Dashboard
Nothing is being dropped right now.
| Address | Customer | Dropped |
|---|---|---|
| Prefix | Announced |
|---|---|
Customers
No customers yet
Protect a game server that runs on your own machine: the network announces its address, filters attacks with checks that understand the game, and sends the clean traffic to your server through a tunnel.
| Server | Status | Players |
|---|---|---|
| not monitored |
Account
The customer's own prefixes (BYOIP) are announced by the anycast network once you've checked their proof of ownership (LOA, WHOIS, IRR) and verified them, and only while the customer is enabled. Allocated blocks come from the platform's pool.
No IP blocks.
| Prefix | Type | Status | Default Deny | |
|---|---|---|---|---|
| announced not verified customer suspended platform pool |
Game Servers
Each game server is a protected address on the anycast network. Its ports pick their protection; linked to a tunnel, its clean traffic goes to your own server. Open one to see how it’s doing and manage it.
No game servers yet. “Protect a game server” sets one up with its tunnel and ports.
Nothing yet: add a game server or open a port.
| Service | Status | Players | Ports | |
|---|---|---|---|---|
| not monitored |
|
This node isn't filtering, so it tracks nothing.
No open connections.
| Server Port | Remote | Protocol | State | Expires in |
|---|---|---|---|---|
| — |
Where the address's clean traffic goes. Tunnels are managed on their own pages under Networking.
Each address you add is protected by the nodes, and its traffic is forwarded through this tunnel to your server. Open ports or add game servers on the address's page afterwards.
No free IPv4 addresses in your IP blocks.
None yet. Add addresses here, or protect a game server and choose this tunnel.
Round Trip
No probes yet (an origin behind NAT isn't probed; its keepalives are the signal).
Traffic
Tests
| Hop | Address | Network | Loss | Best | Avg | Worst | Jitter |
|---|---|---|---|---|---|---|---|
| origin |
Loss at a hop counts only if every later hop shows it too; a router answering few probes is just rate-limiting them. Conclusions are in the findings above.
Recent events
Run this on your server, on any Linux with systemd. It installs kad-tunnel as a service that starts at boot, and from then on the panel sets its addresses and upgrades it. The command works for an hour.
A newer kad-tunnel is available. Upgrading takes a few seconds of downtime; if the new version keeps failing, your server goes back to the previous one by itself.
Set it up by hand instead
Run these as root on your server so it accepts the forwarded traffic and replies through the tunnel:
Address Lists
A named list of addresses and prefixes that allow and block rules on any of your addresses can use: for example the admins allowed to RCON every game server. Change the list and every rule on it follows within seconds. Add a rule from an address's Firewall tab.
No address lists yet.
Address Space
No addresses yet. Protecting a game server protects its address.
Tunnels
Each customer tunnel carries its game servers' clean traffic from the anycast nodes to the customer's own server, and the server's replies back. Health is as this node sees it.
No tunnels yet. A customer's first game server sets one up.
No query port is protected, so KAD can't see what the server tells the server browser. Add the game's query port (Source engine protection) under Ports.
| Name | Score | Time |
|---|---|---|
| Rule | Value |
|---|---|
This game server's ports: its primary port (the address and port it's known by) and the ports that belong to it. Each picks its protection; traffic to a port no game server on the address has is handled by the unmatched-traffic setting.
No ports.
For people: shown when the server doesn't answer queries (while it answers, the panel shows the name it reports). Change it any time; the server is known by its address and port.
Monitoring is off for its tunnel, so it isn't counted either.
Domains
No domains configured
| Name | Track | Metric | Period | Threshold | Action | Cookie |
|---|---|---|---|---|---|---|
| Node | Step | Mode | Request Rate | Error Rate | Baseline | Time |
|---|---|---|---|---|---|---|
No subdomains configured
Tunnels
A tunnel carries a protected address's clean traffic from the anycast nodes to your own server (the origin), and its replies back. Add addresses to it to use it.
No tunnels yet. Create one to your game server, or use "Protect a game server" on the customer's overview.
No users
BGP
Each node's router ID and local AS are its own, set when it was deployed; its page under Nodes shows them.
Live Status
BGP speaker is disabled. Enable it in the [bgp] section card above.
BGP isn't configured.
Global communities go on every announcement (routes, customers' BYOIP prefixes, RTBH routes) unless the announcement overrides them. Standard ASN:value or large a:b:c; Vultr's IXP route servers only read large ones.
No configured routes.
:
;
; NO_EXPORT; NO_ADVERTISE
added to the configured route
| Prefix | Communities | Prepends |
|---|---|---|
|
|
Alerts
Diagnostics
Every node traces the route to a player's address, MTR-style, and compares them: which node they're closest to, and where latency or loss starts.
