eBPF/XDP inline scrubbing at the edge of your network
BlackProtect runs as a transparent L2 bridge in front of your infrastructure. Attack traffic is dropped in kernel space before it ever touches your hosts — no reverse proxy, no re-architecture, no added latency.
How traffic flows through the filter
Switch between the shared Business topology and the fully isolated Enterprise Multi-VRF setup to see how clean traffic reaches your hosts.
Shared filter node · single tagged uplink carries clean traffic back to your server.
Built for operators who run their own metal
Transparent L2 bridge
Inserted inline on your uplink. Your hosts keep their IPs — no NAT, no proxy hop, no application changes.
Kernel-space mitigation
XDP/eBPF programs drop malicious packets at the NIC driver level, before they consume CPU or reach userspace.
Multi-VRF / VLAN isolation
Each customer or backend lives in its own routing domain on a dedicated tagged VLAN — no cross-tenant leakage.
Protocol-aware filtering
Deep understanding of Minecraft, UDP and TCP handshakes to separate real players from volumetric and L7 floods.
Deterministic latency
Filtering adds no measurable round-trip time. Legitimate traffic is forwarded at line rate.
Contractual SLA & 24/7
On-call engineering, defined mitigation SLAs and direct access to the team that built the stack.
Fits your network, not the other way around
- Deployment
- Inline L2 bridge on your uplink
- Data path
- XDP / eBPF in kernel space
- Isolation
- Multi-VRF, per-VLAN routing
- Latency added
- 0 ms (line-rate forwarding)
- Protocols
- Minecraft, UDP, TCP, generic L4
- Provisioning
- API-driven routes & backends
Let's design your mitigation architecture
Tell us about your network and traffic profile — we'll map out a filter deployment that fits.
