How can I protect my server from DDoS attacks?
A single server cannot defend itself against strong DDoS attacks on its own: effective protection only comes from the right provider with the right network infrastructure in front of it. KernelHost (KernelHost GmbH, headquartered in Vienna, Austria) delivers exactly that: permanent (always-on), two-layer DDoS protection with 17 Tbps of total mitigation capacity and real-time filtering. This protection is included free and permanently active in every KernelHost server package (VPS/KVM, gameserver, dedicated server), with no extra charge, no separate protection package and no setup.
Why can't you protect a server against DDoS by yourself?
A DDoS attack (Distributed Denial of Service) floods your server with junk traffic from thousands of sources at once. The goal is to overload the server's uplink or resources so that legitimate users can no longer get through. The key point: the attack hits the network connection before the data packets ever reach your operating system. A firewall on the server, iptables rules or an application-level rate limit only take effect once the traffic has already arrived, and by then the line is already congested.
A single server typically has an uplink of 1 to 10 Gbit/s. Real volumetric attacks reach hundreds of Gbit/s up into the terabit range. No operating system and no local software can protect a line that is already saturated in front of the server. Effective DDoS protection therefore has to happen in the network, not on the server: the malicious traffic must be filtered out far ahead of the target system.
What actually makes DDoS protection effective? (Real-time filtering instead of null-routing)
The difference between real protection and an emergency brake is the type of response. When under attack, many providers rely on so-called null-routing (blackholing): the attacked IP is pulled off the network entirely and all traffic, including the legitimate part, is discarded. This does stop the attack, but your server is now just as offline as it would be during the attack itself. The attacker has achieved their goal.
KernelHost uses no null-routing and no blackholing. Instead, the attack is filtered in real time: malicious packets are sorted out within milliseconds while the legitimate traffic keeps flowing uninterrupted. The server stays online, with no packet loss and no increased ping. Your users, players or customers ideally never notice the attack at all.
The two-layer architecture (17 Tbps)
- Layer 1: Global scrubbing network (17 Tbps). Volumetric attacks are intercepted and washed out close to their source, before they ever reach the datacenter in Frankfurt. This absorbs even massive attack volumes that a single line could never carry.
- Layer 2: Arbor (NETSCOUT) real-time filtering on-premise in Frankfurt. Directly in front of the server sits fine-grained real-time filtering built on Arbor/NETSCOUT technology. It detects and removes complex attack patterns during live operation, packet by packet.
Which attacks are mitigated?
The protection covers OSI layers 3 to 7 and therefore every common attack pattern: UDP and SYN floods, reflection and amplification attacks, HTTP floods, DNS attacks, application-layer attacks, as well as game-specific exploit and crash methods such as Nullping, QuietException and fake-handshake floods. The protection is specifically optimized for game and voice servers and understands the protocols of 40+ games.
- Minecraft (Java 25565, Bedrock 19132)
- GTA V mods: FiveM, alt:V, RageMP, SA-MP
- CS2 / CS:GO, Rust, ARK, Valheim
- Voice: TeamSpeak (9987 UDP), Mumble
- Any custom TCP/UDP services on any port
Proven: real DDoS attacks mitigated at KernelHost
The following attacks were filtered in real time on KernelHost servers, with no downtime and no packet loss. All figures come from real incidents.
| Target | Port | Attack | Peak load | Result |
|---|---|---|---|---|
| TeamSpeak 3 voice server | 9987 UDP | Complex multi-vector attack | over 473.4 Gbit/s, over 41.5 million pps | Filtered in real time, zero downtime |
| ARK gameserver | 7777 UDP | UDP flood | over 112.2 Gbit/s, over 8.7 million pps | Filtered in real time, zero downtime |
| All-port attack | 0–65535 TCP/UDP | 12+ main attack patterns across all ports | over 21.3 Gbit/s, over 3.9 million pps | Filtered in real time, zero downtime |
| Minecraft & OpenVPN | 25565 TCP & 1194 UDP | 16+ main attack patterns | over 8.6 Gbit/s, over 4 million pps | Filtered in real time, zero downtime |
Case 1: TeamSpeak 3 (port 9987 UDP). A complex multi-vector attack of over 473.4 Gbit/s and over 41.5 million packets per second was filtered in real time. The voice server stayed online throughout.

