Shield S
- 1× vCPU · Ryzen 9 9950X
- 1 GB DDR5 RAM
- 20 GB NVMe SSD
- Port 25 Gbps shared 5 TB fair use (outbound)
- Advanced DDoS protection
- 1× IPv4 address
- IPv6 /64 included
VPS / SHIELD
Shield is our always-on DDoS-protected VPS line. Layer 4 + Layer 7 mitigation across more than 3 Tbps of scrubbing capacity, backed by our own XDP filtering and tuned per workload by our team. No waiting, no reconnects, no excuses.
From €6,99/mo · Online in under 60 seconds · 14-day right of withdrawal
shield plans
The same always-on mitigation on every tier. You are picking CPU, RAM and disk, not a protection level.
Pricing in EUR · 20% Austrian VAT for AT consumers · Reverse charge for EU B2B
built for
gaming
FiveM, Minecraft, Rust, DayZ, SA:MP, Palworld, and 29+ protocol profiles in total. Per-game mitigation rules.
commerce
Cart sessions and checkout APIs survive volumetric and L7 attacks without breaking the user flow.
reach
News, forums, dashboards, controversial speech. Reverse-proxied challenge layer keeps bots out, real humans in.
infra
Authentication endpoints, webhooks, SaaS back-ends, protected at line rate without rewriting your stack.
visibility
Every protected IP gets its own page. Peak throughput, peak packets per second, attack type, source network, and which filter handled it, the moment it happens.
No ticket. No waiting on us to explain the outage. Something hits you tonight, the log is there in the morning with the numbers attached.
That is one of our own machines. We would rather show you a real panel than a mockup.
And that was a quiet night. In the past month the largest attack we absorbed peaked at 241 Gbps and 25 million packets per second, on — the top of a burst that stayed above 200 Gbps for 5 minutes. Same always-on path, no detection window to sit through. We have absorbed considerably larger attacks than this. 241 Gbps is the biggest in this window, not the biggest we have ever handled — our incident telemetry only reaches back to early 2026.
panel.1337hosting.com
| Time | Vector | Peak | Top source |
|---|---|---|---|
| 23:05 | TCP flood flowShield | 964 Mbps 149,094 pps | NL · hosting network |
| 21:50 | TCP flood flowShield | 2,186 Mbps 182,681 pps | DE · hosting network |
| 21:43 | TCP flood flowShield | 2,575 Mbps 213,902 pps | CN · national backbone |
One machine, 15 July 2026, all three absorbed by always-on filtering. Peak 2,575 Mbps and 213,902 packets per second. Historical figures from the panel above, not a live feed.
always on
Every packet to a Shield VPS crosses our scrubbing layer, 24/7, attack or no attack. No detection window. No failover shuffle. No blip while we re-route. A malicious flow arrives, it drops.
Standard VPS runs in reactive mode. Fine for back-office workloads. Wrong when five seconds of jitter is a refund or a rage-quit.
shield
0s
Time to mitigation, always-on, no detection window
standard
~5s
Reactive: detection + reroute window, brief reconnect possible
layer 4
∞
Volumetric & protocol attacks dropped at the edge
layer 7
✓
Per-application filters, UDP and TCP, tuned by us
layer 7
L4 protection alone leaks complexity into the application: slow loris, query floods, fake handshakes, malformed game packets. Shield parses traffic at the protocol layer and drops what doesn't belong.
game protocols
Pre-built filters for FiveM, Minecraft, Rust, DayZ, ARK, Source engine, SAMP, and more, both UDP and TCP. We maintain the signature list. New protocol? We add it.
reverse proxy
A fully-customizable challenge layer in front of your web app: JavaScript verification, CAPTCHA, JA3/JA4 fingerprinting, country rules. Similar shape to Cloudflare. Ours sits at our edge, and we configure it for your app.
supported protocols
Each profile understands the protocol it protects, not just IPs and ports. Don't see yours? We add new profiles on request, and tune any of these to your server. UDP and TCP both covered.
Some profiles have a page of their own, covering what the filter checks for that title and where it stops helping:
Full Cfx.re framework protection for GTA V and RDR2 roleplay servers, with optional strict deep-packet inspection.
