In the short time I've been a sysadmin my forum has come under a number of DoS and DDoS attacks, some of them quite large. I use CSF (a WHM frontend for iptables), but it's been my experience that fighting flooding attempts will quickly overwhelm even the best software. Blocking illegitimate traffic syphons memory and bandwidth from legitimate traffic. I guess what I'm saying is software is a poor substitute for hardware. Even an entry-level $200 Cisco device has smarter, more efficient packet filters. you'd be hard-pressed to find any datacentre that doesn't have a firewall. My advice to other sysadmins is software is great, bu you need a second line of defense. If you get attacked, it's your host's responsibility to block the traffic at their routers. They're capable of it in most cases and if they can't or won't do it, leave and find a better host.
|