20% off your first order with code APEX20 00:00:00 See deals

Network product · protect any origin server

GRE Tunnel
DDoS Shielding

A GRE tunnel lets you route traffic to your own server — hosted anywhere, on any provider — through Hoststack's DDoS-protected network edge. Attack traffic gets scrubbed before it ever reaches your real server, and your origin's real IP stays hidden behind ours.

Works with any hosting provider Origin IP stays hidden No migration required Game servers & community hosts
how it works
gre · protected edge
1. RequestProtected IP + GRE endpoint issued by Hoststack
2. ConfigureGRE interface on your own server, pointed at that endpoint
3. RepointDNS or game connect IP updated to the protected IP
4. ScrubAttack traffic filtered at our edge, clean traffic tunnels to origin

Your origin server keeps running wherever it already lives. Only the tunnel and DNS change.

Who it's for

Built for servers you don't want to move.

If migrating hosting isn't an option, a GRE tunnel adds a protected front door to the server you already have.

Game server operators

Running Minecraft, FiveM, CS2 or Rust on your own box and getting hit with layer 3/4 floods? Shield the connect IP without touching the game server itself.

Servers that already got attacked

If you were recently hit with a DDoS on infrastructure hosted elsewhere and need protection fast, without a full migration project.

Community & forum admins

Discord bot hosts, VoIP/TeamSpeak admins and forum owners who need to hide the origin IP behind a scrubbing edge that a rival community can't target directly.

How it works

Four steps to a protected origin.

No migration. No change of hosting provider. Just a tunnel and a new public IP in front of the one you already have.

STEP 1

Request your endpoint

Talk to our network team about your server, expected traffic and mitigation needs. We issue a protected IP and a GRE tunnel endpoint on our edge.

STEP 2

Configure the tunnel

Set up a GRE interface on your own server pointing at our endpoint. Most Linux distros support this natively with ip tunnel; we provide the exact config.

STEP 3

Repoint DNS or connect IP

Update your A record or game server connect address to the new protected IP. Your original server IP is retired from public use.

STEP 4

Traffic gets scrubbed

All inbound traffic hits our edge first. Attack traffic is filtered there; only clean traffic flows through the tunnel to your real server.

Indicative pricing

Starting ranges, not a fixed cart price.

GRE tunnel pricing depends on mitigation capacity, number of protected IPs and traffic profile. The tiers below are typical starting points — your actual quote is scoped to your server and attack history.

Starter

from ₹1,499/mo indicative

Small servers, single game instances, low-traffic origins.

  • Up to ~10 Gbps mitigation
  • 1 protected IP
  • Single GRE tunnel
  • Standard L3/L4 filtering
Talk to us

Growth

from ₹4,999/mo indicative

Popular community servers and higher-traffic origins under recurring attack.

  • Up to ~50 Gbps mitigation
  • Up to 3 protected IPs
  • Priority mitigation response
  • Application-layer filtering options
Talk to our network team

Enterprise

Custom quote

Large networks, multiple origins, sustained high-volume attacks.

  • 100 Gbps+ mitigation capacity
  • Multiple protected IPs / tunnels
  • Dedicated escalation contact
  • Custom mitigation rules
Request a quote

Prices shown are indicative starting points, not fixed quotes. Final pricing depends on mitigation capacity, IP count and traffic profile — talk to our network team for an exact number.

Before you start

Technical requirements.

GRE support on your origin

Your server's OS and hosting provider need to allow a GRE interface. Most Linux distributions (Ubuntu, Debian, CentOS, AlmaLinux) support this natively. Some budget hosts block GRE — check with your provider if unsure, and we can help verify.

A static IP on your origin

The GRE tunnel terminates on a fixed IP at your end. A dynamic IP that changes frequently will break the tunnel — you'll need at least one static IPv4 assigned to the origin server.

Root/admin access

Creating a GRE interface requires root (Linux) or administrator (Windows) access on the origin server, plus the ability to edit firewall rules to only accept traffic from our tunnel endpoint.

A protected IP from us

We assign the public-facing protected IP and GRE endpoint as part of setup. This is what your DNS or game clients will actually connect to going forward.

FAQ

Common questions.

GRE (Generic Routing Encapsulation) is a tunneling protocol that wraps your server's traffic and carries it between two points over the public internet — in this case, between our protected network edge and your origin server. Anyone attacking your public-facing IP is actually attacking our edge, not your real server.
In most cases, yes. As long as your server's OS supports a GRE interface and your provider doesn't block GRE traffic outright, you can tunnel to us regardless of who hosts your actual server. You do not need to move your server to Hoststack.
Attack traffic is directed at the protected IP we assign, which sits at our network edge. Our mitigation filters malicious packets there — before they ever enter the GRE tunnel. Only legitimate traffic gets tunneled through to your real server, so your origin never sees the flood.
There is a small amount of added latency since traffic now makes an extra hop through our edge before reaching your origin. For most web and game traffic this is a few milliseconds and not noticeable, but the exact impact depends on how far your origin server is from our network edge — we'll talk through this during setup.
No. A GRE tunnel protects a server that lives somewhere else — you keep your existing hosting provider and setup. If you'd rather host the server itself with us, our Dedicated VDS and bare metal plans include DDoS protection by default with no tunnel needed.
Not as a self-serve checkout. Because the right mitigation tier depends on your traffic profile, attack history and origin setup, we scope GRE tunnels through a short conversation with our network team first. Reach out via the contact page and we'll get back to you with a proper quote.

Looking for something else? See DDoS Protection included with hosting, Dedicated VDS, bare metal servers, or IP Transit for your own network.

Get protected

Tell us about your server. We'll scope the right tier.

No fixed checkout — every GRE tunnel is scoped to the customer's traffic profile and mitigation needs. Reach out and our network team will get back to you with a quote.

Deploy today

Online in 60 seconds. Supported around the clock.

Hosting, VPS and game servers across Mumbai, Delhi, Singapore & Germany — INR billing, GST invoices, and code APEX20 for 20% off your first order.

5,000+ customers served
99.9% uptime SLA
<8ms ping across India
24/7 expert support
WhatsApp Discord