VPS / SHIELD

Stay online when
someone wants you offline

Shield is our always-on DDoS-protected VPS line. Layer 4 + Layer 7 mitigation across more than 3 Tbps of scrubbing capacity, backed by our own XDP filtering and tuned per workload by our team. No waiting, no reconnects, no excuses.

From €6,99/mo · Online in under 60 seconds · 14-day right of withdrawal

shield plans

Pick a tier, protection is included on every one.

The same always-on mitigation on every tier. You are picking CPU, RAM and disk, not a protection level.

Pricing in EUR · 20% Austrian VAT for AT consumers · Reverse charge for EU B2B

Shield S

€6,99 EUR / mo
  • 1× vCPU · Ryzen 9 9950X
  • 1 GB DDR5 RAM
  • 20 GB NVMe SSD
  • Port 25 Gbps shared 5 TB fair use (outbound)
  • Advanced DDoS protection
  • 1× IPv4 address
  • IPv6 /64 included
Order now

Shield M

€10,99 EUR / mo
  • 2× vCPU · Ryzen 9 9950X
  • 2 GB DDR5 RAM
  • 40 GB NVMe SSD
  • Port 25 Gbps shared 8 TB fair use (outbound)
  • Advanced DDoS protection
  • 1× IPv4 address
  • IPv6 /64 included
Order now

Shield L

€16,99 EUR / mo
  • 2× vCPU · Ryzen 9 9950X
  • 4 GB DDR5 RAM
  • 60 GB NVMe SSD
  • Port 25 Gbps shared 12 TB fair use (outbound)
  • Advanced DDoS protection
  • 1× IPv4 address
  • IPv6 /64 included
Order now

Shield XL

€29,99 EUR / mo
  • 4× vCPU · Ryzen 9 9950X
  • 8 GB DDR5 RAM
  • 100 GB NVMe SSD
  • Port 25 Gbps shared 20 TB fair use (outbound)
  • Advanced DDoS protection
  • 1× IPv4 address
  • IPv6 /64 included
Order now

Shield XXL

€54,99 EUR / mo
  • 6× vCPU · Ryzen 9 9950X
  • 16 GB DDR5 RAM
  • 150 GB NVMe SSD
  • Port 25 Gbps shared 35 TB fair use (outbound)
  • Advanced DDoS protection
  • 1× IPv4 address
  • IPv6 /64 included
Order now

Shield Pro

€99,99 EUR / mo
  • 8× vCPU · Ryzen 9 9950X
  • 32 GB DDR5 RAM
  • 200 GB NVMe SSD
  • Port 25 Gbps shared 75 TB fair use (outbound)
  • Advanced DDoS protection
  • 1× IPv4 address
  • IPv6 /64 included
Order now

built for

High-target services where downtime costs you money or players.

gaming

Game servers

FiveM, Minecraft, Rust, DayZ, SA:MP, Palworld, and 29+ protocol profiles in total. Per-game mitigation rules.

commerce

Web shops

Cart sessions and checkout APIs survive volumetric and L7 attacks without breaking the user flow.

reach

Public websites

News, forums, dashboards, controversial speech. Reverse-proxied challenge layer keeps bots out, real humans in.

infra

APIs & back-ends

Authentication endpoints, webhooks, SaaS back-ends, protected at line rate without rewriting your stack.

visibility

Insight into every incident, in our control panel.

Every protected IP gets its own page. Peak throughput, peak packets per second, attack type, source network, and which filter handled it, the moment it happens.

No ticket. No waiting on us to explain the outage. Something hits you tonight, the log is there in the morning with the numbers attached.

That is one of our own machines. We would rather show you a real panel than a mockup.

And that was a quiet night. In the past month the largest attack we absorbed peaked at 241 Gbps and 25 million packets per second, on — the top of a burst that stayed above 200 Gbps for 5 minutes. Same always-on path, no detection window to sit through. We have absorbed considerably larger attacks than this. 241 Gbps is the biggest in this window, not the biggest we have ever handled — our incident telemetry only reaches back to early 2026.

