Spotlight

Case Study Microsoft

How Microsoft scaled global content delivery

Find out how Microsoft used Gcore to strengthen delivery across regions.

case study ProSieben GNTM app TOPSHOT

How ProSieben scaled GNTM's app TOPSHOT

Explore how ProSieben brought real-time AI portraits to GNTM's audience.

case study Higgsfield

How Higgsfield scaled AI video generation

See how Gcore helped Higgsfield scale with GPUs and Managed Kubernetes.

case study Fawkes Games

How Fawkes Games stopped DDoS attacks

See how Gcore protected gaming servers from massive DDoS threats without disrupting gameplay.

We're hiring

Help build the next chapter of the web

We're not just filling seats. We're building a team that will write the next chapter of the internet.

Edge Proxy

Stop DDoS attacks at the edge. Before they reach your origin.

Keep users connected to the TCP and UDP services they rely on, even when attacks hit. Start with an IP and port, without owning or rebuilding the network around it.

  • Red pepper or chili emoji icon with green stem on white background.FREE Trial
  • Red circular icon with a white radiating sun or burst symbol in the center.Start in 2 minutes
  • Red lightning bolt icon symbolizing electricity, power, or a flash alert.No ASN or BGP required
A shield protects a server from incoming DDoS attack bombs, ensuring secure user connections.
POWERING TEAMS AT
Microsoft logo with a four-color square icon and the word "Microsoft" in gray text.
RTL logo with red, green, blue, and pink squares containing white letters R, T, L, and a colon.
Black square logo icon next to the text "LETZ.AI" in bold black letters on a white background.
Wargaming.net logo with the slogan "Let's Battle" beneath a stylized black bird/griffin emblem.
Logo for StageAudioWorks Technology + Engineering Group, featuring bold text and a horizontal line design.
Leaseweb logo featuring a blue and orange triangular icon beside the company name in dark blue text.

The origin is yours. The route may not be.

Broad controls force you to choose between wasted capacity and blocked users.

You cannot announce what you do not own
— NO ROUTE CONTROL

You cannot announce what you do not own

Your service is live, but the IP address belongs to your provider. Traditional DDoS protection cannot reroute traffic for an address you do not control.

Protection becomes a network project
— SETUP BEFORE PROTECTION

Protection becomes a network project

What should be a security decision turns into paperwork, approvals, and network changes. Protection waits while your team works through ASN, LOA, and GRE requirements.

Your origin becomes the first line of defense
— ORIGIN STAYS EXPOSED

Your origin becomes the first line of defense

Attackers do not care who owns the network. If traffic reaches your origin first, every spike puts availability, users, and your team under pressure.

Protection starts with an IP and a port

Keep your service where it runs and add protection without rebuilding the network.

ADD YOUR ORIGIN

01

Connect the service you already run

Enter your origin IP, port, and protocol, then choose a profile that fits its traffic.

GET PROTECTED

02

Receive a protected Anycast address

Get a Gcore Anycast IP that becomes the protected public address for your service.

MOVE TRAFFIC

03

Give users a protected path to your service

Point traffic to the protected address. Edge filtering sends clean traffic to your origin.

Protection should fit your service.
Not the other way around.

Keep your origin where it is, match filtering to real traffic, and scale by Proxy Mapping instead of attack volume.

STAY REACHABLE
Keep attacks off your bill

Keep real users connected

Let legitimate traffic keep reaching your service while attack traffic is filtered before the origin.

Anycast ingressTCP and UDPEdge filtering
LESS NETWORK WORK
Get protected without rerouting

Get protected without rerouting

Add protection without owning a network, configuring BGP, or building a GRE tunnel around your service.

No ASNNo BGPNo GRE tunnel
FIT YOUR TRAFFIC
Match protection to your service

Match protection to your service

Choose a profile shaped around the TCP, UDP, game, or custom protocol your service actually uses.

Protocol-aware profilesCustom profiles
PREDICTABLE COSTS
Keep attacks off your bill

Keep attacks off your bill

Pay for the Proxy Mappings you use, not attack traffic or every gigabyte that passes through.

Proxy Mapping pricingAttack traffic not billed
ONE STACK

Big attacks need
a bigger network

When attack traffic surges, your service should not have to absorb it. Gcore’s global edge and DDoS filtering take the pressure first, so clean traffic can keep moving.

210+

edge PoPs worldwide

200Tbps

DDoS filtering capacity

≈12Tbps

largest reflected attack

14k+

peering partners

The network takes the pressure.
You keep the control.

Choose how traffic is filtered, forwarded, and observed, then add custom profiles or private paths when your setup demands more.

