What GlitchGuard Is
GlitchGuard is a filtering layer that sits in front of your server's IP address. Every packet heading to your server passes through it first. Packets that match a rule you have allowed are inspected and passed on. Everything else is dropped before it reaches your server.
It does three things at once:
- Blocks floods. Large volumes of junk traffic are dropped at our edge, so your server's network connection and CPU are not consumed by them.
- Understands game and application protocols. For supported protocols it checks that each packet is actually what it claims to be (a real Steam query, a real RakNet handshake, a real WireGuard packet) and drops anything that is not.
- Acts as a firewall. Only the ports and protocols you list are open. Anything you have not listed is closed at the edge, so unused ports cannot be attacked or probed.
What it does not do: it does not filter traffic leaving your server, it does not inspect the content of your website or game data, and it does not protect ports you have not added to your rules.
Getting GlitchGuard Enabled
GlitchGuard is an opt-in add-on. If your service does not have it yet, you will see a GlitchGuard panel at the top of your service page in the client area with an Open a ticket link. Open the ticket, tell us which service you want protected, and we will enable it. Once enabled, the panel on that service page becomes the full control panel described below.
When protection is first enabled on a service we apply a starting configuration: a general preset with Ping, SSH, Remote Desktop, HTTP and HTTPS allowed. From there you choose the preset that matches what you actually run.
Protection applies to the IPv4 address shown on your service. If your service has more than one address, protection covers the primary one shown in the panel.
The Panel, Part by Part
Open your service in the client area. The GlitchGuard DDoS Protection panel is at the top of the page.
Status line
"Active on your IP, current profile: ..." tells you protection is live, which IP it covers, and which preset is applied.
Under-attack mode
A bordered block with two rows.
Manual: a status badge (Off, or ON until a time) and a button. Turning it on applies tighter limits to your server only: fewer new connections per second and lower flood thresholds. Use it while you are actively being hit. It turns itself off after 6 hours, or you can turn it off early. Nobody else's server is affected by your under-attack mode.
Automatic: a status badge and a button. When on, GlitchGuard watches your traffic and switches under-attack mode on by itself the moment an attack on your IP is detected, then switches it off 30 minutes after the attack ends. It is on by default. Turn it off only if you have a specific reason, for example a very busy server where you would rather control the tighter limits yourself.
When under-attack mode is on, legitimate players may find it slightly harder to join during the first seconds of a very busy period, because new connection rates are capped. Established players are not affected.
Preset
A dropdown of games and applications, grouped into Game servers, Voice servers and Other. Under it is a short description of what the preset opens. The Load preset rules button replaces the rows in your rules table that are marked "preset" with the standard ports and filters for that game, and keeps any rows you added yourself.
The preset also sets the flood thresholds for your server behind the scenes (how many packets per second of each type are allowed), tuned to what that game normally generates with a full server. You do not see or edit those numbers; the preset handles them.
Loading a preset does not save anything until you click Save. Review the rules table first.
Rules table
The heart of the panel. Each row is one thing you are allowing through. Columns:
- Protocol: TCP, UDP, Ping (ICMP), IPsec ESP or GRE.
- Port(s): a single port or a range. Ping, ESP and GRE have no port.
- Filter: how traffic on that row is treated. See which ports and filters your server needs.
- From: where the row came from. "preset" means the preset put it there. "http", "ssh" and similar mean an Add service toggle put it there. "custom" means you added it manually.
- The red cross removes the row.
Anything not listed in this table is dropped before it reaches your server.
Add a rule
The row under the table lets you add your own: pick the protocol, type a port or a range (for example 27015 or 27015-27020), pick a filter, click Add. The row appears in the table marked "custom". Use this for non-standard ports, extra game instances, panel ports, or anything the preset does not cover.
Add service
A picker of common services: Ping, SSH, Remote Desktop, HTTP, HTTPS, MySQL, WireGuard VPN, OpenVPN, IPsec. Picking one adds the correct rows for it with the right filter already chosen. This is the easy way to open the standard ports for things that are not games.
Discord webhook
Paste a Discord webhook URL and GlitchGuard will post to that channel when an attack on your server starts, when it ends, and when under-attack mode switches on or off. Leave it blank if you do not want alerts. The URL must start with https://discord.com/api/webhooks/.
To get one in Discord: Server Settings, Integrations, Webhooks, New Webhook, Copy Webhook URL.
Save
Writes your rules, preset and webhook to the protection system. The change is live within a few seconds. There is a minimum interval of 5 minutes between saves to prevent accidental rapid changes.
Traffic graph
Allowed and blocked traffic for the last hour, 6 hours or 24 hours. The blocked line is what GlitchGuard dropped on its way to you. A spike on the blocked line with a flat allowed line is an attack being absorbed. Under the graph, the breakdown shows what kind of traffic was blocked: SYN floods, UDP floods, amplification, invalid game packets, query floods, and "cached" (Steam queries we answered for you without bothering your server).
Attack history
The last attacks detected on your IP: when they started and ended, peak rate, how many packets were dropped, and the dominant type.
Step-by-Step Setup
- Open your service in the client area. The GlitchGuard panel is at the top.
- In Preset, choose the game or application you run. Read the description underneath to confirm the ports match yours.
- Click Load preset rules. The table fills with that game's standard ports.
- Check the ports. If your server runs on a non-standard port (for example Rust on
28025instead of28015), remove the preset row and add your own with the same filter, or add the extra port as a custom row. - Under Add service, turn on anything else your server needs: SSH if you log in to a Linux server, Remote Desktop for Windows, HTTP and HTTPS if it serves a website or web panel, WireGuard or OpenVPN if it is a VPN endpoint. Leave Ping on unless you have a reason to hide the server from pings.
- Optional: paste a Discord webhook.
- Click Save. Wait a few seconds, then test: connect to your game, load your website, SSH in. If something does not respond, see the troubleshooting guide.
- Leave Automatic under-attack mode on.
Frequently Asked Questions
Next Steps
Next, work out exactly which rows your server needs in Which Ports and Filters Your Server Needs. If a term in the panel is unfamiliar, the GlitchGuard glossary explains every one. If something is not working, go straight to Troubleshooting.
Not protected yet?
GlitchGuard is available as an add-on on VPS and dedicated servers. Open a ticket from your service page and we will switch it on, then come back to this guide.