See what every node does with one address's traffic for a set time.
How tracing works
See what every node does with one address's traffic, a player's or one hosted on the network, for a set time: each packet XDP passed, dropped or answered (and which stage did it), what the query cache answered, and what left for that address. With "Capture packets" on, the packets themselves are captured too, downloadable as one pcapng file for Wireshark, with a section per node. The trace runs on every node at once, since traffic reaches whichever node is nearest its sender.
| Node | Trace | |
|---|---|---|
Nothing traced yet.
Threat Detection
Maintenance
No maintenance is scheduled.
Nothing is running. Runs go one node at a time, and each node must come back healthy before the next one starts; a node that restarts or reboots withdraws its routes first, so traffic moves to the others.
Paused: a node failed its turn. Retry or skip it below, or abort the run.
This node runs . Upload a new kad binary to stage it on every node, then roll it out. A node that doesn't come back healthy on the new build rolls itself back and pauses the run.
Patches every node one at a time, each back healthy before the next.
What patching does
Each node in turn repairs any unfinished packages (dpkg --configure -a), refreshes its package lists, checks what a dist-upgrade would do (refusing to remove packages kad needs), upgrades, removes unneeded packages, and verifies every package landed. A node reboots when the updates need it (a new kernel), and must come back on the new kernel. Tick below to reboot every node regardless.
None kept yet: this node keeps the version it runs once it has run for 10 minutes.
| Version | Good Since | Last Ran Here | |
|---|---|---|---|
| previous |
If the panel itself is down, run kad rollback as root on a node: it goes back to the last good version there and restarts kad.
Serving:
| Node | Serves |
|---|---|
| Kept | Commit | API | |
|---|---|---|---|
| serving | |||
| serving |
Next runs:
Nothing scheduled. Pick a time for a run:
Node Firewall
No baseline rules to suppress
No node-specific rules
| Name | Protocol | Dest Port | Source | Action | Actions |
|---|---|---|---|---|---|
Select a node above to manage per-node overrides.
Reserved Addresses
No slice set aside yet: shared reservations may use any free address the network announces. Set a slice aside on IP pools (Set aside for the platform…) to keep the platform's addresses together.
| Slice | Pool | Reserved in It |
|---|---|---|
Nothing reserved yet. Reserve a tunnel endpoint before customers add tunnels, and an address for websites before setting them up.
| Address | For | Used by | |
|---|---|---|---|
|
|
IP Pools
No pools yet. Add the prefixes the platform hands out from.
| Prefix | Family | Allocated | Free | |
|---|---|---|---|---|
|
|
Nothing allocated yet: use Allocate… on a pool.
| Block | Customer | Pool | |
|---|---|---|---|
|
|
Websites
HAProxy serves customers' domains with TLS, certificates, challenge pages and rate limits.
| HAProxy process | running not running |
| Served on | |
| Certificate email | |
| Total customer domains |
The addresses websites are served on. Every node holds them and HAProxy listens there; customers point their domains at them. Pick from the addresses reserved for websites.
Certificates for customers' websites and the panel's own hostname come from Let's Encrypt (ACME), which needs an email address for expiry notices. A customer can't set one of their own, so this one is used for all of them.
Every node installs HAProxy (3.4 or later) now, in the background; it serves once there's a website or a panel hostname. This updates by itself.
A node that can't install it says why on its page (Websites check).
Websites belong to customers: open a customer's Websites to add its first domain.
| Customer | Domain | Subdomains | Cert | |
|---|---|---|---|---|
| yes no | Manage… | |||
| No domains configured. Pick a customer to add one. | ||||
Certificates
No certificates found
Suspicion Scoring
No datacenter ASNs
No VPN ASNs
No JA4 fingerprints
Unable to load MaxMind status
The MaxMind license key and database updates are under Settings → GeoIP.
Rate Limits
Anomaly Detection
No domains currently escalated
| Source | Node | Customer | Domain | Step | Effective Mode | Request Rate | Baseline | Time |
|---|---|---|---|---|---|---|---|---|
| Address | Banned | Time Left | Failures | |
|---|---|---|---|---|
| repeat |
No banned address matches.
No address is banned on this node.
This node's kad doesn't report checks yet.
Not collected yet.
- Release
- Kernel
- Updates
- Reboot
- Held, Broken
- Package Lists
This node's kad doesn't report its machine yet.
- Disk
- Memory
- Load
- Tunnels
- Vultr
- State
- Addresses
- Bandwidth
No maintenance turn on record.
Node settings
What this node uses instead of the cluster's shared settings.
