DDoS mitigation for Linux servers, websites, and game services.
Protect a Linux server at the network edge, put a managed WAF in front of a website, or shield a game service. Spaceflare shows traffic, attack reports, geo data, and mitigation state in one console.
- filtering path
- Sub-ms
- filtering path
- documented benchmark, one core
- 10M+ pps*
- documented benchmark, one core
- XDP/eBPF verdicts before sockets
- Kernel-level
- XDP/eBPF verdicts before sockets
- profiles for UDP + voice fleets
- Game-tuned
- profiles for UDP + voice fleets
* OpenShield-XDP benchmark result from the documented test setup; actual throughput depends on NIC, CPU, packet size, and traffic mix. Read the benchmark notes in the docs.
Everything the firewall sees, in one console
OpenShield-XDP mitigates at line rate inside the NIC driver. The console streams its metrics endpoint into a single pane of glass: per server, per attack, per packet path.
Live traffic
Per-second PPS and bandwidth with incoming vs passed series. Mitigation you can watch, not trust.
Proof of mitigation
Bans, drop paths, per-attack forensics. The passed line collapses; the graph proves it.
Geo analytics
Per-country attack breakdowns on a live map, plus one-click country blocking.
Adaptive baseline
A 30-day baseline memory that learns your traffic and can't be poisoned by a single bad day.
XDP line rate
Drops happen in the NIC driver, before the kernel sees a packet. Benchmark results reach 10M+ pps on one core in the documented test setup.
HWID-bound licensing
Keys bound to hardware, verified online, graceful offline. Your servers stay yours.
Five stages between the flood and your server
Every packet crosses a fixed pipeline inside the NIC driver. Each stage is a verdict measured in nanoseconds, and each one is visible in the console while it happens.
- 01Ban checkKnown offenders never get a second lookup.
- 02Rate limitPer-source floors learned from your own baseline.
- 03Connection trackBogus TCP dies before a socket exists.
- 04Amplification guardDNS/NTP/CLDAP reflection filtered by shape.
- 05L7 filterPattern rules match payload, not just headers.
- DE38%
- CN24%
- BR15%
- NL9%
One account, one daemon, every layer covered
Each product does one job and shares the same plumbing: the fleet daemon on your servers, the same console, the same alerts. Start with one and add pieces as you grow.
OpenShield-XDP
An eBPF firewall agent that drops L3/L4 floods inside the NIC driver, before the kernel sees a packet.
- Line-rate drop, sub-millisecond overhead
- Game and Game Pro editions: per-player token buckets, A2S/RCON shielding, engine presets
- One-time license, lifetime updates
Web Firewall
A managed edge WAF in front of your site. Layer-7 attacks stop upstream after a single DNS change.
- HTTP flood absorption and bot filtering at the edge
- WAF Pro: per-route rate shaping, API schema protection, SLA
- Five-minute setup, monthly plan
L4 Tunnel
Pair two of your own servers into a GRE tunnel, with the real client IP preserved.
Health Monitor
Vitals, health scores, benchmarks and alerts for every connected server.
Server Optimization
One command tunes the host: sysctl, limits, CPU governors, zram. Output streams into the dashboard.
Game Panel Setup
A guided wizard installs a game server panel on your box, database and TLS included.
They stack. OpenShield-XDP guards the origin while the WAF absorbs floods at the edge, and the console shows both.
Protected in three steps
- 01
Connect your server
Install the agent, enable metrics, paste the URL and key into the console. Two minutes, one config line.
Details - 02
Traffic filtered at the kernel
The XDP pipeline learns your baseline and drops floods at the driver. Legit traffic never notices.
Details - 03
Watch it in the dashboard
Per-second graphs, per-attack forensics, geo breakdowns and bans. Proof, live.
Details
Your next attack report will look different
Register, connect a server with its metrics URL and key, and the next flood arrives as a live graph, not a mystery.
Get started