Features

The local protection stack behind LetSecure.

LetSecure combines a control panel, XDP traffic protection, and local geo data so public Linux servers can start with focused profiles and grow into custom rules.

System parts

Three components, one host-owned workflow.

LetCore

Use the local dashboard to configure protection, check services, monitor traffic, and manage settings from the server you control.

LetXDP

Apply packet filtering early in the Linux network path for profiles, advanced rules, counters, and traffic logs.

LetGeo

Load updateable local country IPv4 ranges when a service needs geo blocking without turning LetSecure into a cloud control plane.

Protection controls

Features built for exposed servers.

Ready profiles

Start with website, SSH, and host protection profiles instead of writing every traffic rule from scratch.

Game protection

Use the Minecraft profile to validate TCP handshakes before traffic reaches the game server.

Geo blocking

Search countries and block selected IPv4 ranges from the Network configuration page.

Advanced rules

Match protocol, addresses, ports, TCP flags, packet length, and rate limits when a profile is not enough.

Analytics

Compare country traffic and monthly packet history with allowed, passed, and dropped counters plus recent LetXDP logs.

System configuration

Manage host-level security profiles, network settings, UI password, control panel source restriction, and license state from LetCore.

General profiles

Useful protections for common public traffic.

  • Anti-spoofing for private, loopback, and link-local source ranges.
  • Cloudflare-only website traffic on ports 80 and 443.
  • Website rate limiting and adaptive DDoS protection for sudden traffic floods.
  • SSH anti-brute-force controls for high-rate new attempts.
  • SSH IP whitelist for limiting login access to trusted addresses.

System profiles

Harden SSH without hand-editing every file.

  • Disable SSH password login from the System configuration page.
  • Generate a LetCore-managed SSH key for root access.
  • Download the private key after enabling the profile.

Custom traffic rules

Keep control when profiles stop being specific enough.

  • Allow or drop TCP, UDP, QUIC, ICMP, ICMPv6, GRE, ESP, and AH traffic.
  • Scope matches by source or destination IPv4/CIDR and port.
  • Add source and flow rate limits for packets or bytes.

Website protection

Give public web ports a safer default.

  • Limit abusive HTTP, HTTPS, and QUIC traffic patterns.
  • Keep recently active website visitors trusted during a traffic spike.
  • Temporarily restrict unknown new visitors when the server is under flood pressure.

Operations

See what is active before you tune further.

  • Service status and version visibility for LetCore, LetXDP, and LetGeo.
  • Update or reinstall actions when a local component needs a refresh.
  • Analytics, logs, and counters for checking protection changes.

Workflow

Start small, then become precise.

Enable the profile that matches the host, test the real service, watch Analytics, and add geo blocking or advanced rules only where the server needs them.