Anti-DDoS Protection
Integrated multi-layer L3/L4/L7 filtering included with every MatHost service. Designed for game server infrastructure, eliminating lag during attacks.
Multi-Layer Defense System
Two independent layers - volumetric scrubbing upstream and in-kernel application filtering - protect every service by default.
Volumetric Filtering
PletX is our first line of defense. It guarantees absorption of attacks exceeding terabits of traffic (NTP/DNS Amplification, UDP Floods, TCP SYN Floods), operating at the network edge and BGP level.
MatShield L7
Dedicated L7 hardware filters deeply analyze individual application packets. By knowing the data structure of hundreds of popular games, we mitigate application-specific DDoS attacks (crash exploits) that standard filters have no awareness of.
Why us?
We built this environment over years based on experience with the most attacked servers in Poland.
Terabit-scale capacity
PletX infrastructure analyzes and filters massive volumes of L3/L4 traffic, protecting the upstream pipe from saturation by volumetric DDoS attacks.
Custom game rules
L7/A2S protection. We support advanced filters mitigating attacks based on the Source engine, GTA V (FiveM), Minecraft (RakNet/TCP) and many others.
No false alarms
Stateful Firewall checks connections and validates TCP handshakes, guaranteeing access for players while dropping spoofed and malformed packets.
Short routes
Low latency and zero packet loss thanks to the scrubbing center located at the edge of our own network (AS214762).
Hardware Scrubbing
Traffic is filtered using dedicated hardware and smart NICs, offloading the CPU on the end machine itself.
Always active
Always-On filters. You do not need to worry about attack detection time - protection catches and cleans it before bandwidth starts rising.
Our network and filtering
Traffic enters our AS214762 through ports at the Warsaw exchange points, and MatShield tracks every connection in-kernel with XDP/eBPF. Volumetric floods at Tbps scale are absorbed earlier by our PletX upstream (AS62403), before they ever reach our edge.
MatShield
Hardware infrastructure based on XDP/eBPF, operating in inline architecture. Catches attacks without millisecond delay and immediately drops malicious traffic at the Linux kernel plugin level.
- Multi-Tbps
- DDoS Filtering
- AS214762
- BGP Network
Low latency and zero packet loss
- Symmetric filtering for the lowest false-positive rate
- Automatic Port Learning - no manual configuration
- Permanent Mitigation System with no player timeouts
- Custom filters delivered at no extra cost
Internet Exchange Points
Our own ports at the Warsaw exchange points keep the path to Polish networks short and let us drop attack traffic right at the edge. Below we separate the ports we actually own from the networks reached through upstreams.
- 100G
- 1-PL FREE
- 100G
- 1-IX EU
- 2G
- THINX Warsaw
Warsaw
Warsaw
Warsaw
Reached via upstreams: Equinix Warsaw (via THINX + 1-IX), Orange Polska (via Atman), TPIX (via ZET.net). We reach these through our transit providers rather than from a port of our own, which is why no capacity is claimed for them.
Supported Applications
Our own MatShield L7 filters can recognize and mitigate application-layer (L7) attacks for dozens of the most popular game engines.
Protection in every service
We do not charge extra for our protection network. Every VPS server, Dedicated server, Tunnel, or Colocation service is covered by automatic filtering from the moment it is launched.