Guides

Minecraft protection guides

Practical, no-fluff guides: setting up protection on any host, config walkthroughs, responding to attacks, and choosing the right service.

DDoS-protected hosting

You don't need special 'DDoS protected hosting'. Buy any Minecraft host you like, put Arvoris in front for $0–40/mo, and get 500+ Tbps protection with real player IPs.

Read the guide →

Why you need protection

Booters cost $5 and any argument can get your Minecraft server flooded. What attacks look like, what downtime really costs, why plugins can't stop them — and why starting free removes the last excuse.

Read the guide →

Pterodactyl

Step-by-step: put Arvoris in front of a Pterodactyl-hosted Minecraft server. Find your allocation, add it as a backend, set one DNS record, enable PROXY protocol in the file manager, then firewall the node.

Read the guide →

Stop an attack

Your Minecraft server is being DDoSed right now? Identify the attack type, don't pay ransoms, don't restart-loop — and get behind a filtering edge before the next wave. Honest notes on setup during an active attack.

Read the guide →

Am I being DDoSed?

Lag spikes, timeouts, everyone disconnecting at once — DDoS or just a bad plugin? A symptom table for the three attack types, what your console and host graphs show for each, and how to rule out ordinary causes.

Read the guide →

Free DDoS protection

Every genuinely free way to DDoS-protect a Minecraft server, why most of them fail for game traffic, and how to get a full mitigation pipeline for $0 with no card.

Read the guide →

Velocity setup

Enable PROXY protocol on Velocity in one line: haproxy-protocol = true in velocity.toml. Get real player IPs behind Arvoris, why direct connections then fail (that's a feature), and how to fix 'invalid packet' errors.

Read the guide →

BungeeCord setup

Enable PROXY protocol on BungeeCord or Waterfall to get real player IPs behind Arvoris: set proxy_protocol: true under the listener in config.yml, restart, done.

Read the guide →

Best DDoS protection

There's no single 'best' Minecraft DDoS protection — it depends on player count, budget and region. A criteria checklist, the main options compared, and who each one fits.

Read the guide →

What is a booter

A booter (or stresser) is a paid DDoS-for-hire service, typically $5–30/mo. What they are, why using one against others is illegal, why Minecraft servers are favorite targets, and how to defend.

Read the guide →

How Cryo mitigates attacks

A stage-by-stage walkthrough of how Arvoris' Cryo engine mitigates a Minecraft DDoS attack: anycast absorption, protocol parsing, adaptive rate limits, auto-UAM and verification — what happens to each packet, in order.

Read the guide →

Edge vs. server-side protection

Why Minecraft protection belongs at the edge, not in a plugin, firewall or your host: server-side antibot acts too late, firewalls can't read the protocol, host scrubbing null-routes. Edge stops attacks before your hardware.

Read the guide →

Minecraft bypass bots

Bypass bots are written to defeat a specific antibot's checks. Here's how they work, why open-source and static antibots are vulnerable, and how edge verification with per-session randomization stops them.

Read the guide →

Edge antibot vs plugin

Plugin antibots (Sonar, LimboFilter, nAntiBot) run on your server, after the connection is accepted. Edge antibots filter upstream, before your box sees it. Here's when each wins — and why big attacks need the edge.

Read the guide →

Protocol-aware filtering

Generic DDoS mitigation filters on packet shape, rate and reputation. A Minecraft join flood is correct on all three. Protocol-aware filtering parses the game protocol itself — hostname, version, join intent — and is the only thing that separates bots from players without kicking players.

Read the guide →

Server RAM

Real RAM numbers for Minecraft servers by player count and server type: vanilla, Paper with plugins, and modpacks. Why more RAM often makes lag worse, what actually drives memory use, and how to tell if RAM is your bottleneck at all.

Read the guide →

Velocity vs BungeeCord

Velocity vs BungeeCord compared on performance, security, plugin ecosystem and forwarding. Why modern forwarding matters, what Waterfall's deprecation changed, and when staying on BungeeCord is still the right call.

Read the guide →

Paper vs Purpur vs Folia

Which Minecraft server software should you run? Paper, Purpur and Folia compared on performance, plugin compatibility, configurability and who each one is actually for — including why Folia is not a drop-in upgrade.

Read the guide →

LuckPerms setup

Set up LuckPerms properly the first time: how groups and inheritance actually work, the commands you need, the web editor, and the mistakes that make permissions unmanageable six months in.

Read the guide →

server.properties

A practical server.properties reference for Minecraft admins: what view-distance, simulation-distance, online-mode, network-compression-threshold and the rest actually do, which ones affect performance, and which ones are security decisions.

Read the guide →

Finding lag with spark

Stop guessing at Minecraft server lag. Use the spark profiler to find the actual cause: how to read a profile, tell TPS lag from network lag, and identify the plugin, farm or chunk load eating your tick.

Read the guide →

JVM flags & GC

Why your Minecraft server freezes every few minutes, and what JVM flags actually fix it. G1GC tuning explained, why -Xms should equal -Xmx, which flags are cargo cult, and how to verify the change worked.

Read the guide →

Minecraft in Docker

Run a Minecraft server in Docker properly: volumes that survive a rebuild, memory limits that do not fight the JVM, restart policies, and the networking mistake that exposes your backend to the whole internet.

Read the guide →

Comparisons

TCPShield alternativeNeoProtect alternativeArvoris vs Sonar

Your next attack is already scheduled.
Be behind the edge when it lands.

We take care of security so you can branch out. Free plan, no card, one DNS record — if it doesn't hold, you lost five minutes.