DDoS Protected VDS and Virtual Server Hosting
Most people looking for a DDoS protected VDS have already lived through the same problem: the server itself is fine, but the line leading to it is full, players drop and the site will not load. At Datafex every virtual server is DDoS protected; the protection is not an add-on you buy separately. On every VDS plan, traffic is first scrubbed at distributed nodes inside Türkiye or at filters abroad, then passes our DPDK + VPP router and finally Fexwall's L4–L7 inspection before it reaches your server. The servers run on Datafex owned cabinets in the DGN Data Center in Bursa, Türkiye.
Recommended entry configuration
₺290,00 / mo
2 GB RAM · 2 vCPU · 40 GB NVMe · Xeon E5-2699v4
Prices exclude VAT (20%).
What a DDoS protected virtual server (VDS) actually means
The phrase “DDoS protected” says nothing on its own; the real question is which layer the protection works at and where it sits. Attacks come in two families. Volumetric attacks target the line, not the server: in DNS, NTP or TCP reflection and amplification attacks the attacker sends requests to third-party servers using your address as the source, and every reply comes back to you. Resource-exhausting attacks keep the server busy without filling the line: UDP floods with forged source addresses, half-open TCP connections, botnet-driven request floods. At Datafex these families meet layers that work in sequence. The first scrubbing happens where the traffic comes in: traffic from Turkish ISPs is filtered at distributed nodes inside Türkiye and international traffic at filters abroad, so most of a volumetric flood stops before it reaches our core. What remains arrives at our DPDK + VPP router, which runs full-route and state tracking and applies its own filters to reflection and amplification based TCP/UDP attacks. Fexwall comes last: working between L4 and L7, it removes forged source addresses, tracks connection flow to tell expected traffic from anomalous traffic, and applies protection profiles tailored to your project. Only verified clean traffic reaches your VDS. The protection does not depend on the plan: the smallest VDS and the largest sit behind the same layers.
Why protection belongs in the network, not on the server
The firewall inside the server — iptables or nftables on Linux, Windows Defender Firewall on Windows — only sees a packet after it has crossed the line and reached the machine. In a volumetric attack that is exactly the problem: once the line is full, legitimate packets cannot get through either, and no rule written inside the server can take that traffic back. UDP adds a second problem: there is no handshake, so the source address is easy to forge, and trying to block the attacker's address usually means blocking an innocent third party. That is why for UDP-heavy services such as FiveM, CS2 or voice servers, filtering has to happen at the network layer, before the traffic reaches the server. A CDN placed in front of HTTP does not do this job; game traffic is not HTTP.
Recommended resources
These values match the VDS plan tiers in our catalogue; the exact price is calculated in the configurator.
Prices exclude VAT (20%).
| Scenario | RAM | vCPU | Storage | Monthly price | Note | Buy |
|---|---|---|---|---|---|---|
| Website, API or bot | 2 GB | 2 | 40 GB | ₺290,00 / mo | Protection does not depend on resources; the smallest plan sits behind the same layers. | Buy |
| Game server, up to 64 slots | 8 GB | 4 | 60 GB | ₺770,00 / mo | Matches the entry tier on the FiveM page; game and query ports get their own rules. | Buy |
| Game server + website + database | 16 GB | 8 | 120 GB | ₺1.670,00 / mo | The whole community stack on one machine; each service's port is opened by its own rule. | Buy |
Capacity, limits and the honest answer
The right question about DDoS protection is not “is it unlimited?” but what the capacity is and what happens when it is exceeded. The Datafex network runs on a redundant uplink with 100 Gbps of domestic and 10 Tbps of international capacity. No provider absorbs an attack larger than the total transport capacity of its network, and we do not claim to. The limit is written plainly in section 11 of the service level agreement (SLA): protection applies within capacity limits, and during a volumetric attack that exceeds them, traffic to the targeted IP address may be temporarily quarantined to protect the wider network, and that period is not counted as downtime. Reading that sentence before you buy tells you far more than an “unlimited protection” label. For attacks below the capacity, traffic is filtered across the layers and legitimate traffic keeps flowing; you can follow what the attack looks like and what was dropped from the panel.
What you see and control in the panel
Fexwall is not a black box. The service detail page in the customer panel has a Fexwall section where you follow the bandwidth, packet flow and dropped traffic of your protected IP address. On the rules side there are two routes: pick one of the ready-made protection packages, or define your own allow and deny rules by source, protocol and port. A good rule set shrinks the service surface: a game server exposes only its game and query ports, a website only ports 80 and 443, and management access (SSH 22 or RDP 3389) is allowed from your own address alone. If your attack profile needs filtering beyond the general rules, you can request a security profile tailored to your project. Fexwall works between L4 and L7: it looks not only at the packet header but at connection state and application-layer traffic, so request floods against your website are handled at this layer too. For cases specific to your application — a single endpoint that triggers an expensive query, for example — rate limiting in the application is still a good complement.
