Skip to Content
Virtual ServerVirtual Server Network Policy

Virtual Server Network Policy

This page covers the network specifications, recommended settings, and security policies for Virtual Server.

Network Specifications

ItemDetail
Instance bandwidthUp to 25 Gbps
BackboneDedicated backbone, 800 Gbps+
RoutingAnyCast, Korea-optimized paths
DDoS mitigationIncluded by default
TrafficMonthly allowance divided into a daily limit; throttled when exceeded

For traffic pricing and routing profiles (General / China Optimized / China Direct), see the Plans page.

AnyCast Routing

PacketStream uses AnyCast to deliver traffic over the path closest to each user.

  • Low latency: Automatic routing to the nearest edge
  • High availability: Automatic failover when a path degrades
  • Load distribution: Traffic spread across multiple points
  • DDoS absorption: Attack traffic absorbed across multiple points

MTU Settings

Because AnyCast paths add tunnel encapsulation overhead, we recommend lowering the MTU.

SettingMTUFragmentationNotes
Recommended1400NoneBest throughput and stability
Acceptable1476LowGenerally usable
Standard1500PossibleMay degrade on some paths

Why MTU 1400 is recommended:

  • Accounting for tunnel overhead (~20–100 bytes), packets are not fragmented along intermediate paths.
  • Removing fragment reassembly improves throughput and TCP efficiency.
  • Performance stays consistent even when the AnyCast path changes.

Port Policy

Some ports are restricted to prevent abuse. A few can be unblocked after you justify the intended use.

Blocked by Default (can request unblock)

PortProtocolServiceUnblock Condition
25TCPSMTPAfter justifying sending purpose
137–139TCP/UDPNetBIOSBusiness file sharing
445TCP/UDPSMBBusiness file sharing
1688TCP/UDPWindows KMSLicense management

Permanently Blocked (cannot be unblocked)

PortProtocolServiceReason
17TCP/UDPQOTDPrevent DDoS amplification
19TCP/UDPChargenPrevent DDoS amplification
1900TCP/UDPSSDPPrevent UPnP abuse
11211UDPMemcachedPrevent DDoS amplification
53413UDPNetis backdoorBlock known vulnerability

ASN-based Restrictions

Networks with frequent abuse are subject to communication or rate limits.

ASNNetworkRestriction
AS202425IP Volume IncRate Limit
AS399471SERVERIONCommunication limit
AS213035SERVERIONCommunication limit
AS207566changway-asRate Limit

Contact

For network configuration questions or port unblock requests, use the ticket system in the console or contact support.