Protect any server from DDoS, no network expertise needed.
Attacks die in the kernel, before they reach your machine. Two protection layers (XDP + nftables), one agent you install with a single command, one panel to run it all.
3 € / server / month · 7-day trial · no credit card
Install with
one command.
The agent detects the kernel, network interfaces and existing firewall conflicts. Compatible with Debian 11+, Ubuntu 22+, kernel 5.9+.
Kernel, interface, iptables/nftables/Docker conflicts. Single binary, zero dependencies.
Gaming, anti-flood, rate limiting, amplification, ICMP, VoIP. XDP + nftables.
Describe your rule in plain language, the AI generates the configuration.
XDP + nftables. Defense in depth.
Every packet traverses two independent filters. XDP eliminates volumetric noise. nftables inspects the rest.
Before the kernel
Stateless. Drop at the earliest point in the kernel, before any memory allocation. Up to 256 simultaneous rules per interface.
- ✓ Rate limit per port (pkt/s)
- ✓ Block by protocol and port range
- ✓ Blacklist / Whitelist IP (BPF map)
- ✓ Anti-amplification UDP
After the kernel
Stateful. Conntrack, TCP flags, NAT, per-connection rate limiting. The intelligent layer for application-level attacks.
- ✓ SYN flood protection (conntrack)
- ✓ SSH brute force block
- ✓ Per-connection rate limit
- ✓ Isolated table (zero Docker conflict)
Bans malicious IPs, automatically.
On top of the two layers, Auto Shield spots attackers and bans their IPs on its own, across XDP and nftables at once.
Every agent. All features included.
Real-time monitoring
Marketplace
77 XDP + nftables templates. Gaming, anti-flood, VoIP, infra. One-click deploy.
Zero-downtime hot-swap
Modify your rules on the fly. Zero impact, zero network restart.
Integrations
Pterodactyl, Pelican, public REST API. Integrate protection directly into your panel or software.
The same attack, with and without PAKKT.
A 3.95 billion packet flood hits the same server. On the left without filtering, on the right with PAKKT properly tuned.
One price. No surprises.
Pay per protected server. No tiers, no hidden fees.
1 agent = 1 VPS or 1 dedicated server (one network interface)
7-day trial, no credit card · no commitment
Built on auditable primitives.
Every component rests on open, documented standards. No black box, no empty promises.
XDP code shipped in the Linux kernel since 2018. Validated by the kernel verifier before every load.
Agent ↔ backend mutually authenticated by certificate. Passwords hashed with memory-hard Argon2id.
Payments processed by Stripe (PCI DSS level 1). We never see your card number.
Infrastructure hosted in France. Metrics kept 7 days max, no packet capture, zero data resale.
Frequently asked questions
Everything most people ask before installing.
What is XDP and how is it different from iptables or nftables?
Does installing PAKKT require a server restart?
Does PAKKT conflict with Docker, fail2ban or an existing firewall?
Which operating systems and kernel versions does PAKKT support?
How much does PAKKT cost? Is there a free trial?
Does PAKKT log or forward my server traffic?
What latency does PAKKT add to legitimate traffic?
Can I uninstall PAKKT cleanly?
Ready to protect your servers?
Deploy the agent in under 60 seconds. 7-day free trial, no commitment.