TCP Shield allows you to offer DDoS protection services to your clients. This module integrates with Blesta to automate the provisioning and management of TCP Shield services. Everything you need
From £19.99 - View Pricing
What TCP Shield gives you
Gives both your staff and your clients a purpose-built interface in their own area of Blesta.
Renaming the service in Blesta renames the network at TCPShield too, so the two never drift apart.
Configure it independently for each brand on a multi-company install, so every company runs with its own settings.
Clients add and remove CIDR firewall rules with a whitelist toggle, keeping unwanted networks away from their servers.
Every staff and client label ships in editable language files, ready to translate into any language or reword to match your brand.
Charted player counts and bandwidth for the last 24 hours, 2 days, or 7 days, so clients can see their traffic and you can see theirs.
Bedrock players are covered too - clients create tunnels with their own name, backend set, location, and proxy protocol from a dedicated tab.
A built-in demo mode runs the whole extension from bundled sample data, so you can trial every screen and action before you have an account or API key.
Your team gets the same Domains, Backends, Bedrock, Firewall, and Statistics tabs on the staff side of the service, so support can fix a client's setup for them.
Suspending a service silently neutralises the client's backends instead of deleting their configuration, and reactivating restores every backend exactly as it was.
Clients create and edit backend sets with their own backend addresses and proxy protocol setting, so they can repoint traffic themselves whenever their servers move.
Cap how many domains and how many backend sets a package allows, and the limit is enforced when the client tries to add another. Leave either blank or 0 for unlimited.
Clients add, edit, and remove their own domains, assign each to a backend set, toggle Badlion support, and prove ownership through a guided TXT-record verification flow built into the tab.
The Domains tab walks the client through the whole onboarding - their protected anycast CNAME, the RealIP plugin download for Bungee, Spigot, and Velocity, and the exact DNS records to create - so a new customer gets protected without opening a ticket.
A paid order creates the client's TCPShield network and stores its protected CNAME against the service, so protection is live the moment they pay. Every network is named with your own prefix, keeping one TCPShield account tidy across hundreds of clients.
v2.0.0 - 2026-09-11
PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x
Security: a domain, backend set, Bedrock tunnel or firewall rule id posted from a tab is now checked for shape and re-matched against the service's own network before any call is made, and every id is URL-encoded into the request path - a crafted id previously steered the call at a different network on the same TCPShield account, with the account API key attached, and only the module log showed it. The Network ID is an admin-only field and is now dropped from any client-driven order or service edit and rejected when another active service already holds it - a client could otherwise bind their service to another customer's network and then rename, manage or delete it.
Fixes: a failed backend-set update during suspend or unsuspend is now reported instead of silently ignored (a service could read Suspended while it kept proxying traffic, or stay dead after payment); the pre-suspension snapshot is written before anything is changed, is no longer overwritten by a second suspension - which used to replace the stored backends with 0.0.0.0:0 permanently - and is cleared once restored. Every delete in the Domains, Backends, Bedrock Backends and Firewall tabs now asks for confirmation, and the record to delete travels in its own field so a delete cannot act on the wrong row. API calls carry a total timeout, not only a connect timeout, so a stalled response no longer holds a page or a cron run until PHP's execution limit, and the TLS floor is TLS 1.2. An API response whose body spans more than one line is no longer truncated to its last line (it decoded as nothing while the request still read as successful). A backend list typed without spaces after the commas is split correctly instead of being sent as one malformed backend, and the expected format is spelled out in the tab. The statistics charts cast their plotted values numerically. The five staff-side service tabs (Statistics, Domains, Backends, Bedrock Backends, Firewall) now have their own admin-styled views instead of reusing the client portal's layout, so they match the rest of the admin panel instead of looking visibly out of place. The staff-side domain verification popup no longer renders as duplicated, unstyled chrome on top of the admin theme's own dialog; it now uses an admin-styled view like the rest of the staff tabs. The API Key and Mock API field help tooltips on the Add Account and Edit Account forms no longer drop onto their own line under the field; the Mock API checkbox tooltip in particular no longer floats disconnected from its checkbox.
Features: staff can now manage a client's domains, backends, Bedrock tunnels and firewall from the admin service page; the protected CNAME is stored as a service field, shown on the service summary and available to the welcome email as a tag; renaming a service now renames its TCPShield network; the Statistics tab has a period selector (last 24 hours / 2 days / 7 days); packages can cap the number of domains and backend sets a client may add.
Action required after upgrading from v1.0.0: re-save each TCPShield account. v1.0.0 stored the account API key in plain text, offered it as an email tag and used it as the account's display key; all three are fixed, but an existing account keeps its plaintext key until it is saved again.
v1.0.0 - 2024-09-22
PHP 7.2 - 7.3, 8.1 - 8.4 · Blesta 5.x
Blesta Club release
Get exactly what you need and want.
Requires PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x
Value: £42.3
Not sure whether to lease or own? Our FAQ explains how the licence types differ.
What our customers say
(0 customer reviews)
It is possible to leave a review only if you have purchased this extension or a Club tier which contains it.
We reserve the right to alter wording or formatting for presentation.
We will discuss any changes made and offer the option to withdraw review text if the changes can't be agreed on.
It may take up to 1 hour for a review to appear or update due to caching.
More extensions to explore
Module
Integrate BunnyDNS for automatic DNS provisioning and management.
PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x
Module
Integrate Cloudmini for automatic cloud hosting provisioning.
PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x
Module
Provision servers using Convoy, a Proxmox based VPS management panel
PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x
Module
Integrate Datalix module into your Blesta install to provision VPS servers.
PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x
Module
Integrate Enhance for automatic provisioning and management.
PHP 8.2 - 8.4 · Blesta 6.x
Module
Integrate Hetzner Cloud for automatic server provisioning.
PHP 7.2 - 7.4, 8.1 - 8.4 · Blesta 5.x