Protect your servers with kernel-level precision.
XDP stops volumetric attacks before the network stack. nftables filters remaining traffic with a stateful firewall. Two independent layers, one panel.
Install with
one command.
The agent detects the kernel, network interfaces and existing firewall conflicts. Compatible with Debian 11+, Ubuntu 22+, kernel 5.9+.
Kernel, interface, iptables/nftables/Docker conflicts. Single binary, zero dependencies.
Gaming, anti-flood, rate limiting, amplification, ICMP, VoIP. XDP + nftables.
Describe your rule in plain language, the AI generates the configuration.
XDP + nftables. Defense in depth.
Every packet traverses two independent filters. XDP eliminates volumetric noise. nftables inspects the rest.
Before the kernel
Stateless. Drop at the earliest point in the kernel, before any memory allocation. Up to 256 simultaneous rules per interface.
- ✓ Rate limit per port (pkt/s)
- ✓ Block by protocol and port range
- ✓ Blacklist / Whitelist IP (BPF map)
- ✓ Anti-amplification UDP
After the kernel
Stateful. Conntrack, TCP flags, NAT, per-connection rate limiting. The intelligent layer for application-level attacks.
- ✓ SYN flood protection (conntrack)
- ✓ SSH brute force block
- ✓ Per-connection rate limit
- ✓ Isolated table (zero Docker conflict)
Every agent. All features included.
Real-time monitoring
Marketplace
77 XDP + nftables templates. Gaming, anti-flood, VoIP, infra. One-click deploy.
Zero-downtime hot-swap
Modify your rules on the fly. Zero impact, zero network restart.
Integrations
Pterodactyl, Pelican, public REST API. Integrate protection directly into your panel or software.
One price. No surprises.
Pay per protected server. No tiers, no hidden fees.
1 agent = 1 VPS or 1 dedicated server (one network interface)
No commitment · no credit card
Built on auditable primitives.
Every component has a public audit trail. No black boxes, no marketing promises — just auditable code.
XDP code upstream in the Linux kernel since 2018. Verified by the BPF verifier before load.
Agent ↔ backend mutually authenticated by certificate. Passwords hashed with memory-hard Argon2id.
Payments processed by Stripe (PCI DSS level 1). We never see your card number.
Infrastructure hosted in France. Metrics kept 90 days max, no packet capture, zero data resale.
Frequently asked questions
Everything most people ask before installing.
What is XDP and how is it different from iptables or nftables?
Does installing PAKKT require a server restart?
Does PAKKT conflict with Docker, fail2ban or an existing firewall?
Which operating systems and kernel versions does PAKKT support?
How much does PAKKT cost? Is there a free trial?
Does PAKKT log or forward my server traffic?
What latency does PAKKT add to legitimate traffic?
Can I uninstall PAKKT cleanly?
Ready to protect your servers?
Deploy the agent in under 60 seconds. 7-day free trial, no commitment.