Skip to content

DDoS Protection

1 Mitigation Levels

Our prefixes are generally in one of two DDoS protection classes:

  • Passive: Only basic mitigations (e.g., against volumetric attacks, floods, fragmentation, etc.) are active. This means that no restrictions are expected and latency is optimal due to the use of local peerings and carriers.
  • Permanent: All incoming traffic is routed exclusively through active DDoS mitigation. This can lead to restrictions (see below) and increased latency.

We reserve the right to change the mitigation level for a region without prior notice if we detect an attack that affects other customers (primarily volumetric attacks). Permanent application protection is available as an add-on; please contact us for more information.


2 Filterable Attack Patterns

The following attack patterns can currently be filtered:

  • IPv4+IPv6
  • UDP/TCP (+SYN+ACK)/ICMP Floods
  • Resource Exhaustion Attacks
  • IP Fragmentation Attacks
  • Zero Day Attacks1
  • Additional attack patterns based on machine learning

We do not provide an SLA for DDoS protection or attack filtering.


3 SmartMitigate

In addition to the standard protection, which detects attacks inline via sFlow/NetFlow, continuous filtering is also possible via SmartMitigate (our provider’s proprietary DDoS protection solution).

SmartMitigate enforces TCP/UDP authentication, which prevents TCP/UDP resets from being triggered during an attack. In addition, SmartMitigate responds more quickly to attacks. Customization of SmartMitigate rules is currently not possible.

We recommend setting frequently attacked IP addresses to permanent SmartMitigate. This can be done either via the BGP community 207252: 100: 50 or by submitting a ticket. An option for ccp.realtoxmedia.de is already in the works.

SmartMitigate is permanently enabled by default for the following port ranges: 30000-32000 (FiveM). The only way to disable filtering is via an IP whitelist. For example, you can have an IP network or an IP permanently unblocked via a ticket.

The following sources are on the global whitelist:

  • Cloudflare AS13335
  • Realtox Media AS207252

4 Rate Limits

4.1 TCP

The following restrictions apply to TCP attacks:

  • For applications using ports other than those listed below, “TCP resets” may occur; in such cases, a new connection must be established from the client to the server.
  • For connections established after an attack begins, TCP authentication must be performed. This results in the connection being reestablished. Connections that were active before the attack began are not affected by this.

4.2 UDP

Similar to TCP, resets may also occur here, though in most cases this does not pose a noticeable problem for UDP.

4.3 DNS

DNS traffic is rate-limited. The following public DNS resolvers have higher priority:

NameNameserver 1Nameserver 2
Cloudflare1.1.1.11.0.0.1
Google8.8.8.88.4.4.8
Quad99.9.9.9

Other Restrictions

  • GRE/GRE6/GRETAP/VXLAN traffic is blocked. Unblocking is possible via ticket with fixed source and destination IPs.
  • ICMP is dropped in the event of ICMP floods.
  • All types except 1/4/6/17 are dropped (unblocking possible via ticket).

5 Port Ranges

The following port ranges are specifically intended for the listed applications. If you run other applications within these ranges or a listed service outside of them, the traffic may be dropped at any time.

ProtocolPortApplication
UDP/TCP30000-32000FiveM
UDP34100-34200Factorio
UDP9000-9999TeamSpeak 3
UDP27000-28000Source Engine Game Server
UDP19100-19200Minecraft Bedrock
TCP/UDP25565-26000Minecraft Java
TCP/UDP8200-8300Palworld
UDP28015-28100Rust
UDP7100-7200SCP: Secret Laboratory
UDP1194-1294OpenVPN
UDP51820-51920WireGuard
UDP5520-5620Hytale/QUIC
TCP22SSH
TCP80HTTP
TCP443HTTPS

6 Application-Specific Information

This will also disable several other security mechanisms, which is why we only grant exemptions upon request and not as a general rule.

6.1 3CX Phone System

The UDP ports used by 3CX conflict with the TeamSpeak 3 port range. If you are running a 3CX instance, please contact us to request an exemption.

6.2 IPSEC

IPSEC is blocked by default by DDoS mitigation. Activation is possible via a support ticket.



  1. attacks that do not fall into other categories or are unknown