Global protection for Lineage II servers
Your server can be anywhere.
The attack does not have to reach it.
GX Tunnel hides the real IP, allows protected services to be removed from direct exposure, and connects LoginServer, GameServer and ActiveAntiCheat through Cloudflare's global Anycast network.
The real problem
Your real IP should not be your first line of defense.
When a server is published directly, players and attackers share the same path to your infrastructure. GX Tunnel changes that point of exposure.
DIRECT EXPOSURE
The public route ends at your server.
The real IP and published ports remain within reach of legitimate traffic, scans and attacks.
GX ARCHITECTURE
The public route ends at the global layer.
The player uses a protected domain; the origin maintains an outbound connection, and its real address is not provided as a public destination.
“Your community can reach the server.
Attackers do not need to see where it is.
Specialized infrastructure
More protection.
Less exposure.
An architecture built around the real-world operation of a Lineage II server, from player access to the management of each package.
HIDDEN ORIGIN
The server is no longer the public endpoint.
Players connect to a protected GX domain. The real IP is not distributed as the access address, and protected services can remain outside direct exposure.
ANYCAST
One global entry point
Players can connect through a nearby available point on the network and continue from there to the protected origin.
DYNAMIC IP
The domain stays the same
If the provider changes the public IP, the tunnel can reconnect without requiring your players to change the address.
GX RESUME
Recovery from brief interruptions
When GameServer experiences a brief connection drop, GX attempts to resume transport within a controlled window.
GX CONTROL
Everything centralized
Licenses, installations, origins, renewals and private downloads from a single dashboard.
AUTOMATION
From licensing to delivery
GX Builder prepares the tunnel, domain and custom package while keeping operational secrets outside the public area.
How it works
A protected route from the very first packet.
Public access is moved away from your infrastructure. GX coordinates every layer so the server remains reachable without being published as a direct destination.
-
01
The player connects to GX
They use the protected domain assigned to your project without needing to know the origin's real address.
-
02
The global network receives the connection
Anycast routes the connection through an available location on Cloudflare's network.
-
03
GX Tunnel reaches the server
The outbound connector carries authorized connections to LoginServer, GameServer and ActiveAntiCheat.
Flexible hosting
Your server. Your hardware. Your location.
You do not need to move your project to unfamiliar infrastructure to place a global layer in front of it.
In most scenarios, you need a stable outbound connection, sufficient bandwidth and hardware suited to your player count.
PROTECTED ORIGINProtection before the origin
Malicious traffic meets the global network before it can reach your server.
With GX Tunnel, the public endpoint belongs to the global protection layer. Security is built by reducing the exposed surface, isolating the origin and automating rules for each project.
Reduced attack surface
The IP and protected ports are not published as a direct destination for players.
Global distribution
The global infrastructure can absorb and distribute traffic spikes before they reach the origin.
Isolated origin
The firewall can reserve protected services for the tunnel's private connection.
Managed rules
GX Control keeps each project's configuration, identity and package separate.
| Architecture | Direct server | With GX Tunnel |
|---|---|---|
| Origin address | × Exposed as the connection address | ✓ Hidden from players |
| Protected services | × Published on the Internet | ✓ Outbound tunnel |
| Point of impact | × Server network | ✓ Global layer first |
| IP change | × Requires intervention | ✓ Stable domain |
| Brief GameServer interruption | × May end the session | ✓ GX attempts recovery |
| Provisioning | × Scattered configuration | ✓ Automated GX Builder |
Important: to complete the isolation, the origin IP must not be published through other services, and the firewall must be configured correctly.
Proprietary technology
A brief interruption does not always have to end the game.
GX Resume temporarily preserves the GameServer session state while the client attempts to restore transport. When recovery is possible, the session continues without starting an entirely new connection.
- Designed specifically for GameServer.
- Current client window of approximately 8 seconds.
- Identity validated before resuming.
- Temporary preservation of pending data.
Recovery depends on the duration and cause of the interruption. A prolonged outage, a server shutdown or tunnel termination may require a new connection.
GX Control
Everything you need to operate it, all in one place.
From tunnel creation to final package publication, configurations, licenses and installations remain organized and separated by project.
A model with no wasted months
Buy once. Activate only when you need it.
The license remains permanently assigned to your project. The service is activated in consecutive 30-day periods, with no charges accumulating during paused months.
GX TUNNEL / PER PROJECT
Comprehensive protection
- Custom integration for your project.
- Tunnel, domain and three protected services.
- GX Resume for GameServer.
- Access to GX Control and private packages.
- Installation and origin management.
- Reactivate in the future without buying the license again.
Prices are stated in US dollars. Each activation covers 30 consecutive days.
YOUR SCHEDULE, YOUR RULES
Will your server be offline for six months?
You pay nothing during that period. When you decide to return, you pay US$70 and activate another 30 days. The license remains yours and no charges accumulate.
Getting started
From inquiry to a protected server.
A controlled, customized process. Before creating the package, we verify that your project's architecture is compatible.
- 01
We verify
We review the client, services and configuration of your project.
- 02
We create
We assign an identity, license, domain and private access in GX Control.
- 03
We generate
GX Builder prepares the routes and custom package.
- 04
We activate
You install it, we validate its operation, and you are ready to welcome players.
Frequently asked questions
Everything that matters, with clear terms.
If your client or architecture has a particular requirement, we review it before creating the license.
Discuss my projectWhat is GX Tunnel?
It is a protected connectivity platform developed for Lineage II servers. It integrates the client, LoginServer, GameServer and ActiveAntiCheat with a global network layer and centralized management.
Do I need a fixed public IP?
No. Players connect to the protected domain. If the origin IP changes, the domain does not need to be modified, and the tunnel can re-establish its connection.
Does it work behind NAT or CGNAT?
Yes, provided that the server can establish outbound Internet connections and the network allows the connector to operate.
Do I have to open ports on my router?
Services carried through GX Tunnel do not need to be published directly for players. The exact configuration depends on any other services you keep running on the server.
Does GX Tunnel make the server invulnerable?
No serious solution can promise absolute invulnerability. GX reduces the exposed surface, hides the origin and places a global network in front of it. The real IP must also remain private, and the firewall must be configured correctly.
Does it guarantee lower ping?
The same result cannot be guaranteed across every provider and region. Anycast allows players to enter through a nearby available network location and may improve routing, stability and traffic distribution.
Does GX Resume prevent every disconnection?
No. It is designed for brief GameServer interruptions. A prolonged outage, server shutdown or tunnel termination may require a new connection.
What happens if I do not renew the service?
The permanent license remains assigned to your project. The service is paused and no charges accumulate. You can reactivate it later by paying US$70 for another 30 consecutive days.
Can I move to another computer?
Yes. GX Control lets you securely deactivate the previous installation and authorize the new device under the license terms.
Is GX-EXT part of Cloudflare?
No. GX-EXT is an independent solution that uses Cloudflare technology and infrastructure. It is not an official product and does not imply a commercial partnership.
Your server does not have to be exposed to stay available
Protect the origin. Stay in control. Go live when you choose.
Permanent license for US$300. Activate 30 days of service for US$70 whenever you actually need it.

