TMWTMW Global NetworksTMW Global Networks
TMW Shield

DDoS Protection

Always-on Layer 3–7 mitigation. BGP, GRE/IPIP, L7 proxy, 24/7 NOC.

Request engineering reviewEmergency onboarding
1+ Tbps
Edge capacity
< 100 ms
Detection
5
Edge metros
24/7
NOC
How it works

Real-time traffic filtering

Every packet is inspected at the edge. Attack traffic is dropped before it reaches your infrastructure.

Internet
TMW Shield
Your origin
Attack traffic — blockedClean traffic — passed through

Deployment models

Cloud, remote, on-prem — or hybrid.

Same mitigation stack whether traffic lands on TMW PoPs, tunnels in from your origin, or filters on your own hardware — the Arbor-style layered model without the enterprise lock-in.

Cloud scrubbing

Always-on filtering at TMW PoPs. Announce via BGP or land traffic on protected hosting.

Remote protection

GRE/IPIP or BGP handoff. Keep your origin where it is — only clean traffic returns.

On-prem appliance

Inline mitigation on your hardware for low-latency and state-exhaustion defense.

Hybrid signaling

Local filters for short attacks; automatic escalation to cloud capacity for volumetric floods.

How it works

Four steps from packet to decision.

One pipeline. Measured in microseconds.

01 - Ingest

Anycast ingest at the closest PoP

Nearest scrubbing center — shortest path.

02 - Inspect

Stateful inspection at line rate

Every packet classified in real time.

03 - Mitigate

Vector-specific mitigation

Filters fire on signature match.

04 - Forward

Clean traffic to your origin

Only real traffic reaches you.

30-day telemetry

What Shield handled in 30 days.

817 mitigated events in the latest 30-day window. Vectors, ports and peak intensity are in the July 2026 attack report.

Open the attack report

Built for every attack vector.

UDP, SYN/ACK, amplification, HTTP and game floods — each with its own controls.

Layer 3–7

Network, transport and application filtering.

Automatic Detection

Mitigation before your origin becomes the bottleneck.

Scrubbing Edge

Filter at ingress. Forward only clean traffic.

Always-On

No manual cutover during an attack.

GEO Filter

Allow or block by country or region.

ASN Filter

Allow, challenge or drop by source ASN.

Firewall at the Edge

Stateful inspection before your origin.

Service Filters

HTTP, gaming, voice, mail, VPN and DNS.

Fact

Asymmetric by default

Attack traffic stops at the edge — without symmetric infrastructure.

Who runs on TMW Shield

Built for traffic that can't go down.

Same mitigation for every customer.

Gaming & Game Hosting

Per-title filters. Low latency.

ISPs & Hosting Providers

Prefix-wide BGP mitigation.

E-commerce & SaaS

Checkout and APIs stay online.

FinTech & Trading

Predictable paths under pressure.

Voice, SIP & Streaming

Real-time UDP without jitter.

Critical Infrastructure

Always-on, BGP-routed.

Why TMW Shield

Built on our own network.

Our ASN, our edge, our engineers. Pay for clean traffic — not attacks.

Own network

No reseller between you and our engineers.

Clean traffic pricing

No attack overages.

Engineer on call

24/7. Filters pushed directly.

Protocol-specific filters

Custom filters without a long wait.

NOC-level visibility

Same dashboards our NOC uses.

No route lock-in

Bring your ASN. Run alongside others.

Technical specs

Numbers with definitions.

Edge capacity, clean forwarding and peak absorption — clearly separated.

1+ Tbps

Total Capacity

Aggregate ingress and filtering across the mitigation edge.

< 100 ms

Detection Target

Known L3/L4 vectors trigger automated filters under 100 ms.

5

Public Edge Metros

Frankfurt, Amsterdam, Zurich, North Kansas City, Singapore.

L3 - L7

Layer Coverage

Stateless, stateful and application-layer filters.

99.9 %

Mitigation Uptime

SLA depends on product, handoff and redundancy.

< 30 s

BGP Convergence

Failover under regional incident scenarios.

24 / 7

On-call Engineers

Engineers who can change filters and routes.

Same day

Onboarding Time

BGP up, prefixes announced, traffic mitigated.

TMW Shield DDoS filters

Optimized filters for your applications

Specialized filters for gaming servers, web applications, VPN services, and more.

Minecraft
Rust
Counter-Strike
Source Engine
Garry's Mod
Team Fortress 2
Left 4 Dead 2
Half-Life
Quake
ARK
DayZ
Arma
Squad
Hell Let Loose
Valheim
Sons of the Forest
The Forest
7 Days to Die
Terraria
Factorio
Satisfactory
Palworld
Project Zomboid
Unturned
V Rising
Conan Exiles
Hurtworld
GTA
FiveM
Rage:MP
alt:V
MTA:SA
SA:MP
open.mp
MuOnline
SCP: Secret Laboratory
DDNet
Unreal Tournament 99
Unreal Tournament 2004
BeamMP
Assetto Corsa
Space Engineers
Eco
Don't Starve Together
Killing Floor 2
Insurgency: Sandstorm
Battlefield
Call of Duty
OpenTTD

This list is not exhaustive. Need a specific game or protocol filter? Contact us for custom solutions.

On-Prem

Cloud not the right fit?

Run mitigation on your own hardware — low latency, full control, same TMW Shield stack.

On-Prem

Free Trial - 14 Days

Protection on a real network.

Protected transit, remote protection, proxy or hosting.

Start free trialEmergency onboarding
  • No credit card required
  • Full mitigation capacity
  • Dedicated setup engineer
  • Cancel anytime

TMW Shield service terms

DDoS knowledge hub

Learn before the next attack

Guides, monthly attack telemetry and anonymized customer outcomes — built from TMW edge operations, not generic SEO copy.

Browse all guides

Guides

Multilingual deep dives on DDoS mitigation, BGP, anycast, gaming and hosting.

Attack Reports

Monthly statistics on vectors, peak scrubbing load and NOC recommendations.

Case Studies

What changed for operators after moving prefixes and panels behind TMW.

What is DDoS protection?Game server DDoSBGP mitigationTCP & UDP portsSYN flood explained
TMW Global Networks

Carrier-grade DDoS protection, IP transit, and hosting for networks that need direct operational support.

All systems operational

Hosting

  • Dedicated Servers
  • Cloud VPS
  • KVM Server
  • IP-Transit
  • Network
  • BGP Communities
  • Colocation

Services

  • TMW Shield
  • TMW CDN / Proxy
  • On-Prem
  • Filter Profiles
  • Status page

Guides

  • Guides
  • FAQ
  • Attack Reports
  • Case Studies
  • What is a Cloud Server?
  • What is a VPS?
  • What is DDoS Protection?
  • TCP & UDP Ports Explained
  • TCP/IP Explained

Company

  • Solutions
  • About
  • DDoS Frankfurt
  • abuse@t-w.dev
  • noc@t-w.dev
  • Contact
  • Under Attack?

© 2026 TMW Global Networks. All rights reserved.

ImprintPrivacyTermsTMW Shield Terms