DDoS panel headline figures: peak Mbps, peak packets per second and incident count for a protected IP
DDoS attack history in the panel: attack type, mitigation, peak throughput and originating network per incident

panel.1337hosting.com

The same incidents, in text
Three DDoS incidents mitigated on one 1337 Hosting machine on 15 July 2026, with peak throughput, peak packet rate, attack vector, the filter that handled each one and the originating network.
Time Vector Peak Top source
23:05 TCP flood flowShield 964 Mbps 149,094 pps NL · hosting network
21:50 TCP flood flowShield 2,186 Mbps 182,681 pps DE · hosting network
21:43 TCP flood flowShield 2,575 Mbps 213,902 pps CN · national backbone

One machine, 15 July 2026, all three absorbed by always-on filtering. Peak 2,575 Mbps and 213,902 packets per second. Historical figures from the panel above, not a live feed.

always on

Mitigation runs before the attack, not after.

Every packet to a Shield VPS crosses our scrubbing layer, 24/7, attack or no attack. No detection window. No failover shuffle. No blip while we re-route. A malicious flow arrives, it drops.

Standard VPS runs in reactive mode. Fine for back-office workloads. Wrong when five seconds of jitter is a refund or a rage-quit.

shield

0s

Time to mitigation, always-on, no detection window

standard

~5s

Reactive: detection + reroute window, brief reconnect possible

layer 4

Volumetric & protocol attacks dropped at the edge

layer 7

Per-application filters, UDP and TCP, tuned by us

layer 7

Application-aware filtering for game protocols and HTTPS.

L4 protection alone leaks complexity into the application: slow loris, query floods, fake handshakes, malformed game packets. Shield parses traffic at the protocol layer and drops what doesn't belong.

game protocols

L7 game-protocol filters

Pre-built filters for FiveM, Minecraft, Rust, DayZ, ARK, Source engine, SAMP, and more, both UDP and TCP. We maintain the signature list. New protocol? We add it.

  • ·Per-game packet shape validation
  • ·Auth handshake gating
  • ·Connection-rate per source IP
  • ·Tuneable per server (you tell us)

reverse proxy

Reverse proxy for HTTPS

A fully-customizable challenge layer in front of your web app: JavaScript verification, CAPTCHA, JA3/JA4 fingerprinting, country rules. Similar shape to Cloudflare. Ours sits at our edge, and we configure it for your app.

  • ·JS challenge + optional CAPTCHA
  • ·Per-route rules (allow API, gate /login)
  • ·Bot fingerprinting (JA3 / JA4)
  • ·Custom challenge page on your brand

supported protocols

29+ application profiles, filtered at the packet layer.

Each profile understands the protocol it protects, not just IPs and ports. Don't see yours? We add new profiles on request, and tune any of these to your server. UDP and TCP both covered.

Some profiles have a page of their own, covering what the filter checks for that title and where it stops helping:

Game servers

Full Cfx.re framework protection for GTA V and RDR2 roleplay servers, with optional strict deep-packet inspection.

Standard Experimental Strict DPI

Protocol-aware filtering for Java Edition servers and proxies (Velocity, BungeeCord, Paper).

RakNet handshake validation for Facepunch's Rust, bot joins and connection floods dropped at the edge.

Rust Console (DTLS)

UDP

DTLS session validation for the console edition, with a stricter profile available for sustained pressure.

Standard Strict

DayZ:SA / ArmA III

UDP

Keeps Bohemia survival and mil-sim sessions clean of spoofed and malformed traffic.

Multi Theft Auto (MTA:SA)

UDP

Packet validation for the long-running GTA: San Andreas multiplayer mod.

Filtering for classic SA:MP roleplay and freeroam servers and their query traffic.

alt:V Multiplayer

UDP

Community GTA V multiplayer platform, validated at the protocol layer.

GTA V roleplay framework. Baseline anti-spoofing and connection-flood filtering while the handshake profile is still being tuned.

experimental

SCUM

UDP

Open-world survival sessions shielded from join floods and query abuse.

