Networking Basics
- Port
- A number from 1 to 65535 that identifies which program on a server a packet is for. A web server listens on 80 and 443, Minecraft on 25565, and so on. Think of the IP address as the building and the port as the flat number.
- Protocol
- The kind of packet. The two you will deal with are TCP and UDP.
- TCP
- Connection-based. The two ends perform a handshake before any data flows, and every packet is acknowledged. Used by websites, SSH, Remote Desktop, Minecraft Java, RCON, file transfers and most things that are not real-time games.
- UDP
- Connectionless. Packets are fired off with no handshake and no acknowledgement. Used by almost every real-time game, voice chat and VPN because it is fast. Also the protocol attackers prefer, because there is no handshake to prove the sender is real, which is why UDP rows carry the most filter choices.
- Ping (ICMP)
- The protocol behind the
pingcommand and uptime monitors. Allowing it lets people check your server is up. Turning it off hides the server from pings but does not affect anything else. - IPsec ESP and GRE
- Tunnelling protocols used by some VPNs. Only needed if you run an IPsec VPN or a GRE tunnel on the server.
- pps and Mbps
- Packets per second and megabits per second. The graph shows both because attacks come in two shapes: many small packets (high pps, low Mbps) that exhaust CPU, and large packets (high Mbps) that fill the connection. GlitchGuard handles both.
Filters
- SYN proxy
- The filter applied to every TCP port. When a client tries to connect, GlitchGuard completes the TCP handshake on your server's behalf first. Only once the client has proven it is real (by finishing the handshake) is the connection handed to your server. Fake connection attempts never reach you. Invisible to real users.
- Rate limited
- The default UDP filter. Traffic passes, but if the packet rate to your server exceeds what the preset considers normal for that game, the excess is dropped. Safe for any UDP service.
- Steam query (A2S)
- The protocol the Steam server browser uses to ask a server for its name, map, player count and rules. Query floods are a common way to knock game servers over because each query makes the server do work.
- Steam query only
- For a port that carries nothing but Steam queries. Every packet is checked against the real query format; anything else is dropped.
- Steam query + game
- For Source engine servers where game traffic and queries share one port. Queries are validated, game traffic is passed, everything else is dropped.
- Query cache
- For ports with a Steam query filter, GlitchGuard keeps a fresh copy of your server's own answer to the basic server-info query and replies to that query itself, directly at our edge. During a query flood your server never sees the queries, but your server list entry stays up and players see correct information. Shows as "cached" in the traffic breakdown.
- RakNet
- The networking library used by Rust, Minecraft Bedrock and others. The RakNet filter checks that connection handshakes have the correct RakNet structure and that game packets are well formed, and drops the rest.
- SA-MP query + game
- Validates SA-MP and open.mp query packets on the game port and passes the game traffic.
- WireGuard only / OpenVPN only
- Each VPN protocol has a rigid packet structure. These filters check message types and sizes and drop anything that is not a genuine packet of that protocol, so a flood at your VPN port never reaches the VPN software.
Panel Terms
- Preset
- A ready-made set of ports, filters and flood thresholds for a specific game or application. Loading one fills the rules table; it is not saved until you click Save.
- Rules table
- The list of everything you are allowing through to your server. Anything not in the table is dropped at the edge.
- Under-attack mode
- A temporary tighter setting for your server only. Manual mode lasts 6 hours or until you turn it off. Automatic mode switches it on when an attack is detected and off 30 minutes after the attack ends.
- Webhook
- A URL Discord gives you for a channel. Anything posted to the URL appears in that channel. In Discord: Server Settings, Integrations, Webhooks, New Webhook, Copy Webhook URL.
- Allowed / Blocked
- Allowed is traffic that passed all filters and reached your server. Blocked is traffic GlitchGuard dropped.
- Attack history
- The list of attacks detected on your IP, with start and end times, peak rate, packets dropped and the dominant attack type.
Frequently Asked Questions
Rate limited passes everything on the port until the packet rate goes above what is normal for your game, then drops the excess. A protocol filter checks every packet against the real structure of that protocol and drops anything that does not match, whatever the rate. Protocol filters are stricter, but only work when the port really carries that protocol.
TCP has a handshake, so GlitchGuard can prove a client is real before passing it on, and one filter (SYN proxy) covers every TCP service. UDP has no handshake, so the only way to tell a real packet from a fake one is to check its structure against the protocol it should be speaking. That is what the UDP filters do.
Steam server-browser queries that GlitchGuard answered itself from a stored copy of your server's reply. Your server never saw them, but the players who sent them got a correct answer.
No. The handshake completes slightly differently on the wire, but clients and servers see a normal connection.
Next Steps
With the terms clear, the ports and filters guide shows which filter belongs on each port, and the setup guide walks through the panel itself.
Not protected yet?
GlitchGuard is available as an add-on on VPS and dedicated servers. Open a ticket from your service page and we will switch it on, then come back to this guide.