Gateway Sentry

Solutions / Game Servers / Source Engine

Source Engine DDoS Protection

CS2, TF2, and Garry's Mod servers protected at the edge, with A2S query floods answered from cache so server browsers keep working mid-attack.

27015 default port tcp/udpA2S cached at the edgebrowsers keep working

How Source Engine Servers Are Protected

A2S Floods

A2S_INFO and A2S_PLAYERS floods are a favorite cheap attack on Source servers. The edge answers them from cache, so they cost your box nothing. How query caching works.

Game Traffic

Gameplay on 27015 is filtered with protocol-aware profiles across TCP and UDP, keeping tick stable through volumetric attacks.

Visibility Mid-Attack

Because queries are answered upstream, your server stays listed and joinable in browsers even while a flood is being absorbed. Players find you; the flood does not.

Setup in Practice

Change the address in your server config and point players at the protected IP; 27015 is filtered across TCP and UDP with profiles tuned for Source. A2S answers come from edge cache at every site, which is why your listing stays live even while a flood is being absorbed.

Host It on the Edge

Or skip the forwarding hop entirely: run the server on Sentry Compute and it lives behind its anycast address inside the perimeter, with the same filtering in front and nothing public between the edge and the game.

Frequently Asked Questions

How does Gateway Sentry handle A2S query floods?
Server-browser queries like A2S are answered from edge cache at every site, so query floods terminate at the nearest PoP and your server only sees real gameplay. Listings stay fresh because the cache is refreshed from your server continuously.

Keep the Server Up

Provision a protected IP and point your record at it; setup takes minutes