Setup & configuration

Voice chat behind DDoS protection: Simple Voice Chat and Plasmo Voice

Quele, Founder of BlackProtectUpdated 10 October 20266 min read
In short

Voice chat mods like Simple Voice Chat and Plasmo Voice connect straight to your server over their own UDP port. Without protection, every client gets your server's address.

At BlackProtect your server gets its own voice port for that. You enter it as voice_host, and your real address stays hidden.

Contents
  1. Why voice chat needs its own protection
  2. How it works at BlackProtect
  3. How to set it up
  4. The config for your setup
  5. Lock down the voice port
  6. Common problems
  7. Frequently asked questions

Why voice chat needs its own protection

Minecraft itself runs over TCP and goes through the filter at BlackProtect. Voice chat uses its own UDP port instead (24454 by default for Simple Voice Chat), and the client connects there directly, bypassing your domain.

  • IP leak: every player with the mod receives your voice server's address. Anyone who has it can attack your server directly, even though Minecraft is protected.
  • Attacks on the voice port hit your server unfiltered. If it goes down, it's usually more than just voice chat.

How it works at BlackProtect

  • Your server gets its own voice port at our Frankfurt location. Players don't enter it themselves; the mod gets it from your server automatically.
  • Only packets that look like Simple Voice Chat or Plasmo Voice get through, and every player has a limit on how many packets they may send. Other junk stays with us.
  • Your real address no longer shows up in any client.
To be honest

Voice chat content is encrypted, so we can't look inside it the way we do for Minecraft itself. We check the shape, volume and origin of the packets instead. Large attacks are absorbed by the upstream filter in Frankfurt.

Voice chat through the protection is included from the Starter plan, and in the 30-day trial.

How to set it up

  1. Open your route

    In the dashboard under Domains & routes, open your domain's settings and scroll to Voice chat.

  2. Enter your voice server

    Enter the address and UDP port of your voice chat. For a single server that's your server's address and usually port 24454. For Velocity, see below.

  3. Enable and copy the address

    Click Enable voice chat. You get an address like voice-fra.blackprotect.net:24017.

  4. Put it in the config

    The address goes into the voice chat config as voice_host (examples below). Leave the port there as it is.

  5. Restart and test

    Restart the server or Velocity. In game, press V: if the voice chat menu opens without a connection error and others can hear you, it works.

The config for your setup

Simple Voice Chat on one server (Paper, Fabric)

File plugins/voicechat/voicechat-server.properties (on Fabric config/voicechat/voicechat-server.properties):

properties
voice_host=voice-fra.blackprotect.net:24017

Simple Voice Chat with Velocity

Simple Voice Chat must be installed on Velocity and on every server behind it. Only the proxy exposes a UDP port, by default the same as Velocity's own (port=-1). So in the dashboard you enter your Velocity server's address and port, and on Velocity in plugins/voicechat/voicechat-proxy.properties:

properties
voice_host=voice-fra.blackprotect.net:24017
UDP at your host

Many hosts only open TCP for a port. Make sure your voice chat port lets UDP through as well, or not a single packet arrives.

Plasmo Voice

In Plasmo Voice's config.toml (with Velocity: the proxy's) under [host.public]. Plasmo Voice expects an IP here; the dashboard shows the right one in the Plasmo Voice tab:

toml
[host.public]
ip = "194.62.248.59"
port = 24017

Lock down the voice port

Once everything runs through us, nobody needs direct access to your voice port. On your own Linux server with ufw, allow only our filter servers (addresses are loaded live):

  • Frankfurt194.62.248.59
  • Nuremberg185.217.124.16
Terminal
# Allow SSH first, or you will lock yourself out!
# (If SSH runs on a different port, use that instead of 22.)
sudo ufw allow 22/tcp

# Voice chat only for the BlackProtect filter servers
sudo ufw allow from 194.62.248.59 to any port 24454 proto udp
sudo ufw allow from 185.217.124.16 to any port 24454 proto udp

# Remove an old rule that allowed everyone (if there is one)
sudo ufw delete allow 24454/udp

sudo ufw enable
sudo ufw status

If your voice chat runs on another port (with Velocity usually the Velocity port), replace 24454 with yours. More on firewalls: hide your server IP.

Common problems

  • "Voice chat not connected": usually your host doesn't let UDP through on that port, or the dashboard has the wrong port. Then check that voice_host was saved and the server restarted.
  • With Velocity nobody can hear each other: the plugin is missing on a server behind the proxy, or the dashboard has a backend's port instead of the Velocity port.
  • It worked and now it doesn't: if your voice server's address changed, enter the new one in the dashboard under Change voice server.
  • Bedrock players have no voice chat: Simple Voice Chat and Plasmo Voice only exist for Java Edition. That's the mods, not the protection.

Frequently asked questions

Does voice chat cost extra?

No, it's included from the Starter plan and already in the 30-day trial.

Do my players have to change anything?

No. The mod gets the voice chat address from your server automatically. Players join as always.

Is my real server address really gone afterwards?

Clients only see our address. Anyone who already knows the old one can still attack it, so afterwards allow your voice port only for our filter servers in your firewall.