Behind protection, every player connects through its filter servers. Without PROXY protocol your server sees the same IP for everyone, and an IP ban hits everyone.
You enable it in two places: in your front-most server (Velocity, BungeeCord or Paper) and at BlackProtect in your route settings. Both sides have to match.
Contents
The problem
As soon as your server sits behind BlackProtect, every connection comes from our filter servers. Without anything else, your server sees one of our addresses for every player. That causes trouble:
- An IP ban bans every player at once.
- Plugins that limit accounts per IP only let one player in.
- Logs and anti-cheat show wrong countries and addresses.
PROXY protocol solves this: our filter sends the player's real IP at the very start of every connection, and your server reads it. No plugin needed.
Where to enable it
Only in the front-most server, the one our filter connects to:
- Network with Velocity or BungeeCord: in the proxy. The servers behind it get the real IP as usual through the proxy's forwarding; change nothing there.
- Single server without a proxy: directly in Paper.
If PROXY protocol is only on at one side, nobody can join. So change the setting in your server first, restart it and enable it at BlackProtect right after. Only a few seconds lie in between.
Velocity
In velocity.toml, in the [advanced] section:
[advanced]
haproxy-protocol = trueThen restart Velocity. A reload is not enough for this setting.
BungeeCord and Waterfall
In config.yml, on the listener (keep the other lines as they are):
listeners:
- host: 0.0.0.0:25577
proxy_protocol: trueThen restart the proxy.
Paper (single server)
In config/paper-global.yml, in the proxies section:
proxies:
proxy-protocol: trueThen restart the server. Spigot can't do this on its own: switch to Paper (runs the same plugins) or put Velocity in front. For Fabric and Forge there are mods that add PROXY protocol.
Enabling it at BlackProtect
- Open your route
In the dashboard under Domains & Routes, open your domain's settings.
- Enable Proxy Protocol v2
Under Proxy Protocol v2, click Enable PPv2…, confirm that your server is configured for it, and enable.
- Test
Join yourself and look at the Velocity or Paper console. It should now show your real IP, not one of our addresses.
With PROXY protocol your server trusts whatever comes first in the connection. If someone could connect to your server directly, they could fake an IP. So only let our filter servers reach the port: Firewall setup.
If it doesn't work
- Nobody can join, the connection drops instantly: BlackProtect sends PROXY protocol but your server doesn't expect it. Check the setting and whether the server was really restarted.
- Players hang at “Connecting to the server” and time out: your server expects PROXY protocol but it is off at BlackProtect.
- You can't join directly via the IP any more: that's correct. Always join via your domain.
Frequently asked questions
Do I need a plugin like with TCPShield?
No. Velocity, BungeeCord and Paper support PROXY protocol out of the box. No plugin required.
How is this different from Velocity forwarding?
Velocity forwarding passes the IP from the proxy to the servers behind it. PROXY protocol passes it from the protection to your proxy. Both work together, each in its own place.
Does this apply to Bedrock players too?
Bedrock uses its own path with its own setting. How that works: Geyser and Bedrock behind DDoS protection.
