Enterprise Platform · Inline L2 Scrubbing

eBPF/XDP inline scrubbing at the edge of your network

BlackProtect runs as a transparent L2 bridge in front of your infrastructure. Attack traffic is dropped in kernel space before it ever touches your hosts — no reverse proxy, no re-architecture, no added latency.

Line-rateXDP packet processing
TransparentL2 bridge · no IP changes
Multi-VRFPer-customer isolation
Architecture

How traffic flows through the filter

Switch between the shared Business topology and the fully isolated Enterprise Multi-VRF setup to see how clean traffic reaches your hosts.

IngressAttack trafficBlackProtectXDP L2 Bridge · Mixed UplinkYour HostClean Traffic
Attack traffic (dropped)Clean traffic (forwarded)

Shared filter node · single tagged uplink carries clean traffic back to your server.

Platform

Built for operators who run their own metal

Transparent L2 bridge

Inserted inline on your uplink. Your hosts keep their IPs — no NAT, no proxy hop, no application changes.

Kernel-space mitigation

XDP/eBPF programs drop malicious packets at the NIC driver level, before they consume CPU or reach userspace.

Multi-VRF / VLAN isolation

Each customer or backend lives in its own routing domain on a dedicated tagged VLAN — no cross-tenant leakage.

Protocol-aware filtering

Deep understanding of Minecraft, UDP and TCP handshakes to separate real players from volumetric and L7 floods.

Deterministic latency

Filtering adds no measurable round-trip time. Legitimate traffic is forwarded at line rate.

Contractual SLA & 24/7

On-call engineering, defined mitigation SLAs and direct access to the team that built the stack.

Deployment

Fits your network, not the other way around

Deployment
Inline L2 bridge on your uplink
Data path
XDP / eBPF in kernel space
Isolation
Multi-VRF, per-VLAN routing
Latency added
0 ms (line-rate forwarding)
Protocols
Minecraft, UDP, TCP, generic L4
Provisioning
API-driven routes & backends

Let's design your mitigation architecture

Tell us about your network and traffic profile — we'll map out a filter deployment that fits.