한국어English日本語简体中文繁體中文DeutschไทยTiếng ViệtРусскийPortuguês (Brasil)EspañolBahasa Indonesia

Game Lag White Paper › L2 Client OS and device

Packet inspection by security software Antivirus / firewall inspection

Cause ID co-security · Primary owner External (External) · Also Game team (Client development)

Open the interactive card with figures and simulations →

When antivirus software or a firewall inspects every packet, latency goes up, and in bad cases it mistakes the game for an attack and blocks it.

Why Security software inspects every packet sent and received, one by one → Effect Each packet picks up delay, and packets get dropped when inspection falls behind → On screen Ping spikes irregularly, or connections get blocked

Symptoms
Stutter, Can’t connect / infinite loading
Factors
Jitter, Packet loss
Who’s affected
Just me
When
Always, Right after login or maintenance
Owner
Primary owner External (External) · Also Game team (Client development)
Game team action items
Maintain a security software compatibility list, register a Windows Firewall exception for the game at install time.
External action items
Tell players to add the game as an exception in their security software; if it mistakes the game for an attack, ask the security vendor to fix the false positive.
Ballpark numbers
When everything works normally, packet inspection usually takes under 1 ms. The trouble starts when the inspection module falls behind or has a bug, or when it mistakes game traffic for an attack.
On the graph
Outliers only · RTT, connection failures (per player)
Where to look
Compare after briefly turning off the security software or adding the game as an exception. On Windows, turning on Audit Filtering Platform Connection and Audit Filtering Platform Packet Drop in the audit policy logs 5157 (connection blocked) and 5152 (packet blocked) in the Security log, and Performance Monitor’s WFPv4\Packets Discarded/sec shows the number of discarded packets
Confirmed if
Block records show up for connections or packets to the game server’s address, or ping spikes and connection failures go away with the security software off
Ruled out if
Other devices in the same household behave the same way regardless of security software: the router or connection side
Check with
The player’s own environment

Sources

  1. About Windows Filtering Platform Microsoft
    Packets are allowed or blocked through hooks in the Windows network stack and a filter engine, and third-party security vendors can plug in their own filter modules (callouts)
  2. Windows Firewall Rules Microsoft
    Inbound connections are blocked by default, so apps need exception rules, which the app installer usually creates
  3. Address false positives/negatives in Microsoft Defender for Endpoint Microsoft
    How to set an exclusion and submit a file to Microsoft for analysis when a legitimate program is mistaken for a threat (false positive)
  4. 5157(F): The Windows Filtering Platform has blocked a connection. Microsoft
    Event 5157: Windows Filtering Platform blocked a connection (Audit Filtering Platform Connection)
  5. Audit Filtering Platform Packet Drop Microsoft
    Event 5152: Windows Filtering Platform blocked a packet
  6. Network-Related Performance Counters Microsoft
    WFPv4/WFPv6: Packets Discarded/sec counter

See also

Same layer: L2 Client OS and device

Same symptom (Stutter), other layers

View the interactive card with figures and simulations