Rust Server DDoS Protection: Ports, Filters and Limits
Check Rust DDoS protection for game, query, RCON and Rust+ services. Match configured ports to filters and understand the protection limits.
On this page
Test a player join and a browser query when checking Rust DDoS protection. They use different services. One can answer while the other fails.
Map the ports you expose, then ask which filter covers each and who maintains it. Include what happens when mitigation disrupts legitimate traffic. A large network-capacity number cannot answer those operational questions.
Map the services you actually use
Rust game and query traffic use UDP. RCON and the Rust+ companion service use TCP. These common values are examples; use the values assigned to your service when configuring rules.
| Service | Example port and protocol | What to check |
|---|---|---|
| Game | 28015/UDP | The endpoint players use to join |
| Steam query | 28017/UDP | Query port, separate from the game port |
| RCON | 28016/TCP | Whether remote administration is enabled and who needs it |
| Rust+ | 28082/TCP | Whether the companion service is enabled and its active port |
An unset query port can be derived from the game/RCON configuration. Read the running settings before adding a rule. For Rust+, use its documentation and the app.info diagnostic. Facepunch server setup, Rust+ server documentation
Enable RCON only when your admin workflow needs it. Use a unique secret and restrict access where possible. Redact secrets from public screenshots and logs. Use the provider’s agreed secure channel if a support check requires credentials.
Separate query reachability from gameplay
The Rust browser requests listing information through queries. Blocking that path can hide the listing while direct joins work. A query reply, in turn, does not establish that the game process can handle a playing session. Facepunch’s browser troubleshooting
At the incident time, record:
- Whether a player can connect to the public game endpoint.
- Whether the browser receives a current query response.
- Process health, including CPU, memory and plugin work.
- Any preceding port, protection-rule or server update.
Use the server-list guide for discovery and the Rust lag guide for simulation versus network symptoms. Keep an attack diagnosis open until you have traffic evidence.
What a protection claim needs to tell you
Check packet rate and protocol behavior alongside traffic volume. Legitimate demand and the work performed by the server affect the outcome too. A “generic” or “game-aware” label needs a description of what the service does.
Ask the provider:
- Services and rules: which filters cover game, query and enabled TCP endpoints?
- Legitimate traffic: how do you verify joins and queries after a rule change?
- Capacity: is the number shared network capacity, a port limit or a contractual commitment?
- Mitigation limits: can traffic be rate-limited, dropped or null-routed, and how will I hear about it?
- Incident evidence: which game, date, traffic class and observed outcome does the report cover?
- Responsibility: who adds rules and investigates a changed port or false positive?
Keep those answers with the order. Neither a cache nor a capacity figure promises to stop every attack without packet loss.
VxShield’s published Rust configuration
VYKIX plans include VxShield. Our Rust protection documentation maps services to these filters:
| Service | Published rule |
|---|---|
| Game UDP port | Rust |
| Query UDP port | A2S Query Cache |
| RCON TCP port | Generic TCP |
| Rust+ TCP port | Generic TCP |
Our VxShield firewall guide shows the Rust preset workflow: select the protected IP, add the rule, check its ports and save. Test gameplay and queries afterward, plus RCON or Rust+ if enabled.
We manage those rules on managed Rust hosting. Game VPS and bare-metal customers manage their own rules. VxShield starts with ports closed on those services, and the OS firewall must agree with the upstream rules.
The filter list documents configuration, not a measured outcome for every query or attack. The advertised 17 Tbps is aggregate protection-network capacity, not reserved capacity for one server. Our terms allow for attack-related disruption, including packet loss, latency and null-routing where necessary. Service terms
The KarmaKrew incident report covers a DayZ community. Read it within that incident’s evidence limits; it does not supply a Rust benchmark.
Check the service before committing
Check a new setup with a normal player join and browser query. For a resilience exercise, agree on a controlled, authorised test with the provider first. Do not send attack traffic as an informal trial test.
Our managed Rust PC plan includes file access, Oxide/Carbon support, maintenance schedules and three same-server backup slots alongside VxShield. Check current availability and the order total, including applicable taxes and fees.
The free PC trial lasts 48 hours and requires a valid card for fraud verification. It has no charge or automatic paid conversion. Service is suspended at 48 hours; active data is deleted seven calendar days after suspension. Export needed files before expiry. Continuing requires a separate paid order, and the trial hardware can differ from paid hardware.
For a move, confirm the scope and eligibility of complimentary, best-effort migration with us. Any seven-day switching bonus has qualifying conditions. Trial and migration terms
Compare Rust hosting and its trial terms. For a specific endpoint or rule, ask VYKIX on Discord which service boundary applies.
Game-aware DDoS protection for your server.
Run your game server with VxShield included. Ask about free migration and seven days free for eligible customers switching hosts. VYKIX confirms the scope, timing, and terms before the move.