Skip to main content
Remote DDoS protection via WireGuard lets you place any server behind Packets Decreaser’s scrubbing infrastructure using a modern, lightweight VPN tunnel. Like the GRE option, Packets Decreaser sets up the tunnel over IPv6 and routes your protected IPs to the endpoint entirely in software, but WireGuard has stricter throughput limits, so it is best suited for lower-traffic workloads.

How it works

WireGuard creates an encrypted point-to-point tunnel between your server and the Packets Decreaser scrubbing network. All inbound traffic to your protected IPs is scrubbed before being forwarded over the tunnel to your server. Outbound traffic exits directly from your server without passing through the tunnel.
The tunnel endpoint on the Packets Decreaser side is an IPv6 address. Your server needs outbound IPv6 connectivity to establish the tunnel.

Limits

Exceeding 200,000 PPS causes packet loss on the tunnel. Monitor your server’s packet rate and switch to GRE if you approach this limit.

Comparison with GRE

Get started

1

Open a support ticket

Log in to your customer portal and open a support ticket requesting WireGuard tunnel setup. Include the IP addresses you want to protect and the public IPv6 address of your server.
2

Receive your tunnel configuration

Support will provide you with the Packets Decreaser WireGuard endpoint (IPv6 address), a public key, and the protected IP prefixes to route over the tunnel.
3

Configure WireGuard on your server

Install WireGuard on your server and create a tunnel interface using the provided configuration. The exact steps depend on your operating system — support can assist if needed.
4

Verify traffic flow

Confirm that inbound traffic to your protected IPs is arriving through the tunnel and that the scrubber is active. Support can validate the routing on the Packets Decreaser side.
WireGuard’s built-in encryption adds a small amount of overhead. If your server is already near the 200,000 PPS limit, migrate to a GRE tunnel before traffic grows further.