More on how the protection works
- Fexwall DDoS protection
The path a packet takes: distributed scrubbing, the DPDK + VPP router and the Fexwall control panel, step by step.
- BGP DDoS protection
If you own an IP range and an ASN: announce the range through the Datafex network and get protection wherever your servers are.
- Guide: the difference between L3/L4 and L7 protection
The limits of “unlimited protection” and five questions to ask a provider.
- Guide: telling an attack apart from a resource bottleneck
Most slowdowns are not attacks; the symptoms, the measurements and what to do during an attack.
- Service level agreement (SLA)
Section 11: the capacity limit of DDoS protection and what happens when it is exceeded.
Setup steps
- 1Pick your VDS in the configurator; Fexwall is not a separate option, it is active on every plan automatically.
- 2Provisioning completes automatically once payment is verified; the IP address, username and password appear in the service detail page.
- 3List the ports and protocols your service uses — for example 30120 TCP and UDP for FiveM, 80 and 443 TCP for a website.
- 4In the Fexwall section of the customer panel, pick a ready-made protection package or define your own source, protocol and port rules.
- 5Open management access (SSH 22 or RDP 3389) to your own IP address only.
- 6After adding rules, reach the service from outside over a different connection to confirm legitimate traffic still gets through.
- 7Follow the traffic statistics in the panel; if your attack profile needs special filtering, request a security profile tailored to your project.
Common mistakes
- Looking at the label instead of the layer. What the UDP traffic of game and voice servers needs is L3/L4 filtering; a CDN that only protects HTTP never sees that traffic.
- Trying to stop a volumetric attack with the firewall inside the server. By the time the packet reaches the machine the line is already full; that job belongs at the network edge.
- Blocking IPs one by one during a spoofed attack. The source address is forged, so the address you block most likely belongs to an innocent third party.
- Forgetting your own service port when writing rules. An overly strict rule stops the attack and locks out your players or visitors too; test from outside after every rule.
- Treating every slowdown as an attack. Most slowdowns are CPU, RAM or storage bottlenecks; check the server metrics in the panel first, then the Fexwall traffic statistics.
- Trusting an “unlimited protection” promise without reading the contract. What happens during an attack above capacity is written in the SLA; at Datafex it is section 11.
What is included at Datafex
Layered Fexwall DDoS protection is included free on every plan. Volumetric attacks are stopped at the nodes and the router, forged traffic at Fexwall, while legitimate traffic passes.
Fexwall DDoS protection architectureEvery plan uses NVMe SSD. In most of these scenarios the database runs on the same machine as the application, so storage latency shows up directly in response time.
Servers are in Türkiye, at the DGN data centre in Bursa. Transit is 100 Gbps domestic and 10 Tbps international.
Setup completes automatically within minutes. Extra IPs, rDNS, backups and firewall rules are managed from the customer panel.
Frequently Asked Questions
- Do I pay extra for DDoS protection?
- No. Fexwall is included free on every VDS plan and is not an add-on sold separately. On the smallest plan and on the largest, traffic passes the same layers; the protection does not depend on the vCPU or RAM you choose.
- Which kinds of attack are stopped?
- Volumetric attacks — reflection and amplification types such as DNS amplification, NTP amplification, TCP amplification and TCP reflection — are cut at distributed nodes inside Türkiye or at filters abroad, and then on our DPDK + VPP router. The last layer, Fexwall, handles traffic with forged source addresses, botnet-driven request floods, application-layer request floods and traffic that does not match the rules you define, between L4 and L7.
- How much capacity is there, and what happens if an attack exceeds it?
- The network runs on a redundant uplink with 100 Gbps of domestic and 10 Tbps of international capacity. Under section 11 of the SLA, protection applies within capacity limits; during volumetric attacks that exceed them, traffic to the targeted IP address may be temporarily quarantined to protect the wider network, and that period is not counted as downtime.
- Are UDP services such as FiveM, CS2 or voice servers protected?
- Yes. For UDP-heavy game traffic, volumetric floods are removed at the distributed nodes and the router, and forged-source traffic at Fexwall, while legitimate game traffic — FiveM's UDP traffic on 30120, for example — passes. Per-game resource guidance is on the game server pages.
- Can I define my own security rules?
- Yes. In the Fexwall section of the customer panel you can pick one of the ready-made protection packages or define allow and deny rules by source, protocol and port. The same section shows bandwidth, packet flow and dropped traffic. If general rules are not enough, you can request a security profile tailored to your project.
- My servers are with another provider — can I get only the DDoS protection?
- If you own an IP range and an ASN, yes: with the BGP DDoS protection service your range is announced through the Datafex network and, once filtered, traffic is delivered to you over a GRE tunnel or a direct connection. Without your own range, the way to get the protection is to run the server on Datafex infrastructure directly.
- Where do the servers run?
- There is one location: Bursa, Türkiye. The servers run on Datafex owned cabinets in the DGN Data Center. For projects serving players and visitors in Türkiye, a domestic exit gives lower latency than a location abroad.
Configure your server
Pick the resources that fit and start the setup within minutes.