ovh / infrastructure-roadmap

37 stars 1 forks source link

GAME firewall upgrade #135

Open jslocinski opened 1 year ago

jslocinski commented 1 year ago

As a game hosting company, we would like to benefit from the latest security protections for GAME server ranges so we're protected from DDoS attacks targetting various gaming protocols.

VibeGAMESNL commented 1 year ago

How you gonna do this if OVH management refuses to support certain game protocols because of possible "legal" issues? At least that is their excuse when we asked for it multiple times.

jslocinski commented 1 year ago

OVHcloud supports and develops protections for applications that can be hosted on our servers.

sanguine0 commented 1 year ago

Glad to hear the GAME firewall will be getting some love. I hope that detection and filters for the latest A2S query attacks are on the roadmap. We host DayZ, so updated protocol support for DayZ Standalone would be fantastic. I know Arma 2 was supported in the past, so hopefully that wouldn't be a huge leap. Thank you.

jslocinski commented 1 year ago

Thanks for your comment. DayZ is on our list for the next steps, but nothing prioritized yet.. and Arma 2 is supported since long time already.

millieismillie commented 1 year ago

I've had to disable the game firewall because, to my understanding, it consolidates all traffic directed toward Steam's query servers through one IP, which leads to constant rate limiting. While I'm not 100% on the degree to which the traffic is being consolidated, I do know that it definitely leads to rate limiting, because I can't get my server listed in the browser without turning off Game Firewall.

If I were to attempt to use it again for any reason, I'd need to know that I'll be able to properly connect to the Steam query servers so that I can get my game servers listed in their respective launchers.

AverieMods commented 1 year ago

More robust DayZ Standalone support in the GAME firewall would be amazing. It's been a common frustration among the community of server owners I've spoken to.

Crossing our fingers this gets pushed near the top of the heap.

gegtor commented 1 year ago

I will also chime in and Unturned support would be great

Currently hl2Source filters in game firewall work great but can be improved upon for Unturned specifically because they can be bypassed with a tailor made attack packets

MikeRuSe commented 11 months ago

How is OVH doing with this topic? As an OVH customer I see that the protection that affects Game range it’s getting outdated. New games are out there (for example CS2) and OVH is loosing actual and future customers because the lack of specific filters.

CS2, updated Raknet (for Rust), updated DayZ, FiveM, updated Minecraft and soon ARK Ascended protocol…

Right now the temporary “patch” that the VAC team perform is applying basic profiles to the IPs which still are insufficient for more dedicated and sophisticated attacks. Also “forcing” somehow customers to build their own filters at the server side which is not optimal and force them move to different providers that have more improved filtering at the network.

As an actual customer, I really think it’s something that requires an update (protocols and filters updated) and more supported applications.

Some ideas: OpenVPN, Source Engine Query, RakNetv2, FiveM Server Query…

ubinoob1 commented 8 months ago

Just add ability to create own profile. Even "allow custom initial packet length" feature will dramatically increase usability of game firewall.

1Ronkkeli commented 6 months ago

Will FiveM Protection be added now that it is officially owned by Rockstar?

VibeGAMESNL commented 6 months ago

@jslocinski, with Rockstar Games officially acquiring FiveM, the previous legal concerns that OVH cited to justify not implementing a DDoS protection filter for FiveM should no longer be an issue. Given that FiveM has been officially acquired by Rockstar for several months now, and its popularity remains undiminished, this change in ownership should eliminate any hesitations regarding legalities.

Could you provide any insights into when OVH might plan to implement a DDOS protection filter for FiveM? The community is keenly awaiting an update on this matter, considering the significant impact it would have on user experience and server stability.

https://www.rockstargames.com/newswire/article/8971o8789584a4/roleplay-community-update

jslocinski commented 6 months ago

Thanks for mentioning FiveM. Yes, we saw that and put in discovery with our engineering teams as well as legal. As we're working on few other updates for game in parallel, we few weeks to share more precisely some details of game evolution. I will come back asap.

jslocinski commented 6 months ago

What I can propose is to create separate issues for every game that needs recent support and vote. That will help us to prioritize

Pb600 commented 2 months ago

Just add ability to create own profile. Even "allow custom initial packet length" feature will dramatically increase usability of game firewall.

Exactly! I've been struggling and searching for OS level ways to filter my layer attacks on a custom game, my application does basic initial connection closing based on packet size & then proceed to authentication & encryption/decryption, but 60K of spoofed handshakes can still damage us very hardly.

I think that what actually should be discussed is a way to be able to create your own custom rules, then community could develop known game protocol rules and everyone would be protected despite what game is being hosted, without requiring OVH to slowly implement new protocols.

Something like snort's rules on the upstream filter would help me immensely!

'drop tcp any any -> any 2525 (msg:"Non-standard TCP handshake size"; flow:to_server,established; dsize:!2; sid:1000001;)'

jslocinski commented 2 months ago

@Pb600 thanks for your remark. Custom GAME protection profile is discussed in the https://github.com/ovh/infrastructure-roadmap/issues/175

Heavens-c commented 2 months ago

how long will prioritize this i'm sick of resellers out there image it really said owned by take two

axl303 commented 2 months ago

@jslocinski

we few weeks to share more precisely some details of game evolution. I will come back asap.

We all know the anti-ddos team is pretty busy, but can we get some light to the GAME things, like network upgrade, game anti ddos as a service, private network connections and this one GAME upgrade and filters with OTHER options and newer games like CS2 and etc...