DDoS Protection
How Cafora uses TCPShield Sentry and Cloudflare Tunnel as layered entry points for enterprise-grade DDoS protection on Minecraft and SFTP.
DDoS (Distributed Denial of Service) attacks are one of the most common threats to Minecraft servers. Cafora uses a layered entry architecture: game traffic and file-transfer traffic are scrubbed by TCPShield Sentry and returned over a dedicated VXLAN link, while panel and API traffic is handled by Cloudflare Tunnel.
The guiding principle is simple: the origin IP never serves Minecraft or SFTP directly.
What is a DDoS Attack?
A DDoS attack floods a server with malicious traffic, overwhelming its resources and preventing legitimate players from connecting. Minecraft servers are frequently targeted because:
- Game servers require low-latency, always-on connections
- Server addresses are publicly visible
- Attack tools are widely available
Types of Attacks
Volumetric Attacks
Massive amounts of traffic saturate the network connection. Measured in Gbps or packets per second (pps).
TCP Attacks
Exploit the TCP handshake process:
- SYN Flood — Overwhelms with connection requests that never complete
- ACK Flood — Spoofed acknowledgment packets
- Connection Exhaustion — Opens and holds thousands of connections
UDP Attacks
Target the UDP protocol used by Minecraft for query responses and Bedrock Edition. Common types include UDP floods and amplification attacks.
Application-Layer (L7) Attacks
Target Minecraft-specific services rather than network infrastructure. These attacks mimic legitimate player behavior at scale.
Layered Entry Architecture
Rather than placing a single proxy in front of everything, Cafora splits entry points by traffic plane:
| Traffic plane | Entry point | Protocol & port |
|---|---|---|
| Panel / Wings API | Cloudflare Tunnel | HTTPS |
| Minecraft game | TCPShield Sentry | TCP 25565–25577 |
| SFTP file transfer | TCPShield Sentry | TCP 2022 |
| Malaysia Lite node management | WireGuard | Internal only |
The management plane, game plane, and file-transfer plane stay isolated from each other — an attack against one entry point does not affect the others.
Minecraft Traffic Flow
Minecraft is the most important protected entry point today. Players connect on any port in the 25565–25577 range, and all traffic first enters TCPShield Sentry:
Player
↓
TCPShield Sentry
↓
VXLAN link
↓
Malaysia Lite node
↓
Docker / Pterodactyl
↓
Minecraft :25565TCPShield Sentry completes scrubbing before traffic reaches our infrastructure. Only legitimate connections are delivered to the backend over the VXLAN link.
Origin IP Protection
Cafora backend nodes do not expose Minecraft ports to the Internet on their public address. The firewall layer enforces:
ens18 (public NIC) → TCP 25565–25577 → DROP
vxlan_3234 → TCP 25565–25577 → ACCEPTThe practical result:
TCPShield entry IP :25565 ✅ Reachable
Origin public IP :25565 ❌ DroppedThis means players cannot bypass TCPShield by discovering the origin IP. Only traffic arriving over the TCPShield VXLAN link can reach the Minecraft container.
For security reasons, Cafora does not publish the public IP of origin nodes. You should not attempt to probe or connect to the origin IP directly — those connections are silently dropped.
Multi-Server Port Range
Cafora opens and protects the 25565–25577 (TCP) port range for Minecraft. You can assign your server any port within that range in the Pterodactyl Panel:
25565
25566
25567
...
25577All ports enter through the same TCPShield entry point, so adding a new server requires no extra protection configuration.
SFTP Traffic Flow
SFTP also uses TCPShield Sentry instead of Cloudflare Tunnel:
Pterodactyl user
↓
sftp.caforahost.com:2022
↓
TCPShield Sentry
↓
VXLAN link
↓
Malaysia Lite node
↓
Wings :2022For file transfers to your server, use:
| Purpose | Address | Port |
|---|---|---|
| SFTP | sftp.caforahost.com | 2022 |
See SFTP Access for details.
What Cloudflare Handles
Cloudflare does not handle Minecraft and does not handle player SFTP. Cloudflare Tunnel is dedicated to the control plane:
Panel
↓
Cloudflare
↓
Cloudflare Tunnel
↓
Wings APIThe node FQDN (for example node.caforahost.com) continues to serve as the Wings API entry point, used only for panel and API communication.
Automatic Recovery and Persistence
Cafora runs TCPShield network configuration as a systemd reconcile mechanism. It self-checks every 60 seconds, with the first check 20 seconds after boot.
It automatically verifies and restores:
- The VXLAN interface
- TCPShield address and gateway
- VXLAN MTU
rp_filterreverse-path settings- The policy routing table and rules
- Connection marking (CONNMARK)
- Docker firewall rules
As a result, node reboots, Docker restarts, and accidental network config resets all recover automatically with no manual intervention. iptables rules are persisted and restored after a system reboot.
Risk Overview
| Attack Type | Risk Level |
|---|---|
| Large-scale UDP floods | Low |
| TCP SYN floods | Low |
| Minecraft protocol abuse | Low |
| Direct attacks against the origin IP | Very low (ports dropped by default) |
| Sustained small-scale attacks | Low–Medium |
| Highly novel L7 attacks | Not fully eliminated |
No DDoS mitigation solution can guarantee zero impact from 100% of all possible attacks. Extremely large-scale or novel attack vectors may still cause brief service degradation while mitigation adapts.
What You Can Do
- Keep your server address private when possible
- Use a whitelist for private servers
- Monitor the console for unusual connection patterns
- Report persistent attacks to Cafora support