Language
TR EN
Currency
20% off Virtual Servers – LIGHT20
RouteFence® DDoS Protection

Stop DDoS Attacks with
Always-On Defence

Layer 3, 4 and 7 attacks are filtered before they reach your server. With 140 Gbps in Turkey and 4 Tbps Anycast of capacity abroad, protection stays uninterrupted from game servers to corporate projects.

140 GbpsLocal Protection
4 TbpsAnycast abroad
Always-OnActive 24/7
RouteFence® Guard Protection Active
L3 · L4 · L7Multi-layered filtering
Network traffic
AttackForwarded to server
  • UDP FloodL3/L4Filtered
  • TCP SYN FloodL4Filtered
  • HTTP FloodL7Filtered
View Protected Servers Illustrative view
Always-On Filtering

How Does DDoS Protection Work?

The security steps attack traffic passes through before it reaches your server.

1

Incoming Traffic

A UDP flood, SYN flood, botnet or L7 HTTP attack arrives on the network together with normal traffic.

2

BGP Anycast

Traffic is routed to the RouteFence® scrubbing node closest to its source.

3

XDP Filtering

Packets are inspected at kernel level; traffic that breaks the rules or targets unlearned ports is dropped.

4

Clean Traffic

Validated packets are passed to your server and your service keeps running.

Strong Network Security

Why RouteFence® DDoS Protection?

A multi-layered infrastructure that analyses and filters attack traffic and delivers clean traffic to your server.

RouteFence®

High-Capacity Filtering

Attacks originating in Turkey and abroad are absorbed by separate pools of capacity. Volumetric traffic is scrubbed at the cleaning nodes before it reaches your server, so your players and visitors see no downtime.

In Turkey140 Gbps
Anycast abroad4 Tbps

Multi-layered Protection

L3/L4 From UDP and SYN flood attacks L7 to HTTP flood attacks, everything is filtered simultaneously.

Kernel-Level Filter (XDP / eBPF)

packets are processed before they enter the operating system At NIC driver level — so CPU load stays stable even under a heavy attack.

Automatic Port Learning

The ports active on your server are learned automatically; only traffic to those ports is allowed through.

Always-On Defence

Protection is active 24/7. When an attack starts, filtering kicks in automatically; no manual action is needed.

No Extra Charge

VDS, Ryzen VDS and Dedicated server packages at Light Hosting include it as standard.

Coverage

Attack Types and How They Are Handled

How threats at different layers are filtered on the RouteFence® infrastructure.

Attack typeLayerFiltering methodStatus
UDP Flood / Amplification
Layer 3/4
Packet dropping and rate limiting at kernel level with XDP
Filtered
TCP SYN / ACK / RST Flood
Layer 4
SYN proxy and TCP connection validation
Filtered
DNS / NTP Reflection
Layer 3/4
Source port and packet signature (payload) filtering
Filtered
HTTP / HTTPS Flood
Layer 7
Behaviour analysis and a challenge page — Layer 7 WAF
Filtered
Game Server Bot / Query Flood
Layer 4/7
Automatic port learning and UDP/TCP packet validation tailored to game traffic
Filtered

Are You Under Attack?

Talk to our expert team. With our strong RouteFence® infrastructure, let us find the right protected server for your game servers or corporate projects together.

Knowledge Centre

DDoS & Cyber Security

A short guide to how DDoS attacks work and how your server is protected.

The Basics

What Is a DDoS Attack?

Traffic sent simultaneously from many devices to make a server unable to serve.

Read moreClose

DDoS (Distributed Denial of Service) means flooding a target server with traffic, usually through a botnet of compromised devices. The aim is to fill up the bandwidth, the processor or the connection table so that real users cannot reach the service.

Attacks are grouped by the layer they target: L3/L4 attacks target network and connection resources, while L7 attacks target the web application itself.

Layer 4

How Is a SYN Flood Attack Stopped?

Leaving the TCP handshake half open to fill the server's connection queue.

Read moreClose

The attacker sends a large number of SYN packets but never completes the handshake. Because the server reserves resources for every half-open connection, the backlog fills up and new users cannot connect.

RouteFence® meets this traffic with SYN proxy and TCP connection validation : connections that never complete the handshake are eliminated before they reach your server.

Layer 3/4

Amplification Attacks: DNS and NTP

Using open services that answer small queries with large responses to reflect traffic at a target.

Read moreClose

The attacker replaces the source IP address with the target's address and sends small queries to open DNS or NTP servers. Those servers send far larger responses to the target server, and its bandwidth fills up.

This kind of traffic is dropped source port and packet signature filtering at the XDP layer, while large volumes originating abroad are absorbed at the Anycast scrubbing nodes.

The Web Hosting Provider Turkey Trusts

Light Hosting is built on a principle of high customer satisfaction.

Advanced Data Centre

State-of-the-art servers and Tier-3 data centre infrastructure.

682+ Happy Customers

Uninterrupted service for companies across Turkey.

Ryzen-powered Servers

Feel instant load performance on your websites thanks to high core speeds.

24/7 Nonstop Support

A qualified engineer replies to your support tickets in 15 minutes on average.

S.S.S.

Frequently Asked Questions

Clear answers to the most common questions about our DDoS protection.

Does DDoS protection cost extra?

No. All VDS, Ryzen VDS and Dedicated server packages include standard RouteFence® protection at no extra cost.

What is the protection capacity?

The RouteFence® infrastructure has 140 Gbps of filtering capacity for traffic within Turkey and 4 Tbps for traffic from abroad via BGP Anycast.

Which attack types are covered?

At Layer 3/4, UDP floods, amplification, TCP SYN/ACK/RST floods and DNS/NTP reflection attacks are filtered; at Layer 7, HTTP/HTTPS floods are filtered. Application-layer protection for websites Layer 7 WAF provides this.

Is protection always on, or do I need to do something during an attack?

Protection is Always-On, so it is active at all times. When an attack starts, traffic is filtered automatically; nothing needs to be done on your side.

Does ping or latency increase during an attack?

Attack traffic is scrubbed at the cleaning nodes before it reaches your server. Because filtering happens at kernel level with XDP, the added latency is under 1 millisecond.

Are there dedicated filters for FiveM, Minecraft or other game servers?

Yes. Layer 4 UDP/TCP packet validation filters are active for game servers. Thanks to automatic port learning, only the ports your server uses receive traffic.

How can I reach the support team?

You can reach our support team over WhatsApp (+90 850 304 7683) and through the ticket system.