DDoS Protection
Every Galaxy Nexus server comes with enterprise-grade DDoS protection at no extra cost. Our network filters malicious traffic before it reaches your server, keeping your game online even during an attack.
What's Included
All plans include the same protection tier:
| Feature | Coverage |
|---|---|
| TCP filtering | Blocks volumetric floods and SYN attacks |
| UDP filtering | Game-specific UDP protection with rate limiting |
| Application-layer | HTTP/HTTPS flood mitigation |
| DNS amplification | Blocks reflected amplification attacks |
| Scrubbing capacity | Multi-Tbps network edge capacity |
No Configuration Required
DDoS protection is fully automatic. There's nothing to install, no settings to tweak, and no additional cost. It's active the moment your server deploys.
How It Works
Player Traffic ──→ Border Router ──→ DDoS Mitigation ──→ Clean Traffic ──→ Your Server
↑
Malicious traffic
dropped at the edge
- Traffic enters our network through border routers in Brisbane and Dallas
- Mitigation hardware analyses every packet in real-time, comparing traffic patterns against known attack signatures
- Malicious packets are dropped at the network edge — they never reach your server
- Clean traffic passes through with minimal latency (typically < 1ms added)
- Your server never sees the attack — CPU, RAM, and bandwidth usage remain normal
Detection Methods
Our mitigation system uses multiple detection layers:
- Statistical anomaly detection — compares current traffic to your server's baseline
- Protocol validation — drops packets that violate TCP/UDP protocol standards
- Rate-based thresholds — auto-triggers when traffic exceeds your server's normal pattern
- Signature matching — blocks known attack vectors (amplification, reflection, flooding)
- Challenge-response — silently verifies legitimate players via SYN cookies
Game-Specific Protection
Different games use different protocols. Our filters are tuned per game:
| Game | Primary Protocol | Protection Method |
|---|---|---|
| Minecraft Java | TCP 25565 | TCP scrubbing + rate limiting |
| Minecraft Bedrock | UDP 19132 | UDP flood mitigation |
| Rust | UDP 28015 | Game-specific UDP filtering |
| ARK | UDP 7777-7778 | Query/Game port protection |
| CS2 | UDP 27015 | Source engine packet validation |
| Valheim | UDP 2456-2458 | Steam networking protection |
Custom Ports
If your server uses a non-standard port, you can register it in the panel under Network → Port Registration. This lets our filters apply the correct protection profile.
What Happens During an Attack
Stage 1: Detection (0-10 seconds)
Attack is detected and mitigation kicks in automatically. Your server continues processing legitimate player traffic normally.
Stage 2: Mitigation (ongoing)
Malicious traffic is dropped at the edge. Legitimate players continue connecting. You may notice:
- Slightly higher ping for players far from our data centres (typically +2-5ms)
- A brief connection reset for players who were on unusual routes (they reconnect within seconds)
- No change in server performance — CPU and RAM usage stay normal
Stage 3: Reporting
Within 24 hours of a detected attack, we send an automated report to your account email:
Subject: DDoS Attack Mitigation Report — [Server Name]
Attack detected: 2026-07-15 14:32:00 UTC
Duration: 18 minutes
Peak traffic: 47 Gbps
Packets dropped: 3,200,000+
Mitigation status: Successful
Server impact: None
If Your Server Goes Offline During an Attack
This is extremely rare, but if it happens:
- Don't change your server IP — it won't help and you'll lose DNS propagation time
- Open a support ticket immediately — mark it as urgent
- Don't restart repeatedly — it doesn't help and may trigger rate limiting
False Positives
Occasionally, legitimate traffic can be misidentified as malicious. This is rare but can happen with:
- VPN users — large shared IP ranges sometimes get rate-limited
- Players behind CGNAT — carrier-grade NAT can make individual players look like many
- Server listing sites — some monitoring services ping in patterns that look like scans
Reporting a False Positive
If a player can't connect and you suspect a false positive:
- Ask them to try again after 60 seconds (temporary blocks auto-expire)
- If the issue persists, open a ticket with:
- The player's IP address (they can find it at whatismyip.com)
- The approximate time the connection was blocked
- Your server's IP and game type
We'll investigate and whitelist the address if it was incorrectly blocked.
Attack Protection Best Practices
DDoS protection is only one layer. Combine it with these practices:
1. Keep Your Server Software Updated
Exploits in outdated game servers are a common attack vector. Enable auto-updates where available and check for patches regularly.
2. Use Strong Server Passwords
A weak password lets attackers in without needing a DDoS. Use the panel's password generator and enable 2FA on your account.
3. Don't Share Your IP Publicly
Post your server on community listing sites using your hostname (e.g. play.yourdomain.com) rather than the raw IP. Hostnames can be changed if they become a target.
4. Configure a Firewall
Your panel includes a server-level firewall. Set it to:
- Allow only the game port and any needed management ports
- Block everything else
- Rate-limit connections from unknown IPs
5. Monitor Your Traffic
Check your server's traffic graphs in the panel. A sudden spike of inbound traffic that doesn't match player count is often an early warning sign.
Need Help?
Our network team monitors all servers 24/7. If you're experiencing connection issues that you suspect are attack-related, reach out on Discord or open a ticket. Include your server name and the time the issue started.