Protocol-aware filtering for Java Edition servers and proxies (Velocity, BungeeCord, Paper).
RakNet handshake validation for Facepunch's Rust, bot joins and connection floods dropped at the edge.
Rust Console (DTLS)
UDPDTLS session validation for the console edition, with a stricter profile available for sustained pressure.
DayZ:SA / ArmA III
UDPKeeps Bohemia survival and mil-sim sessions clean of spoofed and malformed traffic.
Multi Theft Auto (MTA:SA)
UDPPacket validation for the long-running GTA: San Andreas multiplayer mod.
Filtering for classic SA:MP roleplay and freeroam servers and their query traffic.
alt:V Multiplayer
UDPCommunity GTA V multiplayer platform, validated at the protocol layer.
GTA V roleplay framework. Baseline anti-spoofing and connection-flood filtering while the handshake profile is still being tuned.
SCUM
UDPOpen-world survival sessions shielded from join floods and query abuse.
SCP: Secret Laboratory
UDPRound-based horror servers kept playable under sustained pressure.
7 Days to Die
UDPCo-op survival servers protected without touching your mod stack.
Conan Exiles
UDPPC and console survival sessions, protocol-validated.
Palworld
UDPDedicated Palworld servers filtered against connection floods.
Mordhau
UDPCompetitive medieval melee servers kept lag-free during attacks.
Battlefield 4
UDPPrivate and community BF4 servers shielded from volumetric abuse.
Call of Duty: Black Ops II (Plutonium)
UDPProtection for the community-run Plutonium server platform.
S.T.A.L.K.E.R.: Shadow of Chernobyl
UDPMultiplayer sessions in the Zone, validated against spoofed packets.
Enginefall
UDPMegatrain survival shooter servers, protocol-filtered.
Hytale (QUIC)
UDPQUIC-based transport profile for Hytale and other modern UDP game back-ends.
GameNetworkingSockets (Valve GNS)
UDPOne profile covering Valheim, V Rising, Satisfactory, Dead by Daylight, Unturned and other GNS-based titles.
Steam Query (A2S)
UDPValidates Steam server-browser (A2S) queries for any Steam-listed game, killing reflection abuse.
TeamSpeak 3
UDPVoice servers stay connected while the flood gets dropped.
WireGuard
UDPModern VPN endpoints protected without breaking the handshake.
OpenVPN
UDPRemote-access and site-to-site tunnels kept online under load.
QUIC / HTTP/3
UDPThe modern UDP transport behind HTTP/3 and next-gen game back-ends, validated at the edge.
DTLS
UDPGeneric Datagram TLS profile for secured UDP applications beyond the named titles above.
Anti-spoofing + rate-limiting
UDP/TCPUniversal source-validation that covers most applications out of the box, before any game-specific tuning.
Per-port lockdown
UDP/TCPDrops everything on ports you don't declare, so only your real services are ever reachable.
Profiles are maintained and updated continuously. "Experimental" marks a profile still being hardened, it works, we just keep refining it. Mitigation tuning for any title is included with every Shield plan.
coverage
The grid above names the titles we have written specific rules for: FiveM and RedM, Minecraft, Rust on PC and Console, DayZ:SA, ArmA III, Multi Theft Auto, San Andreas Multiplayer, alt:V, SCUM, SCP: Secret Laboratory, 7 Days to Die, Conan Exiles, Palworld, Mordhau, Battlefield 4, Black Ops II on Plutonium, S.T.A.L.K.E.R., Enginefall and Hytale. Voice and tunnels get their own profiles too, because TeamSpeak and WireGuard take hits about as often as the game does.
Most people arrive running something we have never heard of. That is fine. Two of our profiles are deliberately generic. One handles GameNetworkingSockets, which Valve built and much of the Source and Unity world now speaks. The other handles Steam Query, the A2S protocol behind almost every server browser. Between them they already cover titles that will never earn their own line in the grid: truck sims, survival co-op, racing servers, older Half-Life engine games. If it announces itself to a Steam server list, we have something to work with.
