Edge Proxy: DDoS protection without BGP, LOAs, or GRE tunnels
- October 6, 2026
- 3 min read

A rented game server or cloud application may give you little more than an IP address and a port. Traditional routed DDoS protection usually assumes much more: an ASN, your own /24 of IPv4 addresses, a signed Letter of Authorization, and a BGP session or GRE tunnel.
Gcore Edge Proxy removes those requirements. You configure an origin, port, and protocol, and Gcore puts the service behind a protected Anycast IP. Attack traffic is filtered, and legitimate traffic is forwarded to your origin.
Edge Proxy started with game servers. Since September 1, 2026, it has expanded to a much wider range of TCP and UDP services, with generic protection profiles, domain-name origins, PROXY protocol support, and a redesigned self-service portal.

Why game servers were a natural place to start
Game servers have a particular DDoS problem. Players need to know how to reach them, which also makes their addresses easy to target. Yet many communities and independent server operators rent infrastructure and have no ASN, provider-independent IP space, or networking team.
Traditional routed protection is difficult to use in that environment. Asking someone running a Minecraft or FiveM community for all of that can end the onboarding process before protection even begins. With Edge Proxy, players connect to a protected Gcore Anycast address instead of the server itself.
For supported gaming protocols, Edge Proxy can apply filtering designed around the traffic. Profiles are available for Minecraft Java, Counter-Strike 2 and other Source-based games, FiveM, SA-MP, TeamSpeak 3, and Unity networking protocols.
Depending on the profile, Gcore can validate handshakes, use cookie challenges, and cache server queries. Some game query protocols return much larger responses than the requests that trigger them, making them useful to attackers. Caching lets repeated queries be answered at the protection layer instead of repeatedly reaching the game server.
The same constraint exists beyond gaming
The problem is not unique to game servers. You may run a fintech service across leased infrastructure or several cloud environments without controlling the underlying address space. A hosting provider may need to protect individual tenants without advertising a separate network for each one. VPNs and other TCP or UDP services can face the same constraint.
A European trading platform is already using Edge Proxy to protect production TLS services running on provider-assigned addresses across several locations. Edge Proxy never terminates TLS, so certificates and private keys stay with the customer while the service still gets network and transport-layer DDoS protection.
Edge Proxy makes more workloads self-service
Before generic TCP and UDP profiles, a non-gaming application could need Gcore engineers to build a custom profile. Now those profiles sit alongside the game presets, so you can set up many of those services yourself. Custom protection templates remain available for enterprise accounts with more specialised traffic patterns.
The redesigned portal lets you edit origins and use a domain name instead of a fixed IP. Any domain that resolves to a routable public IP works, which helps when the address behind it changes.
PROXY protocol can be enabled per mapping, with v1 and v2 support for TCP and v2 for UDP. That allows applications that need the original client address to receive it even though connections pass through Edge Proxy.
Attacks are filtered before they reach the proxy
Traffic first reaches a Gcore Anycast address and is distributed across Gcore's network. Gcore's DDoS mitigation engine filters attack traffic before it reaches the userspace proxy.
The mitigation engine uses XDP and eBPF to process packets very early in the Linux networking path. Traffic that passes mitigation is handed to Edge Proxy and forwarded to your origin.
For TCP, the mitigation engine can use SYN-cookie validation and connection tracking to handle SYN, ACK, and RST floods. Depending on the protection profile, Gcore can also enforce connection-rate limits, new-client limits, per-source rate limits, access-control rules, and protocol-aware checks.

What an L4 proxy can and cannot stop
Edge Proxy is a layer 4, or transport-layer, forwarder. It works with IP and transport headers, connection behaviour, and traffic rates. It does not decrypt the application payload. Volumetric floods and amplification attacks are absorbed by Gcore's Anycast network and DDoS mitigation engine before they reach the proxy.
Edge Proxy does not inspect HTTP requests or provide WAF, bot management, application-layer challenges, or HTTP flood protection. Those are handled by Gcore's WAAP products.
Prevent direct-to-origin attacks
Putting a service behind Edge Proxy does not prevent an attacker from targeting the origin directly if they already know its address. Where possible, Gcore recommends moving the service to a fresh origin IP when you put it behind Edge Proxy.
More importantly, you should firewall the protected ports at the origin so they accept traffic only from Gcore Edge Proxy source addresses. That prevents attackers from bypassing the protected Anycast address and connecting directly to the service.
Pay per protection rule
Since October 1, Edge Proxy uses a self-service pay-as-you-go (PAYG) model priced per translation rule. A rule combines an origin, protocol, port, and protection profile. New customers can start with a two-day free trial.
For current pricing and plan details, see the Edge Proxy page.
Get started
Choose a protection profile, configure your origin, and make sure direct access to that origin is restricted.
Related articles
Subscribe to our newsletter
Get the latest industry trends, exclusive insights, and Gcore updates delivered straight to your inbox.










