Cafora Docs
Security

DDoS Protection

How Cafora uses TCPShield Sentry and Cloudflare Tunnel as layered entry points for enterprise-grade DDoS protection on Minecraft and SFTP.

DDoS (Distributed Denial of Service) attacks are one of the most common threats to Minecraft servers. Cafora uses a layered entry architecture: game traffic and file-transfer traffic are scrubbed by TCPShield Sentry and returned over a dedicated VXLAN link, while panel and API traffic is handled by Cloudflare Tunnel.

The guiding principle is simple: the origin IP never serves Minecraft or SFTP directly.

What is a DDoS Attack?

A DDoS attack floods a server with malicious traffic, overwhelming its resources and preventing legitimate players from connecting. Minecraft servers are frequently targeted because:

  • Game servers require low-latency, always-on connections
  • Server addresses are publicly visible
  • Attack tools are widely available

Types of Attacks

Volumetric Attacks

Massive amounts of traffic saturate the network connection. Measured in Gbps or packets per second (pps).

TCP Attacks

Exploit the TCP handshake process:

  • SYN Flood — Overwhelms with connection requests that never complete
  • ACK Flood — Spoofed acknowledgment packets
  • Connection Exhaustion — Opens and holds thousands of connections

UDP Attacks

Target the UDP protocol used by Minecraft for query responses and Bedrock Edition. Common types include UDP floods and amplification attacks.

Application-Layer (L7) Attacks

Target Minecraft-specific services rather than network infrastructure. These attacks mimic legitimate player behavior at scale.

Layered Entry Architecture

Rather than placing a single proxy in front of everything, Cafora splits entry points by traffic plane:

Traffic planeEntry pointProtocol & port
Panel / Wings APICloudflare TunnelHTTPS
Minecraft gameTCPShield SentryTCP 25565–25577
SFTP file transferTCPShield SentryTCP 2022
Malaysia Lite node managementWireGuardInternal only

The management plane, game plane, and file-transfer plane stay isolated from each other — an attack against one entry point does not affect the others.

Minecraft Traffic Flow

Minecraft is the most important protected entry point today. Players connect on any port in the 25565–25577 range, and all traffic first enters TCPShield Sentry:

Player
  ↓
TCPShield Sentry
  ↓
VXLAN link
  ↓
Malaysia Lite node
  ↓
Docker / Pterodactyl
  ↓
Minecraft :25565

TCPShield Sentry completes scrubbing before traffic reaches our infrastructure. Only legitimate connections are delivered to the backend over the VXLAN link.

Origin IP Protection

Cafora backend nodes do not expose Minecraft ports to the Internet on their public address. The firewall layer enforces:

ens18 (public NIC)  → TCP 25565–25577 → DROP
vxlan_3234          → TCP 25565–25577 → ACCEPT

The practical result:

TCPShield entry IP :25565   ✅ Reachable
Origin public IP   :25565   ❌ Dropped

This means players cannot bypass TCPShield by discovering the origin IP. Only traffic arriving over the TCPShield VXLAN link can reach the Minecraft container.

For security reasons, Cafora does not publish the public IP of origin nodes. You should not attempt to probe or connect to the origin IP directly — those connections are silently dropped.

Multi-Server Port Range

Cafora opens and protects the 25565–25577 (TCP) port range for Minecraft. You can assign your server any port within that range in the Pterodactyl Panel:

25565
25566
25567
...
25577

All ports enter through the same TCPShield entry point, so adding a new server requires no extra protection configuration.

SFTP Traffic Flow

SFTP also uses TCPShield Sentry instead of Cloudflare Tunnel:

Pterodactyl user
  ↓
sftp.caforahost.com:2022
  ↓
TCPShield Sentry
  ↓
VXLAN link
  ↓
Malaysia Lite node
  ↓
Wings :2022

For file transfers to your server, use:

PurposeAddressPort
SFTPsftp.caforahost.com2022

See SFTP Access for details.

What Cloudflare Handles

Cloudflare does not handle Minecraft and does not handle player SFTP. Cloudflare Tunnel is dedicated to the control plane:

Panel
  ↓
Cloudflare
  ↓
Cloudflare Tunnel
  ↓
Wings API

The node FQDN (for example node.caforahost.com) continues to serve as the Wings API entry point, used only for panel and API communication.

Automatic Recovery and Persistence

Cafora runs TCPShield network configuration as a systemd reconcile mechanism. It self-checks every 60 seconds, with the first check 20 seconds after boot.

It automatically verifies and restores:

  • The VXLAN interface
  • TCPShield address and gateway
  • VXLAN MTU
  • rp_filter reverse-path settings
  • The policy routing table and rules
  • Connection marking (CONNMARK)
  • Docker firewall rules

As a result, node reboots, Docker restarts, and accidental network config resets all recover automatically with no manual intervention. iptables rules are persisted and restored after a system reboot.

Risk Overview

Attack TypeRisk Level
Large-scale UDP floodsLow
TCP SYN floodsLow
Minecraft protocol abuseLow
Direct attacks against the origin IPVery low (ports dropped by default)
Sustained small-scale attacksLow–Medium
Highly novel L7 attacksNot fully eliminated

No DDoS mitigation solution can guarantee zero impact from 100% of all possible attacks. Extremely large-scale or novel attack vectors may still cause brief service degradation while mitigation adapts.

What You Can Do

  • Keep your server address private when possible
  • Use a whitelist for private servers
  • Monitor the console for unusual connection patterns
  • Report persistent attacks to Cafora support

See Also

On this page