Does REXE Apply Null Route? DDoS Protection Policy
REXE Technology and Path.net null route policy: With 10Tbps+ capacity, your server stays protected regardless of attack size — no null routing ever applied.
Table of Contents
Introduction
Null route (blackhole routing) is a method some hosting providers use during large DDoS attacks. All traffic to the attacked IP address — including legitimate traffic — is completely blocked, making the server inaccessible.
REXE Technology does not apply null routing.
Regardless of attack size, your server continues to be protected. Your legitimate users maintain uninterrupted access.
Why We Don't Null Route
10Tbps+ Global Network Capacity
Path.net has over 10Tbps of global network capacity. This massive capacity allows even the largest volumetric attacks to be absorbed.
Traditional Hosting:
Attack > Capacity → Null Route → Server Inaccessible
REXE + Path.net:
Attack > Any size → Filtering → Server Protected
Stateful Application/Game Filters
Path.net's stateful filtering technology works by understanding application and game protocols:
- Legitimate traffic is recognized and passed through
- Attack traffic is detected and blocked
- No packet loss or connection interruption
Stateful filtering tracks the state of every connection. This automatically blocks spoofed packets.
Protection Against the Most Sophisticated Attacks
Path.net filters protect against the following attack types:
| Attack Type | Protection Method |
|---|---|
| UDP Flood | Protocol validation + rate limiting |
| SYN Flood | SYN cookie + stateful tracking |
| DNS Amplification | Source validation + filtering |
| NTP Amplification | Protocol analysis + blocking |
| TCP ACK Flood | Connection state validation |
| Application Layer (L7) | Application protocol analysis |
| GRE/IP-in-IP | Protocol filtering |
Comparison with Other Providers
| Feature | REXE + Path.net | Traditional Hosting |
|---|---|---|
| Null Route | Never applied | Applied based on attack size |
| Protection Capacity | 10Tbps+ | Usually 1-10 Gbps |
| Filtering | Stateful, protocol-based | Basic rate limiting |
| Game Filters | Yes, game-specific | Usually none |
| Packet Loss | None | Possible during attacks |
| Extra Cost | Included in plan | Usually extra charge |
Some hosting providers offer "DDoS protection" but apply null route above a certain threshold. REXE has no such threshold.
What Happens During an Attack?
- Attack detected: Attack traffic is automatically detected in Path.net's global network
- Traffic scrubbed: Attack traffic is filtered, legitimate traffic passes through
- Server protected: Only clean traffic reaches your server
- Notification: Attack details are displayed in the Path Panel attack history
Attack Start → Automatic Detection (< 1 second)
→ Traffic Scrubbing (Path.net Global POP)
→ Clean Traffic Delivery (REXE Servers)
→ Attack Logs (Path Panel)
Why Null Route Is Harmful
When null route is applied, legitimate user traffic is blocked along with attack traffic. This leads to:
- Service outage: Real users cannot access the server
- Revenue loss: E-commerce, game servers, or SaaS services go offline
- Reputation damage: Customers perceive the service as unreliable
- Attacker wins: The DDoS attack achieves its goal of service disruption
With REXE + Path.net architecture, null route is never applied. Regardless of attack size, only attack traffic is blocked; legitimate users maintain uninterrupted access.
Path.net's global anycast network absorbs attack traffic at the point closest to the source. This means attack traffic is cleaned before it even reaches REXE data centers.
Path.net Global Network Architecture
The technical infrastructure behind Path.net's ability to absorb DDoS attacks without null routing:
Anycast Network Structure
Path.net uses distributed anycast POP (Point of Presence) nodes worldwide. This structure ensures:
- Attack traffic is absorbed at the POP node closest to the source
- Attack traffic is cleaned before reaching REXE data centers
- Geographic distribution prevents load concentration at a single point
Hardware-Level Filtering
Path.net filters operate at the hardware level, not software:
- FPGA and ASIC based filtering hardware is used
- Billions of packets per second can be processed
- Filtering occurs with near-zero latency
- Server CPU is not affected by filtering load
Automatic Attack Detection
Path.net's machine learning-powered attack detection system:
- Detects attacks in under 1 second
- Automatically learns new attack vectors
- Monitored by a 24/7 NOC team
Conclusion
REXE Technology and Path.net partnership is one of the rare providers offering real DDoS protection without null routing. With 10Tbps+ global network capacity, stateful filtering technology, and 24/7 NOC support, your server stays protected under all conditions.
Regardless of attack size — from a small UDP flood to a large amplification attack — Path.net's filtering infrastructure absorbs attack traffic and ensures only legitimate traffic reaches your server. This means uninterrupted service for game servers, web applications, and critical infrastructure.
For more information, check our Path Panel guide or attack logs guide. You can also view real-time attack statistics in the Path Panel Dashboard.
Related Articles
Path Panel DDoS Protection Management Panel User Guide
Complete REXE Path Panel user guide: Dashboard, My IPs, TR protection status, rule management, attack history, abuse filtered, password change and API access.
Game Server DDoS Filter Selection Guide (Path.net)
Path.net DDoS protection game filters guide: Arma/DayZ, Source Engine, CS:GO, CS2, FiveM, Minecraft, Rust and more — how to apply each filter.
Application and Service DDoS Filter Guide (Path.net)
Path.net DDoS protection application filters guide: OpenVPN, Wireguard, DTLS, RTP, QUIC, SIP, TCP Symmetric and more — how to choose the right filter.