusual that the filtering gets in the way of, and you have confirmed that is what is happening. Everything it filters is already invalid traffic, so switching it off exposes the server for no benefit.
The advanced switches
Below Standard protection is a list of nine more filters, all off by default. Each one trades something away, which is why none of them is on from the start.
Each row has a How it works and settings link that opens two short sections: What it does and When to leave it off. Read both before you switch anything on.
| Filter | What it is for |
|---|---|
| Handshake validation | Defeats spoofed connection floods, the cheapest way to exhaust a server. Needs the list of TCP ports you serve. |
| Connection rate limit | Slows down a single source opening connections faster than a real client would. Default 30 per second with a burst of 60. |
| Concurrent connection cap | Stops one address holding thousands of connections open. Default 200 per address. |
| Reflection filter | Blocks amplified UDP floods, where someone forges your address to aim a much larger reply at you. |
| Scan blocking | Temporarily shuts out addresses probing your server. Needs the list of TCP ports you serve. |
| Known attacker blocklist | Refuses traffic from networks documented as sources of attacks, and from addresses that cannot legitimately exist. |
| Country filter | Limits who can reach your server by country. Blunt, but effective when your audience is regional. |
| Strict ICMP | Removes ping and the diagnostic traffic that can be used to probe or flood you. |
| Outbound abuse guard | Stops your server being used to attack somebody else if it is ever compromised. |
The two that need ports
Handshake validation and Scan blocking need to know which TCP ports you actually serve. When you switch one on, the panel fills the list in from your firewall rules. If no rule allows a TCP port yet, it cannot work it out and asks you to list the ports yourself. Up to 64 ports.
The country filter
Two modes. Block listed refuses the countries you name. Allow only listed refuses everything except the countries you name.
Allow mode is the dangerous one. Put your own country in the list before you save, or you will not reach the server yourself. Up to 60 two letter country codes, comma separated, such as HU, DE, AT.
With no countries chosen the filter does nothing at all.
Related
- The firewall, which decides which ports are reachable in the first place
- Always allowed addresses, so a mistake never locks you out