HolicNode Always-on protection

How we protectyour server.

Four layers working at once — an anycast edge, AI early detection, automatic mitigation and a firewall you control. All of it on the moment your traffic is routed through us.

No hardware · no contracts · protected in minutes

256+ Tbps
Edge capacity
< 1 sec
Time to mitigate
L3/4 + L7
Filtering
99.99%
Uptime target

The four layers

One edge, four lines of defence

Each layer does one job. Together they make sure an attack never reaches the machine your players are on.

The edge

Your server's real address stops being public. Players connect to an address we give you, and their traffic enters the nearest of hundreds of edge locations before it ever reaches your machine.

AI early detection

Our detection reads the shape of your traffic as a network graph and learns what normal looks like for your server — so it recognises an attack forming, often before it peaks, instead of waiting for a threshold.

Automatic mitigation

The moment an attack is recognised, mitigation is already on. It is inline and always-on, so there is no detect-then-enable gap — traffic is scrubbed at the edge in under a second.

The firewall net

Every service carries a firewall you control: rate limiting (10 Mbps), SYN auto-block (50), geo controls and custom rules — all set from your panel.

What it means for you

Protected without the overhead

Your real IP stays hidden

Players connect to the address we give you, so your origin address stops being the target.

Zero runtime config

Everything is on the moment your traffic is routed through us. Tune the firewall if you want; nothing has to be set up to be protected.

Watch it live

Traffic, mitigation events and your services in one panel — so you can see clean traffic, not just trust it.

FAQ

Protection, answered

Is the mitigation automatic?

Detection and mitigation are automatic and always-on. The AI learns what normal looks like for your server and the edge acts on it — you never have to flip a switch during an attack.

What does the 10 Mbps rate limit do?

Every service carries rate limiting you can tune from your panel. A per-connection ceiling (10 Mbps by default) caps how much any single source can pull, so one abusive client cannot starve your other players.

How does SYN auto-block work?

When a source sends an unusual burst of connection attempts — our default triggers at 50 SYN — it is blocked automatically before it can exhaust your server's connection table.

Do I have to configure any of this?

No. The protection layers are on from the moment your traffic is routed through us. The firewall knobs are there if you want to tune them; nothing needs to be configured before you are protected.

Will this reveal my server's real IP?

No. Players connect to the address we give you; your origin address stops being public, so it stops being a target.

Get protected in minutes

No hardware, no long contracts — protection is live the moment your traffic is routed through us.

Choose a plan