SCP: Secret Laboratory

UDP

Round-based horror servers kept playable under sustained pressure.

7 Days to Die

UDP

Co-op survival servers protected without touching your mod stack.

Conan Exiles

UDP

PC and console survival sessions, protocol-validated.

experimental

Palworld

UDP

Dedicated Palworld servers filtered against connection floods.

experimental

Mordhau

UDP

Competitive medieval melee servers kept lag-free during attacks.

Battlefield 4

UDP

Private and community BF4 servers shielded from volumetric abuse.

Call of Duty: Black Ops II (Plutonium)

UDP

Protection for the community-run Plutonium server platform.

S.T.A.L.K.E.R.: Shadow of Chernobyl

UDP

Multiplayer sessions in the Zone, validated against spoofed packets.

Enginefall

UDP

Megatrain survival shooter servers, protocol-filtered.

experimental

Hytale (QUIC)

UDP

QUIC-based transport profile for Hytale and other modern UDP game back-ends.

GameNetworkingSockets (Valve GNS)

UDP

One profile covering Valheim, V Rising, Satisfactory, Dead by Daylight, Unturned and other GNS-based titles.

experimental

Steam Query (A2S)

UDP

Validates Steam server-browser (A2S) queries for any Steam-listed game, killing reflection abuse.

Voice & VPN

TeamSpeak 3

UDP

Voice servers stay connected while the flood gets dropped.

WireGuard

UDP

Modern VPN endpoints protected without breaking the handshake.

OpenVPN

UDP

Remote-access and site-to-site tunnels kept online under load.

Transport & web

QUIC / HTTP/3

UDP

The modern UDP transport behind HTTP/3 and next-gen game back-ends, validated at the edge.

DTLS

UDP

Generic Datagram TLS profile for secured UDP applications beyond the named titles above.

Universal baseline

Anti-spoofing + rate-limiting

UDP/TCP

Universal source-validation that covers most applications out of the box, before any game-specific tuning.

Per-port lockdown

UDP/TCP

Drops everything on ports you don't declare, so only your real services are ever reachable.

Profiles are maintained and updated continuously. "Experimental" marks a profile still being hardened, it works, we just keep refining it. Mitigation tuning for any title is included with every Shield plan.

coverage

What happens when your game is not on the list.

The grid above names the titles we have written specific rules for: FiveM and RedM, Minecraft, Rust on PC and Console, DayZ:SA, ArmA III, Multi Theft Auto, San Andreas Multiplayer, alt:V, SCUM, SCP: Secret Laboratory, 7 Days to Die, Conan Exiles, Palworld, Mordhau, Battlefield 4, Black Ops II on Plutonium, S.T.A.L.K.E.R., Enginefall and Hytale. Voice and tunnels get their own profiles too, because TeamSpeak and WireGuard take hits about as often as the game does.

Most people arrive running something we have never heard of. That is fine. Two of our profiles are deliberately generic. One handles GameNetworkingSockets, which Valve built and much of the Source and Unity world now speaks. The other handles Steam Query, the A2S protocol behind almost every server browser. Between them they already cover titles that will never earn their own line in the grid: truck sims, survival co-op, racing servers, older Half-Life engine games. If it announces itself to a Steam server list, we have something to work with.

When the generic filters are too blunt, we write you a real profile. Send the protocol, a packet capture, or just the name of the game. Every entry above started as somebody asking. No fee, no minimum tier, no waiting on a vendor elsewhere to prioritise your title. Still standing the server up? Our setup guides cover Minecraft on PaperMC and TeamSpeak on Debian 13, both tested on this hardware.

support included

We tune the rules with you. No upsell, no consulting fee.

Every Shield plan includes hands-on mitigation support. Send the attack signature, the affected service, or just the IP being hit. We adjust the L7 rules, tighten the challenge layer, or write a custom XDP filter, usually within minutes. Your change never sits in a vendor queue behind someone else's support desk. Most providers charge extra for that. We don't.

faq

Frequently asked questions

Do you offer DDoS protected RedM server hosting?