When the generic filters are too blunt, we write you a real profile. Send the protocol, a packet capture, or just the name of the game. Every entry above started as somebody asking. No fee, no minimum tier, no waiting on a vendor elsewhere to prioritise your title. Still standing the server up? Our setup guides cover Minecraft on PaperMC and TeamSpeak on Debian 13, both tested on this hardware.
support included
Every Shield plan includes hands-on mitigation support. Send the attack signature, the affected service, or just the IP being hit. We adjust the L7 rules, tighten the challenge layer, or write a custom XDP filter, usually within minutes. Your change never sits in a vendor queue behind someone else's support desk. Most providers charge extra for that. We don't.
faq
Yes. RedM and FiveM both run on the Cfx.re protocol and share a dedicated UDP profile on every Shield plan, with an optional strict deep-packet inspection mode for servers taking sustained pressure. It validates the framework's own handshake, so spoofed sessions and join floods are dropped at our edge before they reach your tickrate.
Usually, yes. Two of our filters are deliberately generic: GameNetworkingSockets, which Valve built, and Steam Query, the A2S protocol behind most server browsers. Between them they cover a wide slice of the Source, Unreal and Unity world. We can have never heard of your game and still recognise how it talks. Where the generic pass is too blunt, ask. We will write you a real profile, no fee and no minimum tier. The 29+ list grew exactly that way, one request at a time.
FiveM and RedM, Minecraft Java, Rust on PC and Console, DayZ:SA and ArmA III, Multi Theft Auto, San Andreas Multiplayer, alt:V, SCUM, SCP: Secret Laboratory, 7 Days to Die, Conan Exiles, Palworld, Mordhau, Battlefield 4, Call of Duty: Black Ops II on Plutonium, S.T.A.L.K.E.R., Enginefall and Hytale. TeamSpeak, WireGuard and OpenVPN have their own profiles too, since voice and tunnels get hit as often as the game itself.
Timing, mostly. A Standard VPS is reactive: an attack has to be detected before filtering engages. That is roughly a five second window where you can see packet loss or a reconnect. Shield keeps every packet crossing the scrubbing layer 24/7, so there is no detection gap to sit through. Shield also adds Layer 7, which reactive Layer 3/4 filtering cannot do at all.
Your traffic crosses the scrubbing layer whether or not anyone is attacking you, and that is the whole design. There is no switchover and no clean path versus attack path, so what you measure on a quiet Tuesday is what you get in the middle of an incident. Nothing changes shape when the traffic arrives.
More than 3 Tbps of scrubbing capacity, with our own XDP filtering in front of it. Volumetric and protocol attacks are dropped at the edge, well before they reach the node your VPS is running on.
Yes, and a fair number of customers do exactly that. The reverse proxy sits in front of your web app with a JavaScript challenge, optional CAPTCHA and JA3/JA4 bot fingerprinting. Rules are per route, so you can leave an API wide open while gating a login page. Checkout sessions ride out a Layer 7 flood and you rewrite nothing.
No. Protection attaches to your VPS IP address, so whatever is listening on that IP is covered from the moment the server boots. There is no separate hostname to point at and no SDK to install.
Included. Open a ticket with the attack signature, the affected service, or just the IP being hit. We adjust the Layer 7 rules, tighten the challenge layer, or write you a custom XDP filter. Most providers bill that as consulting. We do not, and your change never sits in a vendor queue behind someone else's support desk.
Yes, we do it regularly. Contact us with whatever logs you have and we will spec a tier and move you fast. Two things help: the target IP, and a rough idea of the traffic shape. With those we can pre-load the right profile before you cut over, so the protection is already waiting when your DNS moves.
Then mitigation can engage for the entire affected range, which means several customers at once. It is an honest limitation of shared network space and our terms name it as such. It is rare, it is externally caused, and we would rather you read it here than discover it during an incident.
All of them, equally. Every tier from Shield S to Shield Pro gets identical always-on mitigation, the full profile list and the same tuning support. Moving up a tier buys CPU, RAM and disk. It does not buy you a better class of filtering, and we are not going to sell protection back to you in slices.
> under_attack_now?
We onboard active mitigations during attacks. Reach out, bring whatever logs you have, we'll spec a tier and migrate fast.
Talk to us →