Our always-on DDoS protection is built in two layers: a global scrubbing network with 17 Tbps mitigation capacity absorbs volumetric attacks close to their source, while 3.2 Tbps Arbor real-time filtering handles the fine-grained work on-premise in Frankfurt. Automated, permanently active and included with all servers at no extra cost. Your infrastructure stays online even during an attack.
Attacks are detected and filtered within a few milliseconds. No null-routing, your server stays continuously reachable.
Continuous protection runs permanently in the background, no configuration required. All attack patterns are detected automatically and filtered 24/7.
Botnet, flood (ICMP, DNS amplification, TCP/UDP), SYN, fragmentation and HTTP/S flood attacks: every attack pattern is detected and filtered instantly.
Precisely tuned for Minecraft, FiveM, CS:GO, Rust, Arma, Valheim, Teamspeak and more, with minimal latency so your players stay connected.
Enabled on every KernelHost server package at no extra cost. No separate protection tiers, no hidden fees, simply included.
Under attack at your current provider? Contact us for a fast migration, we'll pull you out of the fire.
The second protection layer right in front of your server: no matter how many or which attack patterns hit, Arbor DDoS protection filters them all out.
The protection is developed and adapted daily to detect new attack patterns. It runs continuously and automatically on all root servers, game servers, and web servers.
Advanced DDoS protection with 17 Tbps technology for heavily attacked game servers and demanding projects: a dedicated protected IP from our Frankfurt core, with self-managed protection and firewall rules in the client area.
Order Advanced DDoS Protection and instantly receive your dedicated protected IP address from our low-latency Frankfurt core.
We switch your server to the dedicated protected IP directly inside our own network. No changes needed on your side, protection is active immediately.
Pick a protection profile in the client area, rules apply in real time. Attacks are absorbed in the global scrubbing network close to their source.
Reach us via ticket or WhatsApp emergency chat at +43 650 8209883. We'll help immediately.
For special cases and heavily attacked projects: our Advanced DDoS Protection with 17 Tbps technology and self-managed protection rules in the client area is ready within minutes.
DDoS (Distributed Denial of Service) protection is a security system that detects and filters malicious traffic before it reaches your server. It analyses incoming data packets in real time and blocks attack traffic while allowing legitimate users to connect normally. Without DDoS protection, a targeted attack can overwhelm your server's network connection and take it offline.
KernelHost uses Arbor DDoS permanent protection, which is always active, not just triggered when an attack is detected. All traffic passes through the Arbor scrubbing infrastructure 24/7, where attack patterns across Layer 3 to Layer 7 are identified and filtered within milliseconds. This ensures zero reaction delay and no disruption to normal server operation.
No. KernelHost does not null-route IP addresses during DDoS attacks. Null-routing means blocking all traffic to your IP, which effectively takes your server offline. Instead, our Arbor permanent protection filters out attack traffic while keeping your server online and accessible throughout the attack.
Arbor DDoS filtering adds no latency to your traffic. The filtering is performed at hardware level directly within the network infrastructure, with no measurable impact on ping times. Ideal for gaming applications where every millisecond counts.
Yes. The Arbor DDoS protection at KernelHost filters all attack patterns from Layer 3 through Layer 7 in real time. Layer 7 (application-layer) attacks such as HTTP floods, DNS query floods, and SIP invite floods are identified and blocked within milliseconds without disrupting legitimate traffic.
Yes. KernelHost's Arbor permanent protection includes dedicated gameserver mitigation logic for UDP-based game protocols used by Minecraft, FiveM, CS:GO, Ark, Rust, Valheim and others. Attack packets are filtered while legitimate player traffic passes through unaffected. Voice servers such as TeamSpeak are fully covered as well.
Because KernelHost operates a permanent (always-on) protection, there is no detection delay. All traffic is continuously routed through the Arbor scrubbing infrastructure 24/7. Attack packets are identified and removed within milliseconds, with zero downtime for your server.
Yes. With Advanced DDoS Protection you manage your protection rules yourself in the client area: you choose protection profiles for your game or application per port and protocol, and changes apply in real time. This lets you adapt the mitigation to your project without a ticket, while attack traffic is absorbed in the 17 Tbps scrubbing network before it ever reaches your server.
Your protected IP address is assigned automatically right after ordering. Once your server is connected, you pick a protection profile for your game or application in the client area, with optimized profiles for 40+ games such as Minecraft, FiveM, Rust or Counter-Strike. Rule changes apply in real time.
In practice, KernelHost's 17 Tbps DDoS protection has filtered, among others, a complex multi-vector attack of over 473.4 Gbps and over 41.5 million packets per second against a TeamSpeak server (port 9987 UDP), and a UDP flood of over 112.2 Gbps against an ARK gameserver, each in real time with zero downtime and no packet loss. All-port attacks across every port (0 to 65535) are reliably mitigated as well.
The 17 Tbps always-on DDoS protection is included at no extra charge with every KernelHost server, from KVM VPS starting at 4.99 euro per month through gameservers to dedicated servers. There is no separate protection package and no hidden fees. For particularly heavily attacked projects, Advanced DDoS Protection is additionally available with a dedicated protected IP and self-managed rules from 50 euro per month, PrePaid and with no minimum term.
Yes. The DDoS protection is specifically optimized for gameservers and includes ready-made mitigation profiles for 40+ games and protocols, including Minecraft (Java port 25565, Bedrock 19132), FiveM, alt:V, RageMP, Rust, ARK, CS2 and Valheim, as well as voice servers such as TeamSpeak and Mumble. Game-specific attacks such as Nullping or fake-handshake floods are filtered in real time without affecting legitimate player traffic.