Anti-VPN for BungeeCord and Waterfall
One installation on your BungeeCord proxy checks every player before they reach a backend. Free, open source, with country rules and the detection services you choose.
- Install on
- The BungeeCord proxy
- Java
- 8 or newer
- Works with
- BungeeCord, Waterfall
- Checked
- At login, before any backend
Why check at the proxy
- The proxy receives every player connection with the real client address. One installation covers every server in the network.
- Checking once at the proxy avoids duplicate lookups on each backend, so your detection quota lasts longer.
- Backend servers don't need a copy. Make sure they only accept connections from your proxy; Connection Guard doesn't replace that.
Set up on BungeeCord
Download the JAR
The same file runs on every platform: Modrinth, Hangar, SpigotMC or GitHub.
Put it into the proxy's plugins folder
Only on the proxy. Remove older Connection Guard JARs first.
Start the proxy and review config.yml
The shipped config already refuses VPN and proxy hits and blocks CN and RU. Change it now if that isn't your policy.
Watch before you block (optional)
Turn kicks off and staff alerts on for a few days, as shown here, then set kick-player back to true.
Check an address
Run the command below to see what each service reports for an address.
cg info 203.0.113.7
# plugins/…/config.yml: warn staff first, block later behavior: vpn: kick-player: false notify-staff: true geo: kick-player: false notify-staff: true type: 'BLACKLIST' list: []
New to anti-VPN plugins? Read how to block VPNs on a Minecraft server and how country rules work.
What you control
- VPN and proxy checks
- ProxyCheck, IP-API, IPHub, VPNAPI or your own REST API. With several services, choose how many must agree.
- Country rules
- A blocklist or an allowlist of countries, with its own action and message.
- Your response
- Refuse the connection, alert staff in chat, post to a Discord webhook or run a console command.
- Caching
- Answers are kept in SQLite or Redis, so repeat logins from the same address don't spend your lookup quota.
- Exemptions
- Let trusted players or addresses through by UUID, IP or LuckPerms permission.
- Inspect any address
- /cg info shows what each service reported, so you can see why a player was flagged.
BungeeCord questions
Does it work on Waterfall?
Connection Guard ships one JAR for BungeeCord-based proxies, and the release lists Waterfall as a supported loader. Test on your own proxy version before going live.
Do I need to install it on my backend servers too?
No. Install it on the proxy that receives player connections. Backends behind the proxy only need to be locked to the proxy, which you configure in BungeeCord and your server software.
Is Connection Guard free?
Yes. The plugin is free and open source under the MIT license, and no Connection Guard account is needed. The detection services you choose have their own free plans and limits.
Will it slow down logins?
A new IP address is checked once during login with the services you enabled. The answer is cached (VPN results for 24 hours and country results for 72 hours by default), so the next login from the same address needs no lookup.
Can I warn staff instead of kicking players?
Yes. Set kick-player to false and notify-staff to true for VPN or country rules. Staff with connectionguard.notify.vpn or connectionguard.notify.geo then see an alert, and you can also post to a Discord webhook.
Can I let specific players through?
Yes. Add their UUID or IP address under behavior.vpn.exemptions and behavior.geo.exemptions. Permission-based exemptions use LuckPerms and need the matching use-permission-exemption switch.