Shield S
- · 1× vCPU · Ryzen 9 9950X
- · 1 GB DDR5 RAM
- · 20 GB NVMe SSD
- · 25 Gbps Shared ? 2 TB Fair-Use
- · Advanced DDoS Protection
- · 1× IPv4 Address
// VPS / SHIELD
Shield is our always-on DDoS-protected VPS line. Layer 4 + Layer 7 mitigation, tuned per workload by our team — no waiting, no reconnects, no excuses.
// built_for
// gaming
FiveM, Minecraft, Rust, DayZ, SA:MP, Palworld, and 28+ protocol profiles in total. Per-game mitigation rules.
// commerce
Cart sessions and checkout APIs survive volumetric and L7 attacks without breaking the user flow.
// reach
News, forums, dashboards, controversial speech. Reverse-proxied challenge layer keeps bots out, real humans in.
// infra
Authentication endpoints, webhooks, SaaS back-ends — protected at line rate without rewriting your stack.
// always_on
Traffic to a Shield VPS crosses our scrubbing layer 24/7 — every packet, every connection, regardless of whether anyone is currently throwing one at you. There's no detection window, no failover shuffle, no brief blip while we re-route. The moment a malicious flow hits, it gets dropped.
Standard VPS runs in reactive mode — fine for back-office workloads, wrong for anything where five seconds of jitter is a refund or a rage-quit.
// shield
0s
Time to mitigation — always-on, no detection window
// standard
~5s
Reactive: detection + reroute window, brief reconnect possible
// layer 4
∞
Volumetric & protocol attacks dropped at the edge
// layer 7
✓
Per-application filters, UDP and TCP, tuned by us
// layer_7
L4 protection alone leaks complexity into the application — slow loris, query floods, fake handshakes, malformed game packets. Shield parses traffic at the protocol layer and drops what doesn't belong.
// game_protocols
Pre-built filters for FiveM, Minecraft, Rust, DayZ, ARK, Source engine, SAMP, and more — both UDP and TCP. We maintain the signature list. New protocol? We add it.
// reverse_proxy
A fully-customizable challenge layer in front of your web app — JavaScript verification, CAPTCHA, JA3/JA4 fingerprinting, country rules. Similar shape to Cloudflare, hosted by us, tuned by us.
// supported_protocols
Each profile understands the protocol it protects — not just IPs and ports. Don't see yours? We add new profiles on request, and tune any of these to your server. UDP and TCP both covered.
Full Cfx.re framework protection for GTA V and RDR2 roleplay servers, with optional strict deep-packet inspection.
Protocol-aware filtering for Java Edition servers and proxies (Velocity, BungeeCord, Paper).
RakNet handshake validation for Facepunch's Rust — bot joins and connection floods dropped at the edge.
DTLS session validation for the console edition, with a stricter profile available for sustained pressure.
Keeps Bohemia survival and mil-sim sessions clean of spoofed and malformed traffic.
Packet validation for the long-running GTA: San Andreas multiplayer mod.
Filtering for classic SA:MP roleplay and freeroam servers and their query traffic.
Community GTA V multiplayer platform, validated at the protocol layer.
Open-world survival sessions shielded from join floods and query abuse.
Round-based horror servers kept playable under sustained pressure.
Co-op survival servers protected without touching your mod stack.
PC and console survival sessions, protocol-validated.
Dedicated Palworld servers filtered against connection floods.
Competitive medieval melee servers kept lag-free during attacks.
Private and community BF4 servers shielded from volumetric abuse.
Protection for the community-run Plutonium server platform.
Multiplayer sessions in the Zone, validated against spoofed packets.
Megatrain survival shooter servers, protocol-filtered.
QUIC-based transport profile for Hytale and other modern UDP game back-ends.
One profile covering Valheim, V Rising, Satisfactory, Dead by Daylight, Unturned and other GNS-based titles.
Validates Steam server-browser (A2S) queries for any Steam-listed game, killing reflection abuse.
Voice servers stay connected while the flood gets dropped.
Modern VPN endpoints protected without breaking the handshake.
Remote-access and site-to-site tunnels kept online under load.
The modern UDP transport behind HTTP/3 and next-gen game back-ends, validated at the edge.
Generic Datagram TLS profile for secured UDP applications beyond the named titles above.
Universal source-validation that covers most applications out of the box, before any game-specific tuning.
Drops everything on ports you don't declare, so only your real services are ever reachable.
Profiles are maintained and updated continuously. "Experimental" marks a profile still being hardened — it works, we just keep refining it. Mitigation tuning for any title is included with every Shield plan.
// support_included
Every Shield plan includes hands-on mitigation support. Open a ticket with the attack signature, the affected service, or just the IP being hit — we'll adjust the L7 rules, tighten the challenge layer, or roll a custom filter in minutes. That's the part most providers charge extra for. We don't.
// shield_plans
Pricing in EUR · 20% Austrian VAT for AT consumers · Reverse charge for EU B2B
> under_attack_now?
We onboard active mitigations during attacks. Reach out — bring whatever logs you have, we'll spec a tier and migrate fast.
Talk to us →