| minecraft | Minecraft Protection | Minecraft Java and Bedrock (TCP/UDP): handshake, login, ping, and volumetric floods |
| counter-strike-16 | Counter-Strike 1.6 | GoldSrc engine (Half-Life 1): UDP floods, query abuse, and malformed packets |
| counter-strike-go | Counter-Strike GO | Source engine: Steam A2S query floods, connection floods, and high-PPS UDP |
| counter-strike-2 | Counter-Strike 2 | UDP floods, query abuse, and abnormal packets |
| left-4-dead-2 | Left 4 Dead 2 | Source engine: Steam A2S query floods and volumetric UDP |
| fivem-tcp | FiveM TCP | TCP connection and handshake floods |
| fivem-udp | FiveM UDP | High-PPS UDP floods and abnormal packets |
| samp | San Andreas Multiplayer | SA-MP connection floods, query abuse, and malformed UDP |
| rust | Rust Game Protection | UDP floods, connection spikes, and abnormal packets |
| team-speak3 | TeamSpeak 3 Voice Chat | UDP floods and connection abuse on voice sessions |
| rust-a2s | Rust Game A2S Caching | Caches Steam A2S query responses |
| bf2-query | Battlefield 2 Query Caching | Caches server-browser query responses |
| bf2 | Battlefield 2 Game | UDP floods and malformed packets on gameplay traffic |
| unity-unet | Unity Engine UNET | Malformed packets and high-PPS floods |
| unity-utp | Unity Engine UTP | UDP floods on Unity Transport Protocol |
| geo | Geo Restriction | Allow or deny by client location. Configure on the Policy tab first |
| ssh-server | SSH Server | SSH connection floods |
| default-tcp | Default TCP | Generic TCP. Per-IP 20k pps / 50 Mbps; overall 50k pps / 500 Mbps |
| default-udp | Default UDP | Generic UDP. Per-IP 5k pps / 5 Mbps; overall 50k pps / 50 Mbps |
| default-icmp | Default ICMP | Generic ICMP. Per-IP 100 pps; overall 1k pps |
| default-other | Default Other | Other protocols. Per-IP 200 pps; overall 1k pps |
| ratelimiter-low | Rate Limiter Low | Caps destination rate up to 50 kpps (default 50). Configure on the Policy tab first |
| ratelimiter-medium | Rate Limiter Medium | Caps destination rate up to 150 kpps (default 150). Configure on the Policy tab first |
| ratelimiter-high | Rate Limiter High | Caps destination rate up to 300 kpps (default 300). Configure on the Policy tab first |
| allowlist | Allow List | Matching traffic is forwarded without inspection |
| tcp-autodetect | TCP auto-detect | Passive TCP countermeasure, triggered only during an attack |
| tcp-server | TCP Countermeasure | Always-on SYN-cookie challenge for incoming TCP |
| tcp-server-v2 | TCP Flow Track | Experimental full-session tracking when SYN-cookie fails for an application |
| tcp-private | TCP Ephemeral Ports Protection | Protects ephemeral (client source) TCP ports |