Skip to content
Sentrix Shield

DDoS protection included, not sold separately

Plenty of providers advertise protection and then charge to switch it on when you need it. Here it's standard on every plan.

  • Layer 3 to 7
  • No attack cap
  • No extra cost
How it works

Three layers, three different kinds of attack

A volumetric attack and an application-level one have nothing in common. Each layer needs a different defence.

L3

Network layer

ICMP floods and packet fragmentation. Filtered at the edge, before they reach our routers.

L4

Transport layer

SYN floods, UDP floods and DNS or NTP amplification. The pattern is matched by signature and dropped.

L7

Application layer

Bots that imitate real players. This is where we apply game-specific rules, and it's what makes the difference.

Live simulation

Watch an attack hit the shield

Fifteen seconds, three attack vectors, one server that never notices. Press play: green packets are your players, red ones are the attack.

L3L4L7
0.0s / 15s

Traffic sources

Your players

62 connected

0.38Gbps

Botnet

0Gbps

Inbound

0.4Gbps

Sentrix Shield

Blocked

Your server

sentrixnode

Online

Delivered
0.38Gbps
Latency
17ms
Your players
62
Uptime this run
100%

Mitigation log

  1. Idle — press play to start the simulation

Dramatisation with realistic figures, not live telemetry. Real mitigation is automatic and needs no action from you.

Sentrix Shield

Stay online whatever happens

Sentrix Shield is our own anti-DDoS infrastructure — our hardware, our rules, our engineers. Filtering runs at layers 3, 4 and 7 on every plan, with no attack cap and no surcharge when it is your turn.

Layer 3 · volumetric

Amplification and reflection floods absorbed at our own edge, before they reach the node your server runs on.

Layer 4 · state exhaustion

SYN floods and half-open connection attacks stopped with SYN cookies and rate limits tuned per protocol.

Layer 7 · application

Bots that imitate real game clients, caught by per-game fingerprint rules. This is the layer generic providers miss.

99.99%

Uptime

2 Tbps

Filtering capacity

<1ms

Reaction time

Live log

  • UDP flood filtered · 42 Gbps · 0.8 ms
  • SYN flood filtered · 1.2 Mpps · 0.4 ms
  • Layer 7 · bot pattern blocked
  • ·Service uninterrupted

Illustrative example. Wire in your real telemetry to show live data.

What you should do too

Protection doesn't cover everything

No filter replaces sensible configuration. These three measures avoid most of the problems we see in tickets.

  • Don't hand out the direct IP

    Always give the subdomain. If someone knows the node's IP, they can hit you outside the application filter.

  • Limit connections per IP

    Most games let you cap connection attempts. It's the single most effective defence against layer 7 bots.

  • Close administrative ports

    RCON and web panels shouldn't be open to the internet. Use them behind the reverse proxy.

Common questions

Frequently asked questions

No. It's included on every plan, with no cap on attacks or volume. We don't charge you for defending you.

Still have a question?

Our team answers at any hour. You can also search the knowledge base.

Reviews

What people hosting with us say

You can read every review, unfiltered, on our public profile.

4.8 out of 5 · 420 reviews

Moved three servers over from another host on a Sunday night and support stayed with me the whole way. Zero downtime.

Sample review

Replace with real text

The ping meter pushed me to New York instead of Miami and it shows: my players went from 40 ms to 18 ms.

Sample review

Replace with real text

I run a heavy modpack with 30 people inside and TPS doesn't budge off 20. Best panel I've used.

Sample review

Replace with real text

We got attacked in week one and never noticed until we saw the graph. Mitigation handled it on its own.

Sample review

Replace with real text

Protect your server from day one

No lock-in, no setup fee, and a free day to try it before you commit.