IW IronWipe
Get a Server
Rust DDoS protection

Rust DDoS protection that's always absorbing.

Every server on IronWipe sits behind the same anycast network that shields us — up to 30Tbps of scrubbing capacity across 10 global points of presence, live from the moment your server boots.

30TbpsMitigation capacity
10Global PoPs
<1sDetection time
24/7Network monitoring
By the numbers

What the network actually absorbs

Illustrative figures for this template — wire up real telemetry to replace them.

Attack traffic vs. what reaches your server
24 hours, hover to inspect a point
Attack traffic (edge) Reaches your server
Points of presence
10 PoPs scrubbing traffic on the network
Frankfurt, DE Amsterdam, NL London, UK Paris, FR New York, US Dallas, US Los Angeles, US Miami, US Singapore, SG Tokyo, JP
How it's built

Four layers between an attacker and your server

None of this needs switching on — protection is active on every plan, all the time.

Anycast network

Traffic is pulled in at the nearest of 10 global points of presence and scrubbed there — an attack in one region never has to cross the ocean to reach your server.

30Tbps mitigation

Combined scrubbing capacity across the network absorbs the largest volumetric floods without the traffic ever touching your box.

GSL volumetric filtering

Our GSL filtering layer inspects every packet at wire speed, dropping floods and malformed traffic before they ever reach your server's connection.

Always-on

Protection is live from the moment a server is provisioned — no manual toggle, no delay while an attack is already underway.

What happens during an attack

Detect, scrub, deliver

1

Detect

Traffic is fingerprinted in real time across every PoP. Anomalies trigger mitigation in under a second — no human has to notice first.

2

Scrub

GSL volumetric filtering and Layer 7 behavioral rules strip malicious packets at the edge, closest to where the attack originates.

3

Deliver

Only clean traffic continues on to your server over the anycast network — players stay connected, the attack goes nowhere.

Filter library

Purpose-built filters, not one generic rule

Every filter runs at the edge before traffic ever reaches your box. This list covers the vectors that actually hit Rust servers.

SYN Flood Protection

TCP

Validates the handshake with SYN cookies and drops malformed or incomplete connection attempts before they reach your server's stack.

UDP Amplification Guard

UDP

Detects and blocks DNS, NTP, SSDP and Memcached amplification vectors at the edge — none of it ever reaches your connection.

ICMP Flood Mitigation

ICMP

Rate-limits echo requests and blocks oversized ping packets, stopping Smurf-style floods and reconnaissance probes.

TCP State Validation

TCP

Stateful connection tracking drops ACK floods, RST floods and any packet that doesn't belong to a real, completed handshake.

Adaptive Rate Limiter

Any

Per-source rate limiting against a rolling traffic baseline, so thresholds tighten automatically the moment behaviour looks abnormal.

IP Fragment Filter

IP

Drops abusive fragmented packets at line rate, closing off fragmentation-based DoS vectors before reassembly ever happens.

A2S Query Caching

UDP

Caches Steam A2S server-info responses at the edge, so a flood of fake browser queries never has to touch your Rust process.

Source Engine Handshake Guard

UDP

Validates the connection handshake Rust inherits from Source before allowing a session through, blocking bot-driven join floods.

RCON Brute-Force Guard

TCP

Rate-limits and challenges repeated RCON auth attempts, so your admin console can't be used as a flood or brute-force vector.

Coverage

10 points of presence, one network

Every PoP scrubs locally, so protection stays close to your players no matter where they connect from.

Frankfurt, DE Amsterdam, NL London, UK Paris, FR New York, US Dallas, US Los Angeles, US Miami, US Singapore, SG Tokyo, JP
FAQ

Questions we get a lot

Included on every plan — panel hosting, VDS and baremetal alike. There's no tier where it's optional.

It's the filtering layer that inspects traffic at wire speed and drops volumetric floods and malformed packets before they reach your server, without adding meaningful latency to legitimate players.

No — players are routed to the nearest PoP automatically, which usually means a shorter path than connecting straight to the origin.

Attacks that size are effectively unheard of against a single Rust server. Mitigation capacity is shared and scaled across all 10 PoPs, not a single point that can be saturated.

Every server ships protected

Pick a hosting tier — Panel Hosting, VDS or baremetal — the network underneath is the same either way. See the full Rust server hosting lineup.