# Filterprofile

> Protokollbewusste Profile für Gameserver, VoIP, DNS und Web – eines pro Portbereich.

Source: https://docs.avenlith.com/de/filtering-profiles  
Category: DDoS-Schutz  
Last updated: 2026-09-22

## Warum Profile wichtig sind

Generische Filter sehen nur Paketraten. Profile verstehen das Protokoll: Sie wissen, dass eine gültige Source-Engine-Abfrage einen bestimmten Header hat, ein Minecraft-Login mit einem Handshake beginnt oder DNS-Antworten zu einer vorherigen Anfrage passen müssen. Angriffstraffic, der für generische Filter gültig aussieht, verwirft das Profil.

## Verfügbare Profile

| Profil | Protokolle | Typische Ports |
| --- | --- | --- |
| game-source | CS2, TF2, Garry's Mod (A2S) | UDP 27015–27030 |
| game-minecraft | Java und Bedrock | TCP 25565, UDP 19132 |
| game-rust | Rust / RakNet | UDP 28015–28016 |
| game-fivem | FiveM / RedM | TCP+UDP 30120 |
| voip-sip | SIP, RTP | UDP 5060, 10000–20000 |
| dns-auth | Autoritatives DNS | UDP/TCP 53 |
| https-strict | TLS-Handshake-Prüfung | TCP 443 |
| generic | Nur Raten- und SYN-Schutz | beliebig |

## Regeln anlegen

```bash
avenlith shield profile list
avenlith shield rule create --target 203.0.113.24 --protocol udp --port 27015-27030 --profile game-source
avenlith shield rule create --target 203.0.113.24 --protocol tcp --port 443 --profile https-strict
avenlith shield allowlist add 203.0.113.24 --source 198.51.100.7/32   # monitoring probe
```

> **Tip:** > Setzen Sie Monitoring- und Payment-Provider-IPs auf die Allowlist, damit sie bei einem Angriff nie geprüft werden.

## Auswertungsreihenfolge

Allowlist → Blocklist → Portregel mit Profil → Standardprofil der IP. Die erste passende Regel gilt.
