Portal Home > Knowledgebase > Articles Database > ddos help


ddos help




Posted by Prajyot, 10-26-2009, 12:09 PM
i have windows 03 server getting ddosed many times. attack was upto 2gbit so any way to stop it? Would a higher connection speed/bandwidth limit help? And about load balancing, would more servers help prevent the DDoS? any server administrator will help. we are ready to hire

Posted by bizness, 10-26-2009, 12:49 PM
if the DDOS was 2gigabits and your NIC on the server is 100mbit. No matter what you will do, the DDOS will kill your nic at 95% utilization. This is something your provider / upstream would have to handle.

Posted by Prajyot, 10-26-2009, 12:53 PM
currently we are on 100mbit but we are thinking about 1gbit link. what will happens if we are on 1gbit

Posted by eth00, 10-26-2009, 01:56 PM
If you "only" have a 1Gbps NIC and you get a 2Gbps attack it will still saturate it. That is aside from the fact the server itself probably would not be able to handle all that traffic. Once you saturate the connection you will start to get a lot of packet loss and connection problems, assuming the server could handle that much traffic without crashing.

Posted by Secter, 10-26-2009, 02:30 PM
A larger uplink will not help if it is a 2Gbps attack. Think about it, if your car held 15 gallons of fuel and you tried to put 30 gallons in at once, your fuel tank would overflow.

Posted by Prajyot, 10-26-2009, 02:34 PM
so there any way to stop it like some SW firewall etc?

Posted by jon-f, 10-26-2009, 11:19 PM
For 2gbs you would have to have a network solution for that where they have dedicated hardware with big pipes to process that much incoming. To buy dedicated 2gbs of traffic would be very expensive. you can get a ddos protection proxy for much cheaper. I think blcc has some solutions to protect windows servers, check them - they will be much cheaper then prolexic or gigenet - blacklotus.net

Posted by AdmoNet, 10-26-2009, 11:20 PM
Hello, The main thing is to filter the attack before it arrives at your network. Good luck and I hope you find a solution.

Posted by PeakVPN-KH, 10-27-2009, 02:17 AM
There are several providers that can provide this form of protection to a Windows server. In most cases, it would require a proxy or tunnel for protection. Whoever does it, will have to have actual network-based protection. Staminus.net is another good provider. Best of luck!

Posted by inspiron, 10-27-2009, 07:46 AM
Use Iptables network firewall for narrow the packets.

Posted by WebFoundation, 10-27-2009, 12:27 PM
Your best bet, as others have suggested is to jump to a network or get proxied by one that has invested significant amount of money and resources into handling things like this. iptables for 2Gbp/s flood? Do you seriously believe that will ever work?

Posted by PeakVPN-KH, 10-28-2009, 09:32 PM
Attack was up to 2Gbps... That's horrible advice 2Gbps ----> 100Mbps NIC.... Doesn't fit. You require a DDoS provider or network-based DDoS protection in between to filter the attack and deliver the clean traffic to you at a speed <100Mbps that you can handle.

Posted by jjk2, 10-28-2009, 09:42 PM
would DDOS attack help be covered in managed hosting solutions ? or is there a software that can block this kind of attack ?

Posted by AdmoNet, 10-28-2009, 10:10 PM
Hello, Check out RioRey devices. We've had plenty of experience with them. Here's their site: RioRey Here's a quick review I wrote up after using them: RioRey Review



Was this answer helpful?

Add to Favourites Add to Favourites    Print this Article Print this Article

Also Read
csf on Openvz node.. (Views: 462)