Remote DDoS Protection

Their attack hits our IP. Not yours.

Built for game servers, voice, and any TCP/UDP application. Hand players our protected IP — your origin stays invisible while attacks die at the edge. Flat $3 per TB, unlimited ports.

L3-L7 Mitigation Origin IP hidden Unlimited ports 24/7 NOC
remote-ddos/scrubberMitigating
Internet12 Gb/s · 14 vectors
Fluxorus Edgeddos.fluxorus.com · 95% mitigated
Your Origin (IP hidden)600 Mb/s clean · 0% loss
12 Gb/s
In
95%
Mitigated
600 Mb/s
Clean

Capabilities

Built for origins you already run

Six pillars of edge-to-origin protection — wherever your servers live.

Origin IP hidden

We issue you a Fluxorus protected IP. Attackers see our edge — never your real origin. We rotate the IP if it ever leaks.

L3–L7 mitigation

Volumetric, protocol, and application-layer attacks. SYN floods, UDP amplification, fragmentation, malformed packets — all absorbed at the edge.

TCP & UDP, any port

Game servers, voice, custom application protocols. Forward any TCP or UDP port. Unlimited ports on every plan.

Always-on filtering

Every packet inspected at line rate, 24/7. No 'attack detected' delay — mitigation runs continuously, not on demand.

Anycast edge

Attack traffic gets distributed across our global PoPs instead of concentrating at your origin's single uplink.

24/7 NOC response

Engineers on-call around the clock. Custom mitigation profiles tuned for your game protocol or app.

Use Cases

Built for who actually gets attacked

If your service has a public IP and pissed-off players, customers, or competitors, this is for you.

Roleplay & MMO servers

FiveM and large-population modded servers are top extortion targets. Stay online during ransom attacks and competitor harassment.

FiveMARKConanDayZ

Voice & VoIP

TeamSpeak, Mumble, custom voice protocols. Low-jitter UDP forwarding from our anycast network — voice stays crisp through attacks.

TeamSpeakMumbleSIPCustom UDP

Hosting providers

Resell protection to your customers under your own brand. Bulk pricing, reseller API, white-label dashboards — your IP space behind our edge.

ResellerWhite-labelAPIBulk

Mid-attack rescue

Already getting hit with ransom demands? Provision a protected IP in under 10 minutes and route players to it — even with attacks in flight.

Active attackEmergency<10 min

Custom TCP/UDP apps

Bot networks, IoT control planes, RCON management, custom orchestration protocols. If it runs on TCP or UDP, we forward it.

RCONIoTBotsCustom

Sandbox & survival

Minecraft, Rust, Valheim, Terraria. UDP flood + RCON probes are constant. We filter at line rate so tick rates stay solid.

MinecraftRustValheimTerraria

Pricing

$3 per TB. That's it.

Pay for the clean traffic you commit, not for attack volume. Plans start at 5 TB and scale to 100 TB — beyond that, contact sales. Every plan ships with unlimited ports.

Clean traffic / month
25TB
5 TB minimum
Price
$75/ mo
$3/TB · flat
Ports
Unlimited
Protocols
TCP & UDP
Mitigation
Multi-Tbps
Setup
<10 min
Get protected · $75 / moUnlimited ports. No overages. Cancel anytime.

Need more than 100 TB, a dedicated /29, or white-label? Contact sales.

How It Works

From sign-up to clean traffic

Three commands. No origin migration. Under ten minutes.

fluxorus@onboarding ~
Step 01Tell us your origin
$fluxorus protect --origin 198.51.100.7 --port 30120/udp,30120/tcp
→ Validating origin reachability ...
→ Allocating Fluxorus protected IP from /24 pool ...
✓ Protected IP issued: 203.0.113.42

Share your origin IP and the TCP/UDP ports you need protected. We provision a Fluxorus protected IP and your port mappings within minutes.

Step 02Route traffic through our IP
$fluxorus route --map 203.0.113.42:30120 --to origin:30120
→ Building forwarding table across 23 PoPs ...
→ Anycast announcement propagating ...
✓ Forwarding active · origin IP hidden

Hand players, voice clients, or bots the protected IP:port. They connect to us; we forward clean TCP/UDP to your origin. Your real IP stays invisible.

Step 03Attacks die at the edge
$fluxorus status --tail
→ Ingress 12.4 Gb/s (14 vectors active)
→ Edge drops 95.1% · clean to origin 600 Mb/s
✓ Mitigating · origin healthy · 0.0% loss

Our anycast network absorbs L3-L7 attacks across all PoPs. Only clean post-mitigation traffic reaches your origin.

