Skip to content

Rust DDoS Protection

Existing links still lead to this reference page. For the current dashboard steps, follow the VxShield Firewall Guide.

VxShield starts with ports closed. Add a rule with the matching protocol and filter for every public port your Rust server needs.

Give game traffic, queries, RCON and the Rust+ app their own port rules. This example uses 28015 for the game and 28016 for RCON, without query or Rust+ overrides. Facepunch derives the query port by adding 1 to the larger of the game and RCON ports; for Rust+, it adds 67 to that larger value. Read your server’s active values before adding rules. Server port reference · Rust+ reference

Purpose Port in this example Protocol Filter
Game traffic 28015 UDP Rust
Query traffic 28017 UDP A2S Query Cache
RCON 28016 TCP Generic TCP
Rust+ app 28083 TCP Generic TCP
Scroll to see all columns →

An explicit server.queryport or app.port takes precedence over the derived value. An assigned Rust+ port of 28082 is valid; check the companion listener with app.info. Retain the game and RCON ports assigned to your instance.

  1. Go to the VxShield dashboard.
  2. Choose the protected IP assigned to your VPS or dedicated server.
  3. Select Add rule.
  4. Choose Rust to load the preset for game, query, RCON and Rust+ traffic.
  5. Replace the preset ports with any custom values used by your server.
  6. Apply the rules to save them.
  7. Check that players can join, the server appears in the browser, and RCON works. Test Rust+ if you enabled it.

Follow Rust Protection for the complete dashboard walkthrough and screenshots.