Triple-Layer Active

RAN Online DDoS
Protection for
Private Servers

Triple-layer DDoS protection for RAN Online private servers. Cloudflare Spectrum at the edge, OVH VAC dual-cluster scrubbing, and XDP kernel-level filtering across 7 protected game channels with real player IP preservation.

3 Defense
Layers
7 Protected
Channels
1 Tbps+ Mitigation
Capacity
24/7 Always-On
Protection
RAN Online Enterprise DDoS Protected Server Hosting by HolicNode
7
Protected Ports
2
OVH VAC Clusters
2
XDP Scrub Engines
7
Backend Endpoints

Triple-Layer DDoS Protection Pipeline

Every packet traverses five defense stages before reaching your RAN Online server. Three independent filtering layers provide true defense-in-depth with fault isolation.

1

Cloudflare Spectrum

Player traffic hits Cloudflare's global Anycast network. L3/L4 attacks absorbed across 300+ PoPs before reaching origin.

2

Channel Relay

Clean traffic forwarded through 7 dedicated relay endpoints — one per game channel port.

3

OVH VAC Clusters

Two isolated dedicated server clusters perform hardware-level volumetric scrubbing with fault isolation.

4

XDP Scrubbing

Kernel-level packet filtering validates and scrubs every packet at wire speed before forwarding.

5

Backend Delivery

Verified traffic arrives at multi-IP Windows backend via Proxy Protocol v1 with real player IPs.

Traffic Flow & Network Topology

Full end-to-end view of how player traffic flows from the public internet through triple-layer defense to your RAN Online backend across 7 game channels.

Network Architecture

Live Infrastructure
External

Internet / Players

Player traffic and game sessions entering the protected delivery path.

Cloudflare Spectrum

Public Entry IP

7 forwarded ports across all game channels.

Ch 1

Port 19902

Ch 2

Port 2211

Ch 3

Port 3311

Ch 4

Port 4411

Ch 5

Port 6611

Ch 6

Port 7711

Ch 7

Port 5511

OVH VAC — Cluster A

Dedicated Server 1

Receives traffic on 6 relay IPs through OVH VAC protected network.

OVH VAC — Cluster B

Dedicated Server 2

Isolated path for port 5511 through separate OVH VAC server.

XDP Engine 1

Traffic Filter

High-performance packet filtering for 6 relay endpoints.

XDP Engine 2

Traffic Filter

Dedicated scrubbing for port 5511 traffic.

Windows Backend

Service Host

Multi-IP backend with Proxy Protocol v1 delivery.

IP 1

Port 19902

IP 2

Port 2211

IP 3

Port 3311

IP 4

Port 4411

IP 5

Port 6611

IP 6

Port 7711

IP 7

Port 5511

Cloudflare Spectrum

Single public entry IP distributes traffic across 7 forwarded channels with L4 DDoS protection at the global edge.

OVH VAC Clusters

Two dedicated clusters separate the primary 6-port group from the isolated port 5511 route for fault isolation.

XDP Scrubbing

Kernel-level packet filtering validates and scrubs all traffic at wire speed, dropping malformed packets instantly.

Proxy Protocol v1

Original client connection metadata preserved through every hop, delivering real player IPs to the backend.

Cloudflare Spectrum
Relay Channels
OVH VAC
XDP Scrubbing
Backend
Services

Why Choose HolicNode for RAN Online DDoS Protection

Purpose-built infrastructure for MMORPG workloads. Every feature is designed to keep your players connected and your server online.

7-Port Channel Protection

Full DDoS protection across all 7 RAN Online service ports. Each channel has dedicated Cloudflare Spectrum relay endpoints and XDP scrubbing rules optimized for game traffic patterns.

🛡

Dual OVH VAC Clusters

Traffic isolated across two independent OVH VAC dedicated server clusters. An attack on one cluster cannot impact the other, ensuring partial availability during sophisticated multi-vector campaigns.

🔨

XDP Kernel-Level Scrubbing

eXpress Data Path filtering processes packets at the earliest point in the Linux kernel stack. Malicious packets dropped at wire speed with sub-millisecond latency before consuming server resources.

🔒

Real Player IP Preservation

Proxy Protocol v1 passes original client IPs through all three protection layers. Ban lists, IP-based access control, GeoIP restrictions, and analytics work without modifications.

Always-On, Zero-Delay

Protection is active on every packet at all times. No detection delay or activation period. Attacks are filtered from the first malicious packet across all three layers simultaneously.

💪

1 Tbps+ Mitigation

Combined Cloudflare, OVH VAC, and XDP infrastructure absorbs the largest volumetric attacks. UDP floods, SYN floods, amplification attacks, and connection exhaustion all mitigated.

Frequently Asked Questions

Common questions about HolicNode's RAN Online DDoS protection and enterprise hosting infrastructure.

HolicNode uses a triple-layer DDoS protection architecture. Cloudflare Spectrum provides L4 edge protection at 300+ global data centers. OVH VAC performs volumetric attack mitigation using two dedicated server clusters with hardware-level scrubbing. XDP-accelerated scrubbing engines then filter remaining malicious packets at kernel-level wire speed before traffic reaches your game server.
Two clusters provide fault isolation. Cluster A handles the 6 primary game channel ports (19902, 2211, 3311, 4411, 6611, 7711), while Cluster B is dedicated to port 5511. If one cluster is under heavy attack, the other remains unaffected, ensuring partial service availability even during sophisticated multi-vector DDoS campaigns.
XDP (eXpress Data Path) is a high-performance Linux kernel framework that processes network packets at the earliest possible point in the network stack. HolicNode's XDP scrubbing engines validate and filter every packet before it reaches the RAN Online game server, dropping malformed, spoofed, and malicious packets at wire speed with sub-millisecond processing time.
Cloudflare Spectrum routes traffic through the nearest edge node in their global Anycast network, minimizing added latency. The XDP scrubbing engine operates at kernel level with sub-millisecond processing. Most players experience less than 5ms additional latency, which is imperceptible during gameplay.
Yes. HolicNode uses Proxy Protocol v1 to preserve original client IP addresses through the entire triple-layer protection chain. Your RAN Online server receives real player IPs, so ban lists, IP-based access control, and player analytics all function correctly without any server-side modifications.

Ready to Protect Your RAN Online Server?

Deploy triple-layer DDoS protection in minutes. Keep your players connected and your channels online.

Get Protected Now

More DDoS-Protected Services

HolicNode offers enterprise-grade DDoS protection across all hosting products.