Their attack hits our IP. Not yours.
Built for game servers, voice, and any TCP/UDP application. Hand players our protected IP — your origin stays invisible while attacks die at the edge. Flat $3 per TB, unlimited ports.
Capabilities
Built for origins you already run
Six pillars of edge-to-origin protection — wherever your servers live.
Origin IP hidden
We issue you a Fluxorus protected IP. Attackers see our edge — never your real origin. We rotate the IP if it ever leaks.
L3–L7 mitigation
Volumetric, protocol, and application-layer attacks. SYN floods, UDP amplification, fragmentation, malformed packets — all absorbed at the edge.
TCP & UDP, any port
Game servers, voice, custom application protocols. Forward any TCP or UDP port. Unlimited ports on every plan.
Always-on filtering
Every packet inspected at line rate, 24/7. No 'attack detected' delay — mitigation runs continuously, not on demand.
Anycast edge
Attack traffic gets distributed across our global PoPs instead of concentrating at your origin's single uplink.
24/7 NOC response
Engineers on-call around the clock. Custom mitigation profiles tuned for your game protocol or app.
Use Cases
Built for who actually gets attacked
If your service has a public IP and pissed-off players, customers, or competitors, this is for you.
Roleplay & MMO servers
FiveM and large-population modded servers are top extortion targets. Stay online during ransom attacks and competitor harassment.
Voice & VoIP
TeamSpeak, Mumble, custom voice protocols. Low-jitter UDP forwarding from our anycast network — voice stays crisp through attacks.
Hosting providers
Resell protection to your customers under your own brand. Bulk pricing, reseller API, white-label dashboards — your IP space behind our edge.
Mid-attack rescue
Already getting hit with ransom demands? Provision a protected IP in under 10 minutes and route players to it — even with attacks in flight.
Custom TCP/UDP apps
Bot networks, IoT control planes, RCON management, custom orchestration protocols. If it runs on TCP or UDP, we forward it.
Sandbox & survival
Minecraft, Rust, Valheim, Terraria. UDP flood + RCON probes are constant. We filter at line rate so tick rates stay solid.
Pricing
$3 per TB. That's it.
Pay for the clean traffic you commit, not for attack volume. Plans start at 5 TB and scale to 100 TB — beyond that, contact sales. Every plan ships with unlimited ports.
Need more than 100 TB, a dedicated /29, or white-label? Contact sales.
How It Works
From sign-up to clean traffic
Three commands. No origin migration. Under ten minutes.
fluxorus protect --origin 198.51.100.7 --port 30120/udp,30120/tcpShare your origin IP and the TCP/UDP ports you need protected. We provision a Fluxorus protected IP and your port mappings within minutes.
fluxorus route --map 203.0.113.42:30120 --to origin:30120Hand players, voice clients, or bots the protected IP:port. They connect to us; we forward clean TCP/UDP to your origin. Your real IP stays invisible.
fluxorus status --tailOur anycast network absorbs L3-L7 attacks across all PoPs. Only clean post-mitigation traffic reaches your origin.
Specialized Filters
Tuned for the games you actually run
Generic L4 filtering blocks the obvious stuff. We layer protocol-aware mitigation on top, calibrated against real game traffic so legitimate players never see a captcha.
FiveM
UDP · 30120Custom L7 inspection tuned for GTA V netcode. Filters spoofed queries, malformed connection requests, and ENet-layer floods.
Rust
UDP · 28015Mitigates RakNet probe storms and connection flood attacks common to Rust servers. Validated against live game traffic patterns.
Minecraft
TCP · 25565Java + Bedrock signature filtering, slowloris-style handshake protection, and motd-scrape rate limiting.
TeamSpeak
UDP · 9987Low-jitter UDP forwarding for voice. Mitigates ServerQuery brute-force and amplification reflection across PoPs.
Running a game we haven't tuned for? Tell us the protocol and we'll build a custom filter profile — no extra charge.
Free Migration
Switching shouldn't mean downtime
Already protected somewhere else? Our team handles the entire migration — configuration audit, parallel provisioning, and a coordinated cutover so your players never see a disconnect.
Migration steps
- 01
Tell us your current setup
Share your existing provider, ports, and protocols. We map every game/app you're protecting today.
- 02
We provision in parallel
Your new protected IP and port mappings are live in minutes, side-by-side with your old setup.
- 03
Cut over when you're ready
Swap your DNS or in-game IP. Zero downtime — your old provider keeps running until the last player drains.
Comparison
How it stacks up
Most servers hang out naked on the internet. The rest pay opaque cloud bills. Neither feels good.
| What you care about | Fluxorus | Raw origin | Cloud providers |
|---|---|---|---|
| Origin IP exposure | Hidden behind our IP | Public, easy to scrape | Often exposed in TCP/UDP modes |
| Attack absorption | Multi-Tbps anycast | Crashes at first SYN flood | Plan-dependent |
| TCP/UDP ports | Unlimited, any port | All ports exposed | Limited port count per plan |
| Pricing model | $3 / TB, flat | Your bandwidth bill | Tiered + per-request + egress |
| Setup | Under 10 minutes | It's already there | Hours of config |
| Mitigation latency | Always-on, <1s | N/A | Detection-then-mitigate delay |
| NOC response | 24/7 with custom profiles | You and your pager | Business hours / SLA tier |
FAQ
Common questions
Everything we get asked before signing.
What does my TB commit get me?
A clean-traffic budget for the month. Pick how many TB of legitimate post-mitigation bandwidth you expect (5 TB minimum, up to 100 TB self-serve). Attack traffic we drop never counts. Need more than 100 TB? Contact sales — we'll size a custom plan.
What if I burst past my commit?
Short bursts are absorbed. If you're consistently exceeding your commit we'll suggest bumping up — there are no surprise overage bills, you just upgrade when you outgrow.
Do I need to move my origin to Fluxorus?
No. Your origin stays exactly where it is — AWS, GCP, OVH, your own colo, anywhere with a public IP. You just route traffic through our IP first.
What's a 'protected IP' — do I keep using my origin IP?
We issue you a Fluxorus-owned IP that becomes the public address for your service. Your real origin IP stays private; only our scrubbers know it. If it ever leaks, we rotate on request.
Will it slow down my game server?
Our edge is anycast-routed, so player traffic typically takes a shorter path than going direct. Typical added latency is 2–8ms when players are near a PoP — usually imperceptible at game tick rates.
What attack sizes can you mitigate?
Multi-Tbps. Our anycast network absorbs and disperses volumetric attacks across all PoPs simultaneously. We've eaten 800+ Gbps reflection attacks without an origin packet.
Do you protect HTTP / HTTPS web traffic?
No — we're focused on TCP/UDP forwarding for game servers, voice, and application protocols. If you need web app protection, look at our CDN product instead. We do this one thing well rather than spreading across HTTP.
Can I protect FiveM / Minecraft / TeamSpeak?
Yes. Every plan ships with unlimited ports on any protocol. FiveM (30120), Minecraft (25565), TeamSpeak (9987), Mumble, custom voice — forward as many as you need. No per-port fees.
By the Numbers
Always-on defense
Performance metrics from our production scrubbing infrastructure.
Ready to harden your origin?
Provision a protected IP in minutes. Hand it to your players, your DNS, or your customers — and watch attacks die at the perimeter.