- BGP Router ID
- Local AS
- BGP Peers
- Admin Panel
- Customer Panel
Game Servers
Game protection is what KAD is built for. A customer's game server runs on their own machine (the origin). KAD announces a protected address from every anycast node, filters attacks at the XDP layer with game-aware checks (Source engine challenges and query caching, Rust/RakNet handshakes, rate limits), and forwards the clean traffic to the origin through a tunnel.
To start, pick a customer and run the wizard: it creates the tunnel to their server, the protected address and the game's ports, and prints the commands to run on the origin.
There are no customers yet. Create a customer first.
Users & Groups
Accounts for this admin panel, shared by every node. A user can do what their groups allow, plus capabilities granted to them and minus those denied. Customer accounts are managed on each customer's Users page.
Copy it now: it is shown only once. It has the user's capabilities.
Settings
Unable to load SSH settings.
SSH Keys
Nodes accept SSH by key only: kad turns password logins off on each node that has a key. Keys a VM was created with keep working; remove those on the node itself.
| Name | Key | Added | |
|---|---|---|---|
|
No keys added here yet.
SSH Bans
Nodes
/etc/kad/kad.toml and restart kad to change them.
sudo kad bootstrap --cluster-secret <…> on this node to enable cluster sync.
KAD keeps this list in step with the nodes: the polling node adds each node's addresses and removes a VM's when it's deleted. Entries you add yourself stay.
Vultr only accepts this key from the listed addresses. Turn on "Keep the API key's access list in step" above and KAD adds and removes the nodes' addresses itself.
The list is empty, so the key accepts any address. KAD leaves such a key alone: a first entry would make it accept only the listed addresses.
Allow List
Nothing on the allow list.
Deny List
Nothing on the deny list.
These settings are shared by every node in the cluster. Each node applies them within 30 seconds of a change. Nothing has been saved here yet, so each node runs with its own kad.toml values (shown below).
This Node
| Admin panel listens on | |
| Customer Panel | |
| Panel Hostnames | |
| Request limit per client |
Customer Panel
When enabled, the customer panel listener binds and customer users can log in. Default port: 8444.
Bind Addresses
Cluster-shared bind addresses. Must be 127.0.0.1 or 0.0.0.0. Leave a field empty to use each node's own kad.toml bind. A panel hostname below forces its panel onto 127.0.0.1.
Panel Hostnames
When set, each node asks for the hostname's certificate (Let's Encrypt; point its DNS at the websites address first) and HAProxy serves the panel on it. Once a node holds the certificate, the panel's own ports (8443, 8444) close on that node; until then they stay open, so you're never locked out. To reach a node's panels directly afterwards, run kad panel-access allow <your IP> on it as root, or kad panel-access open in an emergency. Leave a field empty to remove it.
Request Limits
Requests per second each client address may make to a panel, plus a burst allowance. Applies without restarting the listeners.
GeoIP
KAD keeps MaxMind's free GeoLite2 databases (ASN and Country) current on every node: in a cluster, the node that acts for the cluster downloads them and sends them to the others, and if it goes offline the next node in line takes over. Suspicion scoring uses them for visitors' countries and network types, and tunnel path traces for network names. Get an account ID and license key with a free GeoLite2 account at maxmind.com (Manage license keys).
Unable to load GeoIP settings.
| Node | GeoLite2-ASN | GeoLite2-Country |
|---|---|---|
Certificates
No certificates yet. Request one for a domain above, or upload your own.
Challenge Page
Shown to visitors of your websites when they are asked to prove they are human.
Only customer admins can change the branding.
Suspicion
Every visitor to this customer's websites gets a suspicion score from signals such as datacenter or VPN networks, reputation and location. Visitors scoring at or above the threshold are challenged. Country and continent lists raise or lower the score by location.
| Continent | Trusted | Suspicious |
|---|---|---|
Only a customer admin can change these settings.
Rate Limits
HTTP rate limits for this customer's websites, enforced by the proxy on every node. They apply to all the customer's domains unless a domain sets its own. Game and other UDP services are rate-limited per protected address instead.
Only a customer admin can change rate limits.
Anomaly Detection
Learns each domain's normal request rate. When traffic or errors stay well above it, the domain's protection steps up the escalation ladder, and steps back down once traffic settles.
None. All this customer's domains are at their normal protection.
| Domain | Step | Protection Now | Normal Rate |
|---|---|---|---|
Each step replaces the domain's protection while it stays escalated.
Only a customer admin can change these settings.
Threat Detection
Floods the nodes detected against this customer's addresses. Blocking rules drop the traffic on every node until they expire. Recommendations are floods that weren't confident enough to block on their own: block or dismiss them here.
No floods detected against this customer right now.
Alerts
Active alerts about this customer's services: attacks, tunnels going down, certificates, quotas.
No active alerts.
Quotas
How much of each resource this customer uses, against its limit. At the limit, new items are refused; nothing existing is removed.