Spotlight

Case Study Microsoft

How Microsoft scaled global content delivery

Find out how Microsoft used Gcore to strengthen delivery across regions.

case study ProSieben GNTM app TOPSHOT

How ProSieben scaled GNTM's app TOPSHOT

Explore how ProSieben brought real-time AI portraits to GNTM's audience.

case study Higgsfield

How Higgsfield scaled AI video generation

See how Gcore helped Higgsfield scale with GPUs and Managed Kubernetes.

case study Fawkes Games

How Fawkes Games stopped DDoS attacks

See how Gcore protected gaming servers from massive DDoS threats without disrupting gameplay.

We're hiring

Help build the next chapter of the web

We're not just filling seats. We're building a team that will write the next chapter of the internet.

  1. Home
  2. Blog
  3. Edge Proxy: DDoS protection without BGP, LOAs, or GRE tunnels

Edge Proxy: DDoS protection without BGP, LOAs, or GRE tunnels

  • October 6, 2026
  • 3 min read
Edge Proxy: DDoS protection without BGP, LOAs, or GRE tunnels

A rented game server or cloud application may give you little more than an IP address and a port. Traditional routed DDoS protection usually assumes much more: an ASN, your own /24 of IPv4 addresses, a signed Letter of Authorization, and a BGP session or GRE tunnel.

Gcore Edge Proxy removes those requirements. You configure an origin, port, and protocol, and Gcore puts the service behind a protected Anycast IP. Attack traffic is filtered, and legitimate traffic is forwarded to your origin.

Edge Proxy started with game servers. Since September 1, 2026, it has expanded to a much wider range of TCP and UDP services, with generic protection profiles, domain-name origins, PROXY protocol support, and a redesigned self-service portal.

Diagram comparing traditional routed DDoS and Gcore Edge Proxy, noting network ownership.
 Edge Proxy replaces routed-network onboarding with an origin, port, and protocol.

Why game servers were a natural place to start

Game servers have a particular DDoS problem. Players need to know how to reach them, which also makes their addresses easy to target. Yet many communities and independent server operators rent infrastructure and have no ASN, provider-independent IP space, or networking team.

Traditional routed protection is difficult to use in that environment. Asking someone running a Minecraft or FiveM community for all of that can end the onboarding process before protection even begins. With Edge Proxy, players connect to a protected Gcore Anycast address instead of the server itself.

For supported gaming protocols, Edge Proxy can apply filtering designed around the traffic. Profiles are available for Minecraft Java, Counter-Strike 2 and other Source-based games, FiveM, SA-MP, TeamSpeak 3, and Unity networking protocols.

Depending on the profile, Gcore can validate handshakes, use cookie challenges, and cache server queries. Some game query protocols return much larger responses than the requests that trigger them, making them useful to attackers. Caching lets repeated queries be answered at the protection layer instead of repeatedly reaching the game server.

The same constraint exists beyond gaming

The problem is not unique to game servers. You may run a fintech service across leased infrastructure or several cloud environments without controlling the underlying address space. A hosting provider may need to protect individual tenants without advertising a separate network for each one. VPNs and other TCP or UDP services can face the same constraint.

A European trading platform is already using Edge Proxy to protect production TLS services running on provider-assigned addresses across several locations. Edge Proxy never terminates TLS, so certificates and private keys stay with the customer while the service still gets network and transport-layer DDoS protection.

Edge Proxy makes more workloads self-service

Before generic TCP and UDP profiles, a non-gaming application could need Gcore engineers to build a custom profile. Now those profiles sit alongside the game presets, so you can set up many of those services yourself. Custom protection templates remain available for enterprise accounts with more specialised traffic patterns.

The redesigned portal lets you edit origins and use a domain name instead of a fixed IP. Any domain that resolves to a routable public IP works, which helps when the address behind it changes.

PROXY protocol can be enabled per mapping, with v1 and v2 support for TCP and v2 for UDP. That allows applications that need the original client address to receive it even though connections pass through Edge Proxy.

Attacks are filtered before they reach the proxy

Traffic first reaches a Gcore Anycast address and is distributed across Gcore's network. Gcore's DDoS mitigation engine filters attack traffic before it reaches the userspace proxy.

