Protected IP for UDP games: gameplay, heartbeats and reconnections
Validate protocol behavior and legitimate sessions through mitigation and forwarding.
Contents of this article
Separate gameplay from web downloads
Live gameplay may exchange short UDP messages while websites, patches and account services use HTTP or TCP. Inventory every service and confirm protected-IP support for each protocol and port.
Describe legitimate traffic
Provide message sizes, heartbeat intervals, peak sessions, regions and port behavior. UDP lacks a TCP-style connection handshake; session association and idle handling must be validated against the actual forwarding implementation.
Inspect the latency distribution
Test room entry, sustained play, network changes and reconnection from key regions. Observe latency, jitter, loss and disconnects. Confirm legitimate bandwidth, packet processing and attack capacity separately.
Restrict direct origin bypasses
After verifying the protected path, restrict direct origin access while retaining controlled administration. Validate only in authorized environments within an agreed traffic scope, focusing on legitimate player sessions.
References
RFC 8085: UDP Usage Guidelines