Yes. RedM and FiveM both run on the Cfx.re protocol and share a dedicated UDP profile on every Shield plan, with an optional strict deep-packet inspection mode for servers taking sustained pressure. It validates the framework's own handshake, so spoofed sessions and join floods are dropped at our edge before they reach your tickrate.

My game is not on your list. Can you still protect it?

Usually, yes. Two of our filters are deliberately generic: GameNetworkingSockets, which Valve built, and Steam Query, the A2S protocol behind most server browsers. Between them they cover a wide slice of the Source, Unreal and Unity world. We can have never heard of your game and still recognise how it talks. Where the generic pass is too blunt, ask. We will write you a real profile, no fee and no minimum tier. The 29+ list grew exactly that way, one request at a time.

Which games have a dedicated profile today?

FiveM and RedM, Minecraft Java, Rust on PC and Console, DayZ:SA and ArmA III, Multi Theft Auto, San Andreas Multiplayer, alt:V, SCUM, SCP: Secret Laboratory, 7 Days to Die, Conan Exiles, Palworld, Mordhau, Battlefield 4, Call of Duty: Black Ops II on Plutonium, S.T.A.L.K.E.R., Enginefall and Hytale. TeamSpeak, WireGuard and OpenVPN have their own profiles too, since voice and tunnels get hit as often as the game itself.

How is Shield different from the DDoS protection on a Standard VPS?

Timing, mostly. A Standard VPS is reactive: an attack has to be detected before filtering engages. That is roughly a five second window where you can see packet loss or a reconnect. Shield keeps every packet crossing the scrubbing layer 24/7, so there is no detection gap to sit through. Shield also adds Layer 7, which reactive Layer 3/4 filtering cannot do at all.

Does the filtering cost me latency?

Your traffic crosses the scrubbing layer whether or not anyone is attacking you, and that is the whole design. There is no switchover and no clean path versus attack path, so what you measure on a quiet Tuesday is what you get in the middle of an incident. Nothing changes shape when the traffic arrives.

How much attack traffic can you absorb?

More than 3 Tbps of scrubbing capacity, with our own XDP filtering in front of it. Volumetric and protocol attacks are dropped at the edge, well before they reach the node your VPS is running on.

Can I use Shield for a website or a web shop instead of a game server?

Yes, and a fair number of customers do exactly that. The reverse proxy sits in front of your web app with a JavaScript challenge, optional CAPTCHA and JA3/JA4 bot fingerprinting. Rules are per route, so you can leave an API wide open while gating a login page. Checkout sessions ride out a Layer 7 flood and you rewrite nothing.

Do I have to change my DNS or my code?

No. Protection attaches to your VPS IP address, so whatever is listening on that IP is covered from the moment the server boots. There is no separate hostname to point at and no SDK to install.

Is tuning included, or is it a paid add-on?

Included. Open a ticket with the attack signature, the affected service, or just the IP being hit. We adjust the Layer 7 rules, tighten the challenge layer, or write you a custom XDP filter. Most providers bill that as consulting. We do not, and your change never sits in a vendor queue behind someone else's support desk.

I am under attack right now. Can you onboard me mid-incident?

Yes, we do it regularly. Contact us with whatever logs you have and we will spec a tier and move you fast. Two things help: the target IP, and a rough idea of the traffic shape. With those we can pre-load the right profile before you cut over, so the protection is already waiting when your DNS moves.

What if the attack targets your whole subnet instead of my IP?

Then mitigation can engage for the entire affected range, which means several customers at once. It is an honest limitation of shared network space and our terms name it as such. It is rare, it is externally caused, and we would rather you read it here than discover it during an incident.

Which Shield tier gives me the best protection?

All of them, equally. Every tier from Shield S to Shield Pro gets identical always-on mitigation, the full profile list and the same tuning support. Moving up a tier buys CPU, RAM and disk. It does not buy you a better class of filtering, and we are not going to sell protection back to you in slices.

> under_attack_now?

We onboard active mitigations during attacks. Reach out, bring whatever logs you have, we'll spec a tier and migrate fast.

Talk to us →