How Curt Creation's Anti-DDoS Keeps RanOnline Servers Online
RanOnline private servers are attacked constantly. Here is how an anycast upstream and our own XDP firewall keep yours online through a flood.

On this page
Every RanOnline server hosted on Curt Creation sits behind an Anti-DDoS system we built ourselves. Our XDP firewall filters traffic using rules written for how RanOnline actually talks, and an anycast upstream absorbs the largest floods before they ever reach us.
Why RanOnline needs its own protection
RanOnline private servers get attacked constantly. A rival server launching the same week, a banned player with a grudge, or a cheap booter subscription is enough to take a server down at peak hours.
A RanOnline server is also not one program. It is a set of services (login, patch, session, agent and field), each listening on its own TCP port. Knock any one of them over and players cannot log in, cannot patch, or get kicked mid-game.
Generic protection treats all of that as ordinary TCP traffic. Ours knows which ports belong to your server and what a legitimate connection to them looks like.
Two layers, one path
Traffic to your server passes our anycast upstream first and our own firewall second. Each layer removes what it is best placed to catch, and only game traffic comes out the other end.
Animated flow chart. Traffic from the internet, a mix of players, volumetric floods and game-like attacks, passes two layers. Layer 1, the anycast upstream, drops the floods. Layer 2, our XDP firewall, drops the game-like attacks and anything else that is not RanOnline traffic. Only players reach your RanOnline server.
Layer 1: an anycast upstream absorbs the volume
A volumetric attack is not clever. It sends more traffic than the target's connection can carry, and no firewall on your server can fix that, because the link is already full before the firewall sees a single packet.
So the largest floods are handled before they reach us. We run our own network and announce our IP ranges through an anycast upstream, Global Secure Layer (GSL). The same range is announced from many locations at once, so attack traffic enters at the site nearest each bot and is scrubbed there, instead of being carried to our racks in Makati and Singapore.
Animated diagram. Botnets in Europe and the Americas, and a mix of players and bots in Southeast Asia, each send traffic to the anycast site nearest to them, which drops the attack traffic. Only the players' clean traffic continues to Curt Creation's servers in Makati and Singapore, on network AS209612.
This layer is always on, with nothing to switch over when an attack starts. What reaches our edge is your players, plus whatever was too game-like for an upstream filter to judge. That remainder is where our own firewall takes over.
Layer 2: our XDP firewall filters what is left
Volume is only half the problem. An attack small enough to slip past an upstream scrubber can still knock a login server over if every packet looks like it could be a player.
That is the job of the firewall we wrote ourselves. It runs on XDP, a Linux kernel technology that inspects each packet inside the network card's driver, before the operating system spends real work on it. Our firewall can discard millions of packets per second and still have room for players.
For a RanOnline server, that means the firewall knows which traffic belongs to your game and drops everything else before it reaches your machine. It reacts on its own while an attack is under way, so there is no waiting for someone to step in.
Animated flow chart of the XDP firewall. Each packet arriving at the network card is checked in the driver. First: is it for one of your server's ports? If not, it is dropped and counted as "not your ports". Second: does it look like a real RanOnline connection? If not, it is dropped and counted as "not RanOnline". Packets that pass both checks go on to the Linux network stack and then to your RanOnline server.
Every drop is counted and labelled by reason. When you ask what hit your server, we can tell you which kind of attack it was and how big.
Because the firewall is our own code, a new attack pattern is a rule we add, not a ticket we open with a vendor.
What you and your players notice
The goal is that you notice nothing.
- Players stay in game. Legitimate sessions keep flowing while the flood is dropped around them.
- New players can still log in. The login, agent and field ports stay reachable during an attack.
- Nothing to install or switch on. Both layers sit in front of your server and are always active. Your server files and your client stay as they are.
- You get answers afterwards. We can show you what the attack was, how large it got, and where it was stopped.
Host your RanOnline server with us
Size is handled upstream and precision is handled at our edge. Neither layer is enough alone, and together they are why a RanOnline server on Curt Creation stays online when someone decides it should not be.
If you run a RanOnline server, or you are tired of losing players every time a rival attacks, talk to us.