The mitigation engine uses XDP and eBPF to process packets very early in the Linux networking path. Traffic that passes mitigation is handed to Edge Proxy and forwarded to your origin.

For TCP, the mitigation engine can use SYN-cookie validation and connection tracking to handle SYN, ACK, and RST floods. Depending on the protection profile, Gcore can also enforce connection-rate limits, new-client limits, per-source rate limits, access-control rules, and protocol-aware checks.

Ocore network diagram illustrates DDoS mitigation, filtering malicious traffic from legitimate users.

What an L4 proxy can and cannot stop

Edge Proxy is a layer 4, or transport-layer, forwarder. It works with IP and transport headers, connection behaviour, and traffic rates. It does not decrypt the application payload. Volumetric floods and amplification attacks are absorbed by Gcore's Anycast network and DDoS mitigation engine before they reach the proxy.

Edge Proxy does not inspect HTTP requests or provide WAF, bot management, application-layer challenges, or HTTP flood protection. Those are handled by Gcore's WAAP products.

Prevent direct-to-origin attacks

Putting a service behind Edge Proxy does not prevent an attacker from targeting the origin directly if they already know its address. Where possible, Gcore recommends moving the service to a fresh origin IP when you put it behind Edge Proxy.

More importantly, you should firewall the protected ports at the origin so they accept traffic only from Gcore Edge Proxy source addresses. That prevents attackers from bypassing the protected Anycast address and connecting directly to the service.

Pay per protection rule

Since October 1, Edge Proxy uses a self-service pay-as-you-go (PAYG) model priced per translation rule. A rule combines an origin, protocol, port, and protection profile. New customers can start with a two-day free trial.

For current pricing and plan details, see the Edge Proxy page.

Get started

Choose a protection profile, configure your origin, and make sure direct access to that origin is restricted.

Try Edge Proxy or read the Edge Proxy setup documentation.




 

Related articles

Silver shield with an orange padlock and a banner reading Cybersecurity Month.
Take control of your traffic: Cybersecurity Month at Gcore

October is Cybersecurity Awareness Month. At Gcore, we’re marking it with a range of activities to help you understand security threats and protect your websites, applications, and infrastructure. The data is clear on why this topic is more

A global distributed network showing multiple servers connected across a world map outline.
How Gcore Built a Global Private Backbone Across Three Continents

Gcore's CDN, cloud, and AI services increasingly need to move traffic between regions, sometimes across continents. For customers, those journeys should be largely invisible: applications need predictable connectivity whether traffic is mov

A digital dashboard displays various data visualizations and the collaboration text 'Gcore x AVEQ'.
When the numbers lie: A CDN diagnostics case study

Real streaming problems rarely show up with a label on them. The broadcaster's ops team is fielding complaints. A dashboard glows with elevated stall counts. Meanwhile the CDN logs look perfectly healthy — latency is nominal, cache hits are

Sifted 100 France & Benelux 2026 announcement with falling confetti and spotlights.
Gcore named in Sifted Top 100 France & Benelux 2026

Gcore has been recognized as one of the top 100 fastest-growing technology startups in France and Benelux by Sifted — one of Europe's leading tech publications. Our inclusion in the B2B SaaS & Cloud Infrastructure category points to ris

GCORE Connect logo on a vibrant orange background with a subtle network pattern.
Gcore Connect: discussing the future of AI in Europe

The first-ever Gcore Connect forum took place on 6 and 7 July 2026 in Luxembourg. Held in collaboration with Nokia, Dell, and VAST, it brought together policymakers, academics, and business leaders. The invite-only event, hosted at the Muda

World Cup 2026 Streaming Roundup text with a stylized soccer stadium and ball.
How various audiences viewed the World Cup via Gcore

Gcore's content delivery network (CDN) was the backbone behind many broadcasters and live streams at the recent 2026 World Cup, and we observed some interesting stats on how tournament viewing habits differed across the five regions where w

Subscribe to our newsletter

Get the latest industry trends, exclusive insights, and Gcore updates delivered straight to your inbox.