DDoS Protection¶
1 Mitigation Levels¶
Our prefixes are generally in one of two DDoS protection classes:
- Passive: Only basic mitigations (e.g., against volumetric attacks, floods, fragmentation, etc.) are active. This means that no restrictions are expected and latency is optimal due to the use of local peerings and carriers.
- Permanent: All incoming traffic is routed exclusively through active DDoS mitigation. This can lead to restrictions (see below) and increased latency.
We reserve the right to change the mitigation level for a region without prior notice if we detect an attack that affects other customers (primarily volumetric attacks). Permanent application protection is available as an add-on; please contact us for more information.
2 Filterable Attack Patterns¶
The following attack patterns can currently be filtered:
- IPv4+IPv6
- UDP/TCP (+SYN+ACK)/ICMP Floods
- Resource Exhaustion Attacks
- IP Fragmentation Attacks
- Zero Day Attacks1
- Additional attack patterns based on machine learning
We do not provide an SLA for DDoS protection or attack filtering.
3 SmartMitigate¶
In addition to the standard protection, which detects attacks inline via sFlow/NetFlow, continuous filtering is also possible via SmartMitigate (our provider’s proprietary DDoS protection solution).
SmartMitigate enforces TCP/UDP authentication, which prevents TCP/UDP resets from being triggered during an attack. In addition, SmartMitigate responds more quickly to attacks. Customization of SmartMitigate rules is currently not possible.
We recommend setting frequently attacked IP addresses to permanent SmartMitigate. This can be done either via the BGP community 207252: 100: 50 or by submitting a ticket. An option for ccp.realtoxmedia.de is already in the works.
SmartMitigate is permanently enabled by default for the following port ranges: 30000-32000 (FiveM). The only way to disable filtering is via an IP whitelist. For example, you can have an IP network or an IP permanently unblocked via a ticket.
The following sources are on the global whitelist:
- Cloudflare AS13335
- Realtox Media AS207252
4 Rate Limits¶
4.1 TCP¶
The following restrictions apply to TCP attacks:
- For applications using ports other than those listed below, “TCP resets” may occur; in such cases, a new connection must be established from the client to the server.
- For connections established after an attack begins, TCP authentication must be performed. This results in the connection being reestablished. Connections that were active before the attack began are not affected by this.
4.2 UDP¶
Similar to TCP, resets may also occur here, though in most cases this does not pose a noticeable problem for UDP.
4.3 DNS¶
DNS traffic is rate-limited. The following public DNS resolvers have higher priority:
| Name | Nameserver 1 | Nameserver 2 |
|---|---|---|
| Cloudflare | 1.1.1.1 | 1.0.0.1 |
| 8.8.8.8 | 8.4.4.8 | |
| Quad9 | 9.9.9.9 |
Other Restrictions
- GRE/GRE6/GRETAP/VXLAN traffic is blocked. Unblocking is possible via ticket with fixed source and destination IPs.
- ICMP is dropped in the event of ICMP floods.
- All types except 1/4/6/17 are dropped (unblocking possible via ticket).
5 Port Ranges¶
The following port ranges are specifically intended for the listed applications. If you run other applications within these ranges or a listed service outside of them, the traffic may be dropped at any time.
| Protocol | Port | Application |
|---|---|---|
| UDP/TCP | 30000-32000 | FiveM |
| UDP | 34100-34200 | Factorio |
| UDP | 9000-9999 | TeamSpeak 3 |
| UDP | 27000-28000 | Source Engine Game Server |
| UDP | 19100-19200 | Minecraft Bedrock |
| TCP/UDP | 25565-26000 | Minecraft Java |
| TCP/UDP | 8200-8300 | Palworld |
| UDP | 28015-28100 | Rust |
| UDP | 7100-7200 | SCP: Secret Laboratory |
| UDP | 1194-1294 | OpenVPN |
| UDP | 51820-51920 | WireGuard |
| UDP | 5520-5620 | Hytale/QUIC |
| TCP | 22 | SSH |
| TCP | 80 | HTTP |
| TCP | 443 | HTTPS |
6 Application-Specific Information¶
This will also disable several other security mechanisms, which is why we only grant exemptions upon request and not as a general rule.
6.1 3CX Phone System¶
The UDP ports used by 3CX conflict with the TeamSpeak 3 port range. If you are running a 3CX instance, please contact us to request an exemption.
6.2 IPSEC¶
IPSEC is blocked by default by DDoS mitigation. Activation is possible via a support ticket.
attacks that do not fall into other categories or are unknown ↩