Frequently asked questions
Everything on routing, kernel-level mitigation, proxy compatibility and EU compliance – for Minecraft networks that take uptime seriously.
Routing & Telekom Performance
Telekom routing often sends game traffic over poorly-peered transit paths, causing lag and packet loss. Our edge node in Frankfurt peers directly with Tier-1 carriers (GTT, Zayo, Cogent), so Telekom players reach your Minecraft server over a short, optimised path – noticeably lower latency and fewer spikes.
You set a single CNAME record to the target the setup assistant shows for your domain. It routes traffic and proves domain ownership in one step. If an edge node fails or we rotate IPs, we update the target behind the CNAME – you never touch DNS again. No hard-coded A-record, no manual IP swaps, no downtime while records propagate.
Attack packets are dropped at the edge node in the kernel (XDP/eBPF) before they consume transit to your backend, and legitimate traffic takes the shortest peering path. The result is DDoS mitigation without the detour through distant scrubbing centres that most providers rely on.
eBPF/XDP Security & Bot Protection
Bot waves are intercepted and dropped directly at the NIC/kernel level with eBPF/XDP – before they reach the network stack or your backend. There is no user-space hop and no Java process to overwhelm. Protocol-aware filters detect invalid Minecraft handshakes and join-floods and drop them at near line-rate.
No – zero CPU overhead at the backend. All filtering happens at the edge node in the kernel. Your Paper/Velocity process only ever sees already-cleaned, legitimate traffic, no matter how large the L7 bot wave is.
Yes. We detect half-open connections, slow handshakes (Slowloris) and handshake-timeout attacks at L7 and cut them before they exhaust connection slots. Handshake state is held at the edge, not on your server, so your backend never stalls waiting on malicious clients.
Proxy & Server Compatibility
Yes. We forward the real client IP via HAProxy PROXY protocol v2 (PPv2) to Velocity, BungeeCord and Paper. Bans, player tracking and IP-based plugins keep working correctly – while your origin IP stays hidden behind the edge.
Yes. Bedrock runs over UDP, and we filter Geyser/Bedrock UDP traffic at the edge without session loss. Java and Bedrock players connect through the same protected endpoint, so crossplay stays seamless under attack.
Fully. Whether you run Paper, Velocity or BungeeCord, integration needs no plugin installed on your backend servers. Our edge anti-bot complements existing BungeeCord anti-bot plugins instead of colliding with them.
Compliance & Provider Comparison
Yes. Our filter servers are in Germany (Frankfurt and Nuremberg): your players' traffic is filtered there and never takes a detour through the US, unlike with Cloudflare Spectrum. We process data under the GDPR; for side services such as sending email, the privacy policy names every provider.
Cloudflare Spectrum meters mitigation bandwidth. We don't meter mitigation bandwidth at all, and dedicated edge nodes deliver protocol-aware Minecraft filtering that generic TCP proxies can't match. Every account starts free, with 30 days of Pro included.
A dedicated edge node is filter capacity assigned to you at the EU edge. Getting started is self-serve: create your account, connect your domain via CNAME, and protected traffic flows immediately – free, with 30 days of Pro included.
Still have a question?
Talk to the engineers who run the edge. Most questions are answered in minutes on Discord.