Match protection to traffic
TRAFFIC FIT
Match protection to traffic

Choose game-specific or generic TCP and UDP profiles so filtering starts with the traffic your service expects.

Game profilesGeneric TCP/UDP
Preserve the real client IP
CLIENT IDENTITY
Preserve the real client IP

Pass the original client IP to compatible TCP backends with PROXY protocol v1 or v2.

PROXY v1/v2Per mapping
Tune protection around risk
CUSTOM CONTROL
Tune protection around risk

Shape custom profiles around proprietary traffic with rate limits, ACLs, and country controls.

Custom profilesACLsRate limits
Manage more endpoints
PRIVATE DELIVERY
Keep the path private

Connect eligible origins through PNI or Direct Connect when the public path is not the right fit.

Shield modePNIDirect Connect
Keep the path private
TRAFFIC VISIBILITY
See what protection handles

Review traffic and protection statistics so your team can see what reaches the service.

Traffic statisticsPer endpoint
See what protection handles
FLEET SCALE
Manage more endpoints

Provision Proxy Mappings through the API and raise account limits as your service footprint grows.

REST APILimit overrides

Different traffic. Different stakes.
One protected path.

Give the moments your customers remember the speed, resilience, and control they need to hold up under pressure.

FINTECH

Keep critical transactions moving

Run TCP and TLS services through protected ingress without handing over private keys or terminating encryption at the edge.

End-to-end TLSPROXY protocol
Keep critical transactions moving
CONTROLLED ACCESS

Keep access inside approved boundaries

Limit traffic by country and apply custom rate controls when your service needs tighter access rules.

Custom profilesCountry controls
Keep access inside approved boundaries
CLOUD

Protect services without route control

Add protected ingress to cloud VMs and hosted services even when the provider controls the addressing and routing.

Provider-assigned IPsAnycast ingress
Protect services without route control
HOSTING

Keep one target from affecting everyone

Give each tenant endpoint its own Proxy Mapping and profile so one attack does not pressure the wider fleet.

Per-tenant mappingsREST API
Keep one target from affecting everyone
NETWORKING

Keep relay and matchmaking fleets reachable

Protect growing fleets with engine-aware profiles, Proxy Mappings, and API provisioning.

Engine profilesFleet provisioning
Keep relay and matchmaking fleets reachable
CUSTOM APPs

Protect protocols beyond the catalogue

Build custom profiles around VPNs, proprietary protocols, and other non-HTTP services when standard filtering does not fit.

Geo-aware routingCustom Rules
Protect protocols beyond the catalogue
ONE STACK

Stop attacks. Keep adventures moving.

Floods, fake handshakes, and protocol abuse should not interrupt gameplay or push players off your server. Add game-aware protection in minutes, with no engineering required.

    Start in 2 minutes
    Game-specific protection profiles
    Attack traffic not billed
  • TCP and UDP support
A shield with a padlock secures a cloud, servers, and an AI chip, illustrating data protection.

Your bill should not grow with the attack.

PAYG
17€/ per month

for the 1st month. Renews at €9/mo. No commitment. Cancel anytime.

2-day free trial
Unmetered attack capacity
Setup under 2 minutes
Gaming-optimized presets
TCP/UDP application support
1 rule = 1 protected app
1 proxy rule included

Add proxy rules anytime

Rules 2-5€10/mo
Rules 6-10€8/mo
Rules 11+€6/mo

Make the edge your first line of defense

Your service has users to serve. Let us handle the attacks.

FREE trial available · Start in 2 minutes

Frequently asked Questions

Everything you need to know about Edge Proxy.

Getting Started
Edge Proxy is DDoS-protected Layer 4 ingress for TCP and UDP services. It filters attack traffic at Gcore’s edge and forwards clean traffic to your origin.
Add your origin IP, port, protocol, and protection profile. No ASN, /24, LOA, BGP, or GRE tunnel is required.
A standard setup can be activated in about two minutes through the Gcore Customer Portal.
Pricing is based on Proxy Mappings. Each mapping connects one origin, protocol, port, and protection profile. Attack traffic is not billed.
Capabilities and product fit
Protect game servers, TCP and TLS services, cloud workloads, relay fleets, and custom TCP or UDP applications. Proprietary protocols may need a custom profile.
Yes. Compatible TCP origins can receive the original client IP through PROXY protocol v1 or v2.
They can target an origin that remains directly reachable. Restrict direct access to the origin and publish the protected address to prevent bypass.
No. Keep your existing cloud, hosted, or on-premises origin and point traffic to the protected Edge Proxy address.