Overview
Protect a game server that runs on your own machine: the network announces its address, filters attacks with checks that understand the game, and sends the clean traffic to your server through a tunnel.
| Server | Status | Players |
|---|---|---|
| not monitored |
Game Servers
Each game server is a protected address on the anycast network. Its ports pick their protection; linked to a tunnel, its clean traffic goes to your own server. Open one to see how it’s doing and manage it.
No game servers yet. “Protect a game server” sets one up with its tunnel and ports.
Nothing yet: add a game server or open a port.
| Service | Status | Players | Ports | |
|---|---|---|---|---|
| not monitored |
|
This node isn't filtering, so it tracks nothing.
No open connections.
| Server Port | Remote | Protocol | State | Expires in |
|---|---|---|---|---|
| — |
Where the address's clean traffic goes. Tunnels are managed on their own pages under Networking.
Each address you add is protected by the nodes, and its traffic is forwarded through this tunnel to your server. Open ports or add game servers on the address's page afterwards.
No free IPv4 addresses in your IP blocks.
None yet. Add addresses here, or protect a game server and choose this tunnel.
Round Trip
No probes yet (an origin behind NAT isn't probed; its keepalives are the signal).
Traffic
Tests
| Hop | Address | Network | Loss | Best | Avg | Worst | Jitter |
|---|---|---|---|---|---|---|---|
| origin |
Loss at a hop counts only if every later hop shows it too; a router answering few probes is just rate-limiting them. Conclusions are in the findings above.
Recent events
Run this on your server, on any Linux with systemd. It installs kad-tunnel as a service that starts at boot, and from then on the panel sets its addresses and upgrades it. The command works for an hour.
A newer kad-tunnel is available. Upgrading takes a few seconds of downtime; if the new version keeps failing, your server goes back to the previous one by itself.
Set it up by hand instead
Run these as root on your server so it accepts the forwarded traffic and replies through the tunnel:
No query port is protected, so KAD can't see what the server tells the server browser. Add the game's query port (Source engine protection) under Ports.
| Name | Score | Time |
|---|---|---|
| Rule | Value |
|---|---|
This game server's ports: its primary port (the address and port it's known by) and the ports that belong to it. Each picks its protection; traffic to a port no game server on the address has is handled by the unmatched-traffic setting.
No ports.
For people: shown when the server doesn't answer queries (while it answers, the panel shows the name it reports). Change it any time; the server is known by its address and port.
Monitoring is off for its tunnel, so it isn't counted either.
Domains
No domains configured
| Name | Track | Metric | Period | Threshold | Action | Cookie |
|---|---|---|---|---|---|---|
| Node | Step | Mode | Request Rate | Error Rate | Baseline | Time |
|---|---|---|---|---|---|---|
No subdomains configured
Address Lists
A named list of addresses and prefixes that allow and block rules on any of your addresses can use: for example the admins allowed to RCON every game server. Change the list and every rule on it follows within seconds. Add a rule from an address's Firewall tab.
No address lists yet.
Address Space
No addresses yet. Protecting a game server protects its address.
Tunnels
A tunnel carries a protected address's clean traffic from the anycast nodes to your own server (the origin), and its replies back. Add addresses to it to use it.
No tunnels yet. Create one to your game server, or use "Protect a game server" on the customer's overview.
Users
No users
Certificates
No certificates yet. Request one for a domain above, or upload your own.
Challenge Page
Shown to visitors of your websites when they are asked to prove they are human.
Only customer admins can change the branding.
Suspicion
Every visitor to this customer's websites gets a suspicion score from signals such as datacenter or VPN networks, reputation and location. Visitors scoring at or above the threshold are challenged. Country and continent lists raise or lower the score by location.
| Continent | Trusted | Suspicious |
|---|---|---|
Only a customer admin can change these settings.
Rate Limits
HTTP rate limits for this customer's websites, enforced by the proxy on every node. They apply to all the customer's domains unless a domain sets its own. Game and other UDP services are rate-limited per protected address instead.
Only a customer admin can change rate limits.
Anomaly Detection
Learns each domain's normal request rate. When traffic or errors stay well above it, the domain's protection steps up the escalation ladder, and steps back down once traffic settles.
None. All this customer's domains are at their normal protection.
| Domain | Step | Protection Now | Normal Rate |
|---|---|---|---|
Each step replaces the domain's protection while it stays escalated.
Only a customer admin can change these settings.
Threat Detection
Floods the nodes detected against this customer's addresses. Blocking rules drop the traffic on every node until they expire. Recommendations are floods that weren't confident enough to block on their own: block or dismiss them here.
No floods detected against this customer right now.
Alerts
Active alerts about this customer's services: attacks, tunnels going down, certificates, quotas.
No active alerts.
Quotas
How much of each resource this customer uses, against its limit. At the limit, new items are refused; nothing existing is removed.