In Network Security
Uninterrupted Protection
We analyze your traffic in real time, stop attacks before they start, and maintain clean traffic flow with low latency. Location-independent protection via direct connection, L2 circuit, or GRE tunneling.
High-Capacity Protection
with Global Backbone
Our infrastructure architecture works with a traffic scrubbing approach through global carriers and POP points. This way, traffic is separated at the nearest point during an attack and clean traffic is delivered to you.
Deep Analysis + Dynamic Rules
The protection strategy changes instantly based on the type and intensity of the attack. In UDP/TCP Layer 4 attacks and network-level Layer 7 attacks, your traffic is separated and delivered as "clean traffic".
Our Service Points
Your traffic is scrubbed at the nearest point; low latency is maintained.
Setup Process
Contact → Setup → Filtering → Seamless Network
Share your network and needs; let's determine the right solution for you.
Fast activation with direct connection, L2 circuit, or GRE tunnel setups.
Malicious traffic is separated; clean traffic is safely delivered to you.
After setup, your network stays under continuous protection against attacks.
Connection Options & Symmetric Routing
We offer three different connection methods for delivering clean traffic to customers. REXE is directly connected to Path.net infrastructure via L2 circuit .
REXE is directly connected to Path.net infrastructure via Layer 2 circuit. Lowest latency, highest reliability. Traffic is transmitted transparently.
- Lowest latency
- High reliability
- Transparent traffic transmission
Physical connection in the same data center or via cross-connect. No IP change required, clean traffic delivery with low latency.
- No IP change required
- Physical security
- Fast activation
Your server is protected regardless of its physical location. No IP change required, traffic is tunneled and scrubbed transparently.
- Location independent
- No IP change required
- Fast activation (< 1 hour)
Incoming (ingress) and outgoing (egress) traffic passes through the same protection line. Stateful inspection issues, false blocking, and log inconsistencies experienced in asymmetric routing are completely eliminated.
- Stateful inspection works correctly
- False-positive risk minimized
- Consistent traffic logs
Supported DDoS Filters
All filters below are Layer7 hard filter options: each recognises the packet structure of its protocol and tracks connection state. Filter rules are managed from the REXE panel; for each port you define either a standard rule or a suitable L7 filter.
Game Protocol Filters
Game filters operate at Layer7: they recognise each game protocol's packet structure, passing legitimate player connections while separating attack traffic arriving on the same port.
| Filter | Protocol | Default port | Usage |
|---|---|---|---|
| Arma / DayZ | UDP | 2302–2306 | Arma 3, DayZ |
| HL2 / Source Engine | UDP | 27015 | Half-Life 2, TF2, CS:Source |
| HLDS / GoldSrc | UDP | 27015 | Half-Life 1, CS 1.6 |
| L4D2 / CS:GO | UDP | 27015 | CS2, CS:GO, L4D2, Portal |
| GTA SA-MP / FiveM | UDP | 7777 / 30120 | SA-MP, FiveM |
| Source Engine Queries | UDP | 27015 | Tüm Source Engine oyunları |
| RakNet | UDP | 28015 / 19132 | Rust, Minecraft Bedrock |
| Minecraft Java Edition | TCP | 25565 | Minecraft Java |
Application and Protocol Filters
Protocol-aware Layer7 filters can be defined for VPN, VoIP, WebRTC and general TCP services.
| Filter | Protocol | Default port | Usage |
|---|---|---|---|
| OpenVPN UDP Server | UDP | 1194 | OpenVPN sunucu koruması |
| Wireguard Server | UDP | 51820 | Wireguard VPN koruması |
| DTLS Server | UDP | — | WebRTC, IoT, güvenli UDP |
| RTP Server | UDP | — | VoIP, video konferans, medya streaming |
| STUN Server | UDP | 3478 | NAT traversal, WebRTC |
| QUIC Server | UDP | 443 | HTTP/3, modern web uygulamaları |
| SIP Server | UDP | 5060 | VoIP telefon sistemleri |
| TCP Service | TCP | — | Genel TCP servis koruması |
| TCP Service (Symmetric) | TCP | — | SSH, RDP ve tüm TCP servisleri |
Standard Filter and Hard (L7) Filter
There are two modes when creating a rule. In the standard filter you enter only protocol and port; that rule is also filtered and tracks connection state. In the hard filter you select one of the game or application filters above. State tracking exists in both modes; there is no protection mode without state tracking.
The only difference of the hard filter is that application-specific packets are inspected from the application's initial handshake through the entire packet flow. Since standard filters achieve roughly 99.99% filtering success, the hard filter is rarely needed in practice. No filter is a WAF; none provide in-application security (SQL injection, XSS) — the scope is network and protocol level.
Frequently Asked Questions About DDoS Protection
Is DDoS protection included by default?
Without the optional protection, the default L3/L4 protection covers only traffic arriving from abroad. With the optional protection, both domestic and international traffic are protected and the IP stays on a protected route continuously.
Where can I see attack reports?
Attack reports, filter and rule management are handled through REXE's own panel. Customers do not connect directly to the Path.net panel.
Is Layer7 filtering a WAF?
No. All game and application filters operate at Layer7: they recognise the protocol's packet structure and track connection state. In the hard filter, application-specific packets are additionally inspected from the initial handshake onward. However this is not a WAF; it does not protect against in-application attacks such as SQL injection or XSS.
Does protection activate only during an attack?
The optional protection is always-on: the IP stays on a protected route continuously and no attack threshold is awaited. This removes the first-minutes outage risk seen in threshold-based systems.
What is my filtering capacity?
No artificial per-customer filtering capacity limit is applied. Protectable traffic is bounded by REXE's total local and global protection capacity. There is also no separate per-customer limit defined for clean traffic.
What happens if I choose the wrong filter?
A filter that does not match your service can block legitimate traffic. For each port you should define either a standard rule or an L7 filter matching the protocol. No false positives have occurred to date; should one occur, resolution takes 2-3 business days on average.