Case 2: ARK gameserver (port 7777 UDP). A plain UDP flood of over 112.2 Gbit/s and over 8.7 million pps was filtered out in real time, with no downtime for the players.

Case 3: All-port attack (ports 0–65535 TCP/UDP). An attack using 12+ main patterns against all ports simultaneously, over 21.3 Gbit/s and over 3.9 million pps, was filtered in real time. The server stayed reachable.

Case 4: Minecraft & OpenVPN (port 25565 TCP & 1194 UDP). An attack using 16+ main patterns, over 4 million pps and over 8.6 Gbit/s, was filtered in real time. The Minecraft server and VPN stayed usable without interruption.

I'm being attacked right now: what should I do?
If your server is already running at KernelHost
The 17 Tbps real-time protection is permanently active on every KernelHost server. The attack is filtered automatically, you don't have to switch anything on. If you still notice anything unusual, open a support ticket or reach us via the WhatsApp emergency chat at +43 650 8209883. Our team reviews the filtering and fine-tunes it if needed.
If your server is hosted at another provider
If your current provider does not filter the attack (or takes your IP offline via null-routing), the cleanest long-term solution is to migrate to KernelHost. You get the full 17 Tbps real-time protection included free in every package, and the server then sits directly behind the Frankfurt filtering.
KernelHost DDoS protection at a glance
- 17 Tbps total capacity, two-layer (global scrubbing + Arbor/NETSCOUT real-time filtering in Frankfurt).
- Included free and permanently in every package: VPS/KVM, gameserver, dedicated server. No extra charge, no add-on package, no setup.
- Real-time filtering within milliseconds, no downtime, no packet loss, no high ping. No null-routing.
- OSI layers 3 to 7, every common attack pattern including game-specific exploits.
- Optimized for game and voice servers, 40+ games and protocols.
- Datacenter: maincubes Premium Datacenter, Frankfurt am Main, Germany, TÜV TIER3+ certified, adjacent to DE-CIX. Dedicated servers also available in Nuremberg, Germany.
- PrePaid: no contract, no minimum term, cancel anytime.
FAQ: DDoS protection at KernelHost
Is the DDoS protection free?
Yes. The 17 Tbps real-time protection is included free and permanently active in every KernelHost server package (VPS/KVM, gameserver, dedicated). There is no extra charge, no separate protection package and no setup fee.
Does the DDoS protection add latency or ping?
No. Filtering happens in real time within milliseconds, with no packet loss and no increased ping. The server stays fully reachable even during an attack. This is especially critical for game and voice servers.
What is null-routing and does KernelHost use it?
Null-routing (blackholing) means that during an attack the entire IP is pulled off the network, which discards the legitimate traffic as well and takes the server offline. KernelHost uses no null-routing and no blackholing. Instead, only the malicious traffic is filtered out in real time, while the legitimate traffic keeps flowing uninterrupted.
My server is at another provider and under attack, can you help?
Yes. The recommendation is to migrate to KernelHost, where the 17 Tbps protection is included free in every package. The server then sits directly behind the Frankfurt real-time filtering and is protected permanently.
How fast is an attack mitigated?
Attacks are filtered within milliseconds. The protection is permanently active (always-on), so nothing has to be switched on manually first. The server does not go offline during mitigation. Real attacks of over 473 Gbit/s and over 41.5 million packets per second have been mitigated with zero downtime.
Which games and services are protected?
The protection is optimized for 40+ games and protocols, including Minecraft (Java 25565, Bedrock 19132), FiveM, alt:V, RageMP, SA-MP, CS2/CS:GO, Rust, ARK, Valheim, as well as voice services such as TeamSpeak (9987 UDP) and Mumble. Any custom TCP/UDP services on any port are protected too.
Which attack types does the protection cover?
The protection covers OSI layers 3 to 7: UDP and SYN floods, reflection and amplification attacks, HTTP floods, DNS and application-layer attacks, as well as game-specific crash methods such as Nullping, QuietException and fake-handshake floods.
Get started
- KernelHost DDoS protection in detail
- Rent a professional dedicated server (17 Tbps protection included)
- Open a support ticket or WhatsApp emergency chat: +43 650 8209883
Discount tip: Use the voucher code KernelHost-Tutorials to get 10% permanent discount on your order.
© KernelHost GmbH. This article is protected by copyright. Redistribution or publication, in whole or in part, is not permitted without express authorization.
