Game Server DDoS Filter Selection Guide (Path.net)
Path.net DDoS protection game filters guide: Arma/DayZ, Source Engine, CS:GO, CS2, FiveM, Minecraft, Rust and more — how to apply each filter.
Table of Contents
Introduction
REXE Technology offers game-specific DDoS filters through the Path.net infrastructure. These filters analyze traffic specific to game protocols, allowing legitimate player connections while blocking attack traffic.
Game filters can be selected from the "Filter" field when creating rules in the Path Panel.
Supported Game Filters
Arma / DayZ
| Game | Protocol | Default Port |
|---|---|---|
| Arma 3 Multiplayer Server | UDP | 2302-2306 |
| DayZ Server | UDP | 2302-2306 |
This filter recognizes Arma/DayZ protocol-specific packets, blocking spoofed query packets and UDP flood attacks.
HL2 / Source Engine
| Game | Protocol | Default Port |
|---|---|---|
| Half-Life 2 | UDP | 27015 |
| Team Fortress 2 | UDP | 27015 |
| Counter-Strike: Source | UDP | 27015 |
HLDS / GoldSrc
| Game | Protocol | Default Port |
|---|---|---|
| Half-Life 1 | UDP | 27015 |
| Counter-Strike 1.6 | UDP | 27015 |
| Ricochet | UDP | 27015 |
L4D2 / CS:GO
| Game | Protocol | Default Port |
|---|---|---|
| Counter-Strike 2 (CS2) | UDP | 27015 |
| Counter-Strike: Global Offensive | UDP | 27015 |
| Left 4 Dead 2 | UDP | 27015 |
| Portal 2 | UDP | 27015 |
Use this filter for CS2 servers. It provides effective protection against Source Engine Query flood attacks.
Grand Theft Auto (SA-MP / FiveM)
| Game | Protocol | Default Port |
|---|---|---|
| SA-MP Server Queries | UDP | 7777 |
| GTA V Multiplayer (FiveM) | UDP | 30120 |
FiveM servers require both TCP (30120) and UDP (30120) filter rules. txAdmin panel also needs TCP 40120.
Source Engine Queries
Comprehensive filter for all games using the Source Engine query protocol: CS 1.6, TF2, Garry's Mod, Rust, ARK: Survival Evolved, and all HL1/HL2 based games.
This filter validates A2S_INFO and A2S_PLAYER Source Engine query packets, blocking spoofed queries.
RakNet
| Game | Protocol | Default Port |
|---|---|---|
| Rust | UDP | 28015 |
| Minecraft Bedrock Edition (Geyser) | UDP | 19132 |
Minecraft Java Edition
| Game | Protocol | Default Port |
|---|---|---|
| Minecraft Java Edition | TCP | 25565 |
This filter validates Minecraft protocol handshake and login packets, blocking bot attacks and TCP floods.
Filter Selection Table
Not sure which filter to use? Reference this table:
| Game / Platform | Recommended Filter | Protocol | Port |
|---|---|---|---|
| CS2 / CS:GO | L4D2 / CS:GO | UDP | 27015 |
| FiveM | GTA FiveM | UDP+TCP | 30120 |
| Minecraft Java | Minecraft Java Edition | TCP | 25565 |
| Minecraft Bedrock | RakNet | UDP | 19132 |
| Rust | RakNet | UDP | 28015 |
| Garry's Mod | Source Engine Queries | UDP | 27015 |
| ARK: Survival | Source Engine Queries | UDP | 27015 |
| DayZ | Arma / DayZ | UDP | 2302 |
| SA-MP | GTA SA-MP | UDP | 7777 |
How to Apply Filters
- Log in to Path Panel (my.rexe.tr → Path Panel)
- Click on your server IP in IP Management
- Click Create New Rule
- Fill in the details:
Protocol: UDP (or TCP, depending on game)
Destination Port: Game's default port
Filter: Select the appropriate game filter
Comment: Descriptive note like "FiveM game filter"
- Save and wait for propagated status (2-5 min)
Make sure to select the correct filter for your game. An incorrect filter may block legitimate player traffic.
How Game Filters Work
Path.net game filters learn the packet structure of each game protocol. For example:
- Minecraft filter: Validates the handshake packet sent by a real Minecraft client. Bot attacks cannot pass this validation.
- Source Engine filter: Validates A2S_INFO queries. Spoofed query floods are blocked.
- FiveM filter: Recognizes packets specific to the GTA V multiplayer protocol.
This ensures your players experience no interruption while attackers cannot reach your server.
Game filters only apply to the specified port and protocol combination. Create separate rules for different ports.
Frequently Asked Questions
My game is not in the list, what should I do?
For games not in the list, you can use a general TCP or UDP filter. If you need a custom filter, contact our support team to request one for your specific game.
Can multiple games run on the same server?
Yes, by creating separate rules for each game port, you can protect multiple game servers on the same IP address.
Do game filters affect performance?
No, Path.net filters operate at the hardware level and add no measurable latency to game traffic. Your players continue playing without interruption while attack traffic is automatically cleaned.
How long does it take for a filter rule to become active?
After creating a rule, it takes 2-5 minutes to reach the propagated status and become fully active across all network points.
Related Articles
Path Panel DDoS Protection Management Panel User Guide
Complete REXE Path Panel user guide: Dashboard, My IPs, TR protection status, rule management, attack history, abuse filtered, password change and API access.
Application and Service DDoS Filter Guide (Path.net)
Path.net DDoS protection application filters guide: OpenVPN, Wireguard, DTLS, RTP, QUIC, SIP, TCP Symmetric and more — how to choose the right filter.
Does REXE Apply Null Route? DDoS Protection Policy
REXE Technology and Path.net null route policy: With 10Tbps+ capacity, your server stays protected regardless of attack size — no null routing ever applied.