$
3 commands · zero downtime
Provisioned< 10 min
Origin migrationNone

Specialized Filters

Tuned for the games you actually run

Generic L4 filtering blocks the obvious stuff. We layer protocol-aware mitigation on top, calibrated against real game traffic so legitimate players never see a captcha.

FiveM

UDP · 30120

Custom L7 inspection tuned for GTA V netcode. Filters spoofed queries, malformed connection requests, and ENet-layer floods.

Rust

UDP · 28015

Mitigates RakNet probe storms and connection flood attacks common to Rust servers. Validated against live game traffic patterns.

Minecraft

TCP · 25565

Java + Bedrock signature filtering, slowloris-style handshake protection, and motd-scrape rate limiting.

TeamSpeak

UDP · 9987

Low-jitter UDP forwarding for voice. Mitigates ServerQuery brute-force and amplification reflection across PoPs.

Running a game we haven't tuned for? Tell us the protocol and we'll build a custom filter profile — no extra charge.

Free Migration

Switching shouldn't mean downtime

Already protected somewhere else? Our team handles the entire migration — configuration audit, parallel provisioning, and a coordinated cutover so your players never see a disconnect.

Migration steps

  1. 01

    Tell us your current setup

    Share your existing provider, ports, and protocols. We map every game/app you're protecting today.

  2. 02

    We provision in parallel

    Your new protected IP and port mappings are live in minutes, side-by-side with your old setup.

  3. 03

    Cut over when you're ready

    Swap your DNS or in-game IP. Zero downtime — your old provider keeps running until the last player drains.

Comparison

How it stacks up

Most servers hang out naked on the internet. The rest pay opaque cloud bills. Neither feels good.

Origin IP exposure
Fluxorus
Hidden behind our IP
Raw
Public, easy to scrape
Cloud
Often exposed in TCP/UDP modes
Attack absorption
Fluxorus
Multi-Tbps anycast
Raw
Crashes at first SYN flood
Cloud
Plan-dependent
TCP/UDP ports
Fluxorus
Unlimited, any port
Raw
All ports exposed
Cloud
Limited port count per plan
Pricing model
Fluxorus
$3 / TB, flat
Raw
Your bandwidth bill
Cloud
Tiered + per-request + egress
Setup
Fluxorus
Under 10 minutes
Raw
It's already there
Cloud
Hours of config
Mitigation latency
Fluxorus
Always-on, <1s
Raw
N/A
Cloud
Detection-then-mitigate delay
NOC response
Fluxorus
24/7 with custom profiles
Raw
You and your pager
Cloud
Business hours / SLA tier

FAQ

Common questions

Everything we get asked before signing.

What does my TB commit get me?

A clean-traffic budget for the month. Pick how many TB of legitimate post-mitigation bandwidth you expect (5 TB minimum, up to 100 TB self-serve). Attack traffic we drop never counts. Need more than 100 TB? Contact sales — we'll size a custom plan.

What if I burst past my commit?

Short bursts are absorbed. If you're consistently exceeding your commit we'll suggest bumping up — there are no surprise overage bills, you just upgrade when you outgrow.

Do I need to move my origin to Fluxorus?

No. Your origin stays exactly where it is — AWS, GCP, OVH, your own colo, anywhere with a public IP. You just route traffic through our IP first.

What's a 'protected IP' — do I keep using my origin IP?

We issue you a Fluxorus-owned IP that becomes the public address for your service. Your real origin IP stays private; only our scrubbers know it. If it ever leaks, we rotate on request.

Will it slow down my game server?

Our edge is anycast-routed, so player traffic typically takes a shorter path than going direct. Typical added latency is 2–8ms when players are near a PoP — usually imperceptible at game tick rates.

What attack sizes can you mitigate?

Multi-Tbps. Our anycast network absorbs and disperses volumetric attacks across all PoPs simultaneously. We've eaten 800+ Gbps reflection attacks without an origin packet.

Do you protect HTTP / HTTPS web traffic?

No — we're focused on TCP/UDP forwarding for game servers, voice, and application protocols. If you need web app protection, look at our CDN product instead. We do this one thing well rather than spreading across HTTP.

Can I protect FiveM / Minecraft / TeamSpeak?

Yes. Every plan ships with unlimited ports on any protocol. FiveM (30120), Minecraft (25565), TeamSpeak (9987), Mumble, custom voice — forward as many as you need. No per-port fees.

By the Numbers

Always-on defense

Performance metrics from our production scrubbing infrastructure.

Multi-Tbit/s
Mitigation Capacity
<1s
Response Time
0.0%
Packet Loss
24/7
Always-On Protection

Ready to harden your origin?

Provision a protected IP in minutes. Hand it to your players, your DNS, or your customers — and watch attacks die at the perimeter.