Path Panel DDoS Protection Management Panel User Guide
Complete REXE Path Panel user guide: Dashboard, My IPs, TR protection status, rule management, attack history, abuse filtered, password change and API access.
REXE Technology remote protection service GRE tunneling support, L2 circuit connection, setup process, and Path.net integration — comprehensive guide.
GRE (Generic Routing Encapsulation) tunneling is a method of encapsulating traffic by creating a virtual tunnel between two network points. DDoS protection providers use GRE tunnels to offer remote protection services.
REXE Technology supports GRE tunneling as part of its remote protection service.
GRE tunnels can only be set up by the REXE team via the Path panel. Customers cannot set up GRE tunnels on their own.
Using a server rented from REXE as an entry point to carry protection to a system outside REXE is prohibited. This covers:
Remote protection is provided by REXE only. If you want to protect a server at an external location, the REXE team sets up the configuration through the Path panel. Tunnel or proxy solutions built by the customer violate the terms of service and lead to service suspension.
The restriction is not arbitrary: filter rules and protection capacity are allocated per IP. Moving traffic outside REXE invalidates attack reports, null-route decisions and SLA measurement; once an attack targets the far end of your tunnel rather than your server, there is nothing left for REXE to see or act on.
If your server is located outside the REXE data center, the REXE team configures a GRE tunnel as part of the remote protection service:
Internet Traffic
↓
Path.net Global POP (Traffic Scrubbing)
↓
GRE Tunnel (Configured by REXE)
↓
Customer Server (External Location)
Key points:
If your server is hosted in the REXE data center, GRE tunneling is not needed. Your server is directly connected to the Path.net infrastructure via an L2 (Layer 2) circuit:
Internet Traffic
↓
Path.net Global POP (Traffic Scrubbing)
↓
L2 Circuit Connection (Low Latency)
↓
REXE Data Center (Your Server)
Benefits:
If your server is in the REXE data center, an L2 circuit connection is used. If it's at an external location, the REXE team configures a GRE tunnel for you.
GRE (Generic Routing Encapsulation), defined in RFC 2784, works as follows in the DDoS protection context:
When using a GRE tunnel, the MTU value decreases:
Standard Ethernet MTU: 1500 bytes
GRE Header: 24 bytes
GRE Tunnel MTU: 1476 bytes
This can cause issues with some applications. The REXE team optimizes MTU settings during GRE tunnel setup.
GRE tunnels can only be set up by the REXE team. Customers do not have the ability to set up GRE tunnels on their own servers. Contact our support team for remote protection services.
If your server is hosted at a location other than the REXE data center:
By migrating your existing server to the REXE data center, you can benefit directly from Path.net protection:
You can host your own hardware in the REXE data center:
| Feature | GRE Tunnel | L2 Circuit (REXE DC) |
|---|---|---|
| Latency | +1-3ms extra | Minimum latency |
| MTU | 1476 bytes | 1500 bytes |
| Setup | By REXE team | Automatic |
| Location | External servers | REXE data center |
| Cost | May require extra fee | Included in plan |
For best performance, we recommend hosting your server in the REXE data center. L2 circuit connection provides lower latency and higher MTU compared to GRE tunneling.
Steps to follow to get remote protection with a GRE tunnel:
You do not need to make any changes on your server for GRE tunnel setup. All configuration is done by the REXE team via the Path panel.
Yes, REXE supports GRE tunneling as part of its remote protection service. However, GRE tunnels can only be set up by the REXE team via the Path panel — customers cannot set up GRE tunnels on their own.
No. GRE tunnels are configured exclusively by the REXE team. Setting up your own tunnel on a server rented from REXE, proxying traffic through it, or carrying protection to a system outside REXE is prohibited and leads to service suspension.
No. Carrying traffic to a destination outside REXE via tunnel, reverse proxy, NAT or port forwarding is prohibited. For a server at an external location, remote protection is provided only by REXE, through the configuration the REXE team sets up on the Path panel.
Yes, if your server is at an external location, the REXE team configures a GRE tunnel to provide remote DDoS protection. Contact our support team.
Complete REXE Path Panel user guide: Dashboard, My IPs, TR protection status, rule management, attack history, abuse filtered, password change and API access.
Path.net DDoS protection game filters guide: Arma/DayZ, Source Engine, CS:GO, CS2, FiveM, Minecraft, Rust and more — how to apply each filter.
Path.net DDoS protection application filters guide: OpenVPN, Wireguard, DTLS, RTP, QUIC, SIP, TCP Symmetric and more — how to choose the right filter.