Skip to content
FadedServers

Shield:

Active on every service

The attack ends before your players notice

FadedServers Shield is our always-inline mitigation system. Malicious traffic is fingerprinted and dropped at the network edge in under a second, while legitimate players keep the connection they already had. It is included on every plan we sell.

Included on every service
Under 1 second to mitigate
Always inline, never on demand
24/7 mitigation NOC

Traffic through Shield during a live attack

A representative four-hour window. Legitimate traffic is unaffected while the flood peaks at 500 Gbps.

Blocked malicious

Allowed legitimate

1 Tbps+

Global scrubbing capacity across our mitigation network

<1 sec

From the first malicious packet to a filter being applied

65,000+

Attacks already mitigated for Australian communities

24/7

On-call network engineers, not a ticket queue

How Shield stops an attack

Most hosts sell DDoS protection that only turns on once someone notices. Shield never turns off.

Your traffic already runs through it

Shield is inline by default. There is no BGP swing to trigger, no dashboard button to press and no window where an attack lands on bare IPs while protection spins up. The filtering path is the only path.

Every packet is fingerprinted

Detection runs continuously against packet rate, protocol behaviour and source reputation. When a flood starts it is profiled and matched to a signature in under a second, without waiting on a human to notice a graph.

Attack traffic is dropped, yours is not

Filters are applied at the edge and tuned adaptively as the attack changes shape. Legitimate players keep their connections. Nobody gets null-routed, and nobody gets an email telling them their IP is offline for the next four hours.

What it filters

Coverage runs from layer 3 through layer 7, with signatures written for the attacks aimed at game servers specifically.

Volumetric floods

The raw bandwidth attacks that saturate a link before the server ever sees them.

  • TCP SYN, ACK, PSH, RST and URG floods
  • UDP floods and UDP fragmentation
  • ICMP floods and Ping of Death

Reflection and amplification

Small requests bounced off open internet services to multiply into hundreds of gigabits.

  • DNS, NTP and LDAP amplification
  • SSDP/UPnP, SNMP and Chargen reflection
  • Memcached, TFTP, RIP and Smurf

Resource exhaustion

Malformed traffic designed to burn CPU on your machine rather than fill your pipe.

  • Malformed packets and bad checksums
  • IP fragmentation and invalid TCP segments
  • Illegal TCP/UDP flags and reserved addresses

Game layer attacks

Protocol-aware filtering for the floods aimed specifically at game servers.

  • A2S Source floods and A2S GETSUM
  • FiveM exhaustion and RTFM requests
  • Minecraft protocol abuse, TS3INIT and NetBIOS

Built for game traffic, not web traffic

Generic scrubbing treats a burst of small UDP packets as an attack. That is also what a busy Minecraft or FiveM server looks like. Shield understands the protocols underneath, so it can tell a query flood from a full lobby.

It never adds lag

Filtering happens inline at the edge on the path your traffic already takes. There is no detour through a remote scrubbing centre and no extra hops added to your players’ route.

Nothing to configure

Shield is on from the moment your service is provisioned. No thresholds to guess at, no protection mode to remember to enable before a raid night.

Humans behind the automation

Automated mitigation handles the flood, and on-call network engineers pick up anything unusual. If something needs a hand-written filter, someone writes it.

We answer for it

You are not being handed a vendor support portal. If an attack causes you trouble, you talk to us in Discord or a ticket and we chase it down.

Capacity where the attacks come from

A flood aimed at Sydney is usually sourced from the other side of the world. Shield drops it at the closest edge instead of hauling it across the Pacific first.

Australia

Sydney, alongside the hardware we host

New Zealand

Local capacity for trans-Tasman communities

Asia

Filtering close to APAC source traffic

Europe & UK

Scrubbing before floods cross the ocean

North America

Coverage across the largest attack origin

Questions we get a lot

Shield comes with the server

Every game server, VPS, dedicated server and colocated rack we sell sits behind it at no extra cost. Pick the hardware and the protection is already there.

Running your own hardware, or need managed firewall policy on top of Shield?