Every server on IronWipe sits behind the same anycast network that shields us — up to 30Tbps of scrubbing capacity across 10 global points of presence, live from the moment your server boots.
Illustrative figures for this template — wire up real telemetry to replace them.
None of this needs switching on — protection is active on every plan, all the time.
Traffic is pulled in at the nearest of 10 global points of presence and scrubbed there — an attack in one region never has to cross the ocean to reach your server.
Combined scrubbing capacity across the network absorbs the largest volumetric floods without the traffic ever touching your box.
Our GSL filtering layer inspects every packet at wire speed, dropping floods and malformed traffic before they ever reach your server's connection.
Protection is live from the moment a server is provisioned — no manual toggle, no delay while an attack is already underway.
Traffic is fingerprinted in real time across every PoP. Anomalies trigger mitigation in under a second — no human has to notice first.
GSL volumetric filtering and Layer 7 behavioral rules strip malicious packets at the edge, closest to where the attack originates.
Only clean traffic continues on to your server over the anycast network — players stay connected, the attack goes nowhere.
Every filter runs at the edge before traffic ever reaches your box. This list covers the vectors that actually hit Rust servers.
Validates the handshake with SYN cookies and drops malformed or incomplete connection attempts before they reach your server's stack.
Detects and blocks DNS, NTP, SSDP and Memcached amplification vectors at the edge — none of it ever reaches your connection.
Rate-limits echo requests and blocks oversized ping packets, stopping Smurf-style floods and reconnaissance probes.
Stateful connection tracking drops ACK floods, RST floods and any packet that doesn't belong to a real, completed handshake.
Per-source rate limiting against a rolling traffic baseline, so thresholds tighten automatically the moment behaviour looks abnormal.
Drops abusive fragmented packets at line rate, closing off fragmentation-based DoS vectors before reassembly ever happens.
Caches Steam A2S server-info responses at the edge, so a flood of fake browser queries never has to touch your Rust process.
Validates the connection handshake Rust inherits from Source before allowing a session through, blocking bot-driven join floods.
Rate-limits and challenges repeated RCON auth attempts, so your admin console can't be used as a flood or brute-force vector.
Every PoP scrubs locally, so protection stays close to your players no matter where they connect from.
Included on every plan — panel hosting, VDS and baremetal alike. There's no tier where it's optional.
It's the filtering layer that inspects traffic at wire speed and drops volumetric floods and malformed packets before they reach your server, without adding meaningful latency to legitimate players.
No — players are routed to the nearest PoP automatically, which usually means a shorter path than connecting straight to the origin.
Attacks that size are effectively unheard of against a single Rust server. Mitigation capacity is shared and scaled across all 10 PoPs, not a single point that can be saturated.
Pick a hosting tier — Panel Hosting, VDS or baremetal — the network underneath is the same either way. See the full Rust server hosting lineup.