Skip to content

Attacks stop before they reach you.

Game or bare metal, your server sits behind Terabit DDoS Protection in every region we run. It is on from the first minute, it is not an add-on, and it costs nothing extra. Wipe day, raid night, a 100-player milsim op, the filtering does not care.

on every plan
500+ Tbps

Always on

5

Every one protected

Every plan

Game and bare metal

$0

Never an upsell

On from the first minute, included on every plan

Watch a flood hit the filter.

This is the real Terabit mitigation visualisation. Turn the filtering off and watch the attack traffic reach the origin. Turn it back on and watch it stop.

Attack traffic is absorbed at the edge, game-aware rules drop what is left, and only real player traffic reaches your server.

The interactive version renders in WebGL and needs a larger screen. Open this page on a desktop and you can drive the attack rate yourself.

Four stages, none of them on your node.

Filtering happens upstream. By the time traffic reaches your server it has already been through every stage below.

01

Anycast ingress

Traffic enters at the closest edge instead of a single choke point, so a flood is split geographically before anything is filtered.

02

Volumetric scrubbing

L3 and L4 floods are absorbed at edge capacity. The bulk of any attack dies here, off your node entirely.

03

Stateful filtering

What survives meets protocol-aware and game-aware rules that understand what a real join looks like and what a forged one looks like.

04

Clean traffic

Only validated traffic reaches your server. Your players stay connected and your tick rate does not move.

What it actually stops.

Volumetric floods are the easy half. The half that breaks game servers is protocol abuse that looks almost exactly like a real player.

Volumetric

  • TCP flood (ACK, PSH, SYN, RST, URG)
  • UDP flood
  • ICMP flood
  • GTP and ESP flood
  • Ping of Death
  • Teardrop and reflected

Reflection and amplification

  • DNS amplification
  • NTP amplification
  • SSDP and UPnP
  • Memcached
  • QUIC
  • Chargen, SNMP, LDAP, RIP, TFTP

Resource exhaustion

  • Malformed and truncated packets
  • IP fragmentation
  • Invalid TCP flag attacks
  • Bad checksums
  • Bogus TCP and UDP flags
  • Reserved IP addresses

Gaming

  • A2S source flood
  • A2S GETSUM
  • FiveM exhaustion
  • Handshake abuse
  • HTTP Slowloris
  • NetBIOS

The filtering is the same on every server.

There is no tier to choose and nothing to switch on. Every server gets the same profile, on every plan, at no extra cost.

Terabit DDoS Protection

Included

Included on every server, in Dallas, Los Angeles, New York, Frankfurt and Sydney.

  • 500+ Tbps volumetric capacity
  • 13+ Tbps stateful filtering
  • Built for Arma Reforger traffic

What came with Terabit.

Loafhosts is now owned by Terabit.io, and the protection stack got deeper because of it. The first two are live. The last one is still on the way.

Real-time attack alerts

Discord and email notifications the moment an attack starts, and again when it clears. Every server keeps its own attack history, so you can see when you were hit and how long it ran.

Terabit bare metal

Loafhosts infrastructure now runs on Terabit-owned hardware across every region we operate.

Upstream firewall manager

Soon

Allow and deny rules per protocol and per country, plus mitigation profiles on individual ports, applied at the network edge. The per-server Firewall Manager is already live; this one filters upstream of it.

Protected from the first minute.

You do not configure it, you do not pay extra for it, and you do not wait for an attack to find out whether it works.

Included on every plan · No setup fees · Cancel any time