infrastructure-roadmap icon indicating copy to clipboard operation
infrastructure-roadmap copied to clipboard

GAME firewall upgrade

Open jslocinski opened this issue 2 years ago • 17 comments

As a game hosting company, we would like to benefit from the latest security protections for GAME server ranges so we're protected from DDoS attacks targetting various gaming protocols.

jslocinski avatar Jan 20 '23 08:01 jslocinski

How you gonna do this if OVH management refuses to support certain game protocols because of possible "legal" issues? At least that is their excuse when we asked for it multiple times.

VibeGAMESNL avatar Feb 11 '23 01:02 VibeGAMESNL

OVHcloud supports and develops protections for applications that can be hosted on our servers.

jslocinski avatar Feb 21 '23 10:02 jslocinski

Glad to hear the GAME firewall will be getting some love. I hope that detection and filters for the latest A2S query attacks are on the roadmap. We host DayZ, so updated protocol support for DayZ Standalone would be fantastic. I know Arma 2 was supported in the past, so hopefully that wouldn't be a huge leap. Thank you.

sanguine0 avatar Aug 03 '23 17:08 sanguine0

Thanks for your comment. DayZ is on our list for the next steps, but nothing prioritized yet.. and Arma 2 is supported since long time already.

jslocinski avatar Aug 04 '23 09:08 jslocinski

I've had to disable the game firewall because, to my understanding, it consolidates all traffic directed toward Steam's query servers through one IP, which leads to constant rate limiting. While I'm not 100% on the degree to which the traffic is being consolidated, I do know that it definitely leads to rate limiting, because I can't get my server listed in the browser without turning off Game Firewall.

If I were to attempt to use it again for any reason, I'd need to know that I'll be able to properly connect to the Steam query servers so that I can get my game servers listed in their respective launchers.

millieismillie avatar Aug 07 '23 05:08 millieismillie

More robust DayZ Standalone support in the GAME firewall would be amazing. It's been a common frustration among the community of server owners I've spoken to.

Crossing our fingers this gets pushed near the top of the heap.

AverieMods avatar Aug 07 '23 09:08 AverieMods

I will also chime in and Unturned support would be great

Currently hl2Source filters in game firewall work great but can be improved upon for Unturned specifically because they can be bypassed with a tailor made attack packets

gegtor avatar Aug 07 '23 09:08 gegtor

How is OVH doing with this topic? As an OVH customer I see that the protection that affects Game range it’s getting outdated. New games are out there (for example CS2) and OVH is loosing actual and future customers because the lack of specific filters.

CS2, updated Raknet (for Rust), updated DayZ, FiveM, updated Minecraft and soon ARK Ascended protocol…

Right now the temporary “patch” that the VAC team perform is applying basic profiles to the IPs which still are insufficient for more dedicated and sophisticated attacks. Also “forcing” somehow customers to build their own filters at the server side which is not optimal and force them move to different providers that have more improved filtering at the network.

As an actual customer, I really think it’s something that requires an update (protocols and filters updated) and more supported applications.

Some ideas: OpenVPN, Source Engine Query, RakNetv2, FiveM Server Query…

MikeRuSe avatar Oct 10 '23 23:10 MikeRuSe

Just add ability to create own profile. Even "allow custom initial packet length" feature will dramatically increase usability of game firewall.

ubinoob1 avatar Jan 02 '24 12:01 ubinoob1

Will FiveM Protection be added now that it is officially owned by Rockstar?

1Ronkkeli avatar Feb 13 '24 10:02 1Ronkkeli

@jslocinski, with Rockstar Games officially acquiring FiveM, the previous legal concerns that OVH cited to justify not implementing a DDoS protection filter for FiveM should no longer be an issue. Given that FiveM has been officially acquired by Rockstar for several months now, and its popularity remains undiminished, this change in ownership should eliminate any hesitations regarding legalities.

Could you provide any insights into when OVH might plan to implement a DDOS protection filter for FiveM? The community is keenly awaiting an update on this matter, considering the significant impact it would have on user experience and server stability.

https://www.rockstargames.com/newswire/article/8971o8789584a4/roleplay-community-update

VibeGAMESNL avatar Feb 13 '24 12:02 VibeGAMESNL

Thanks for mentioning FiveM. Yes, we saw that and put in discovery with our engineering teams as well as legal. As we're working on few other updates for game in parallel, we few weeks to share more precisely some details of game evolution. I will come back asap.

jslocinski avatar Feb 14 '24 10:02 jslocinski

What I can propose is to create separate issues for every game that needs recent support and vote. That will help us to prioritize

jslocinski avatar Feb 28 '24 10:02 jslocinski

Just add ability to create own profile. Even "allow custom initial packet length" feature will dramatically increase usability of game firewall.

Exactly! I've been struggling and searching for OS level ways to filter my layer attacks on a custom game, my application does basic initial connection closing based on packet size & then proceed to authentication & encryption/decryption, but 60K of spoofed handshakes can still damage us very hardly.

I think that what actually should be discussed is a way to be able to create your own custom rules, then community could develop known game protocol rules and everyone would be protected despite what game is being hosted, without requiring OVH to slowly implement new protocols.

Something like snort's rules on the upstream filter would help me immensely!

'drop tcp any any -> any 2525 (msg:"Non-standard TCP handshake size"; flow:to_server,established; dsize:!2; sid:1000001;)'

Pb600 avatar Jul 02 '24 00:07 Pb600

@Pb600 thanks for your remark. Custom GAME protection profile is discussed in the https://github.com/ovh/infrastructure-roadmap/issues/175

jslocinski avatar Jul 02 '24 07:07 jslocinski

how long will prioritize this i'm sick of resellers out there image it really said owned by take two

Heavens-c avatar Jul 06 '24 06:07 Heavens-c

@jslocinski

we few weeks to share more precisely some details of game evolution. I will come back asap.

We all know the anti-ddos team is pretty busy, but can we get some light to the GAME things, like network upgrade, game anti ddos as a service, private network connections and this one GAME upgrade and filters with OTHER options and newer games like CS2 and etc...

axl303 avatar Jul 07 '24 08:07 axl303

ARK Survival Ascended this is a newer version of ARK and is not on the new firewall list.

Marrcell avatar Oct 03 '24 16:10 Marrcell