Network product · protect any origin server
GRE Tunnel
DDoS Shielding
A GRE tunnel lets you route traffic to your own server — hosted anywhere, on any provider — through Hoststack's DDoS-protected network edge. Attack traffic gets scrubbed before it ever reaches your real server, and your origin's real IP stays hidden behind ours.
Your origin server keeps running wherever it already lives. Only the tunnel and DNS change.
Who it's for
Built for servers you don't want to move.
If migrating hosting isn't an option, a GRE tunnel adds a protected front door to the server you already have.
Game server operators
Running Minecraft, FiveM, CS2 or Rust on your own box and getting hit with layer 3/4 floods? Shield the connect IP without touching the game server itself.
Servers that already got attacked
If you were recently hit with a DDoS on infrastructure hosted elsewhere and need protection fast, without a full migration project.
Community & forum admins
Discord bot hosts, VoIP/TeamSpeak admins and forum owners who need to hide the origin IP behind a scrubbing edge that a rival community can't target directly.
How it works
Four steps to a protected origin.
No migration. No change of hosting provider. Just a tunnel and a new public IP in front of the one you already have.
STEP 1
Request your endpoint
Talk to our network team about your server, expected traffic and mitigation needs. We issue a protected IP and a GRE tunnel endpoint on our edge.
STEP 2
Configure the tunnel
Set up a GRE interface on your own server pointing at our endpoint. Most Linux distros support this natively with ip tunnel; we provide the exact config.
STEP 3
Repoint DNS or connect IP
Update your A record or game server connect address to the new protected IP. Your original server IP is retired from public use.
STEP 4
Traffic gets scrubbed
All inbound traffic hits our edge first. Attack traffic is filtered there; only clean traffic flows through the tunnel to your real server.
Indicative pricing
Starting ranges, not a fixed cart price.
GRE tunnel pricing depends on mitigation capacity, number of protected IPs and traffic profile. The tiers below are typical starting points — your actual quote is scoped to your server and attack history.
Starter
from ₹1,499/mo indicative
Small servers, single game instances, low-traffic origins.
- Up to ~10 Gbps mitigation
- 1 protected IP
- Single GRE tunnel
- Standard L3/L4 filtering
Growth
from ₹4,999/mo indicative
Popular community servers and higher-traffic origins under recurring attack.
- Up to ~50 Gbps mitigation
- Up to 3 protected IPs
- Priority mitigation response
- Application-layer filtering options
Enterprise
Custom quote
Large networks, multiple origins, sustained high-volume attacks.
- 100 Gbps+ mitigation capacity
- Multiple protected IPs / tunnels
- Dedicated escalation contact
- Custom mitigation rules
Prices shown are indicative starting points, not fixed quotes. Final pricing depends on mitigation capacity, IP count and traffic profile — talk to our network team for an exact number.
Before you start
Technical requirements.
GRE support on your origin
Your server's OS and hosting provider need to allow a GRE interface. Most Linux distributions (Ubuntu, Debian, CentOS, AlmaLinux) support this natively. Some budget hosts block GRE — check with your provider if unsure, and we can help verify.
A static IP on your origin
The GRE tunnel terminates on a fixed IP at your end. A dynamic IP that changes frequently will break the tunnel — you'll need at least one static IPv4 assigned to the origin server.
Root/admin access
Creating a GRE interface requires root (Linux) or administrator (Windows) access on the origin server, plus the ability to edit firewall rules to only accept traffic from our tunnel endpoint.
A protected IP from us
We assign the public-facing protected IP and GRE endpoint as part of setup. This is what your DNS or game clients will actually connect to going forward.
FAQ
Common questions.
Looking for something else? See DDoS Protection included with hosting, Dedicated VDS, bare metal servers, or IP Transit for your own network.
Get protected
Tell us about your server. We'll scope the right tier.
No fixed checkout — every GRE tunnel is scoped to the customer's traffic profile and mitigation needs. Reach out and our network team will get back to you with a quote.