AntiDDoS protection?

I've was using a OVH VPS for DDoS protection with custom iptables, but seems like OVH's AntiDDoS is really bad and let's thru most of the attacks. Any good alternatives?
231 Replies
Admincraft Meta
Admincraft Meta7mo ago
Thanks for asking your question!
Make sure to provide as much helpful information as possible such as logs/what you tried and what your exact issue is
Make sure to mark solved when issue is solved!!!
/close !close !solved !answered
Requested by bruhdows#0
Jenkins
Jenkins7mo ago
OVH is very good
Bruhdows
BruhdowsOP7mo ago
Yeah, but most of the attacks go thru lagging out the server
Jenkins
Jenkins7mo ago
can you show the logs from the ovh dashboard
Bruhdows
BruhdowsOP7mo ago
I have Gate Lite on my VPS proxying connections to main Dedicated Well I have an ongoing attack right now litterary, but I switched to neoprotect temporaily
Jenkins
Jenkins7mo ago
Can you show logs of the network scrubbing center
Bruhdows
BruhdowsOP7mo ago
Yeah, give me a moment
Bruhdows
BruhdowsOP7mo ago
No description
Jenkins
Jenkins7mo ago
That's not good Can you show the network logs and see the leaking traffic
Bruhdows
BruhdowsOP7mo ago
Yeah I know, tried blocking it using IP Tables, but most of time they are finding new one Yeah, moment
Jenkins
Jenkins7mo ago
You can deploy the Edge Firewall instead of blocking it on your machine, should prevent your server from being exhausted
Bruhdows
BruhdowsOP7mo ago
I've did, but the rules seem very limited That's my current rules
Bruhdows
BruhdowsOP7mo ago
No description
Bruhdows
BruhdowsOP7mo ago
I don't really know how I could fully block these attacks They're using alot of methods
Jenkins
Jenkins7mo ago
Those look good Honestly you can try contacting OVH
Bruhdows
BruhdowsOP7mo ago
Well i've tried, 3 times
Jenkins
Jenkins7mo ago
They could be attacking from another OVH machine Those bypass the DDoS protection afaik
Bruhdows
BruhdowsOP7mo ago
They probably are As I've seen some OVH machines in netstat
Jenkins
Jenkins7mo ago
Btw, how did you configure Gate Lite to forward Player IPs to the backends?
Bruhdows
BruhdowsOP7mo ago
proxy protocol
Jenkins
Jenkins7mo ago
is that a built in feature ⁉️
Bruhdows
BruhdowsOP7mo ago
Yeah
Jenkins
Jenkins7mo ago
i didn't know that Nothing you can do about it honestly What did they reply with when you contacted them?
Bruhdows
BruhdowsOP7mo ago
How about somehow blocking all OVH asns from even doing something to the server You could possibly do that with some software But not sure if that would do anything Most of the time suggested to buy a game dedicated server for the DDoS Protection Also I was thinking about buying something like minekube connect - from the gate like owners
Jenkins
Jenkins7mo ago
No description
Jenkins
Jenkins7mo ago
That is full yap You don't need game DDoS protection for Java, that is covered by the general Anti DDoS Don't do that
Bruhdows
BruhdowsOP7mo ago
Like it's the same price as OVH VPS, so I am considering Yeah, should be
Jenkins
Jenkins7mo ago
Can you show this
Bruhdows
BruhdowsOP7mo ago
In the like logs of attacks? From here?
Jenkins
Jenkins7mo ago
no 1 sec
Jenkins
Jenkins7mo ago
@BruhdowsYou can view from here
No description
Jenkins
Jenkins7mo ago
OVH site is extremely slow for me, for some reason lmao
Bruhdows
BruhdowsOP7mo ago
No description
Bruhdows
BruhdowsOP7mo ago
180 attacks in a 14 days are crazy tho
Jenkins
Jenkins7mo ago
That is something I have not seen ever in my life What the hell That is insanity XD
Bruhdows
BruhdowsOP7mo ago
I know right
Jenkins
Jenkins7mo ago
Who did you even anger that much I do know you have a fairly large server
Bruhdows
BruhdowsOP7mo ago
I didn't, there is just some kids that go over random servers and just DDoS them or some other exploits, like connection spamming velocity etc. that affected some other servers that I know (caused by the same group)
Jenkins
Jenkins7mo ago
Can you turn off stack data and send another screenshot
Bruhdows
BruhdowsOP7mo ago
Yeah, moment
Jenkins
Jenkins7mo ago
Also set the period to something lower
Bruhdows
BruhdowsOP7mo ago
6 hours?
Jenkins
Jenkins7mo ago
24 should be fine
Bruhdows
BruhdowsOP7mo ago
No description
Bruhdows
BruhdowsOP7mo ago
And they're still attacking
Bruhdows
BruhdowsOP7mo ago
No description
Jenkins
Jenkins7mo ago
it seems like no packets are leaking to your dedicated at least do you know if your dedicated receives the malicious packets
Bruhdows
BruhdowsOP7mo ago
Nope, it does not go thru it
Jenkins
Jenkins7mo ago
What VPS do you have? It's very likely they are attacking from other OVH servers
Bruhdows
BruhdowsOP7mo ago
Like Specs?
Jenkins
Jenkins7mo ago
That seems to be it yeah
Bruhdows
BruhdowsOP7mo ago
It's like practically the lowest one :tf: 2 cores and 4 gigs of ram
Jenkins
Jenkins7mo ago
How much is the bandwith? Like 1gbps, 250mbps Honestly I'd just say nag OVH about it and tell them they are advertising Java DDoS protection as included with their general infastructure, so buying a game server would be pointless They will probably, anyway do something about it
Bruhdows
BruhdowsOP7mo ago
500mbps without limit
Jenkins
Jenkins7mo ago
uh yeah just stay on neo for the time being and nag ovh Neo is very costly
Bruhdows
BruhdowsOP7mo ago
Yeah
Jenkins
Jenkins7mo ago
What exactly happens during an attack? Just extreme lag?
Bruhdows
BruhdowsOP7mo ago
Lag Spikes
Jenkins
Jenkins7mo ago
If you see traffic coming to the server on netstat then it means it is leaking the attack
Bruhdows
BruhdowsOP7mo ago
To the dedi, or VPS?
Jenkins
Jenkins7mo ago
Where did you see traffic increasing on netstat anyways dedi or VPS?
Bruhdows
BruhdowsOP7mo ago
VPS. Dedi only VPS ones And as I said, there was some OVH ips included in the attack.
Jenkins
Jenkins7mo ago
If it reaches your VPS it should pass to your dedi just fine, unless another protection catches the remaining one Yeah Just nag OVH till they do something about it
Bruhdows
BruhdowsOP7mo ago
Not sure if it would pass thru Gate Lite
Jenkins
Jenkins7mo ago
Depends on the attack method™️ @Eternal
Bruhdows
BruhdowsOP7mo ago
Most of the are just trying to DDoS the SSH or the 25565 port.
Jenkins
Jenkins7mo ago
You should probably close the SSH port Use something like Tailscale to access it securely via a VPN
Bruhdows
BruhdowsOP7mo ago
I've did. They're still DDoSing the 25565 port. I could change it I guess, as they would need to port scan?
Jenkins
Jenkins7mo ago
That won't really work How are you setting up DNS requests to your VPS
Bruhdows
BruhdowsOP7mo ago
A record.
Jenkins
Jenkins7mo ago
someone can just look at the DNS info via something like dig and see the port it's going to yeah that won't work
Bruhdows
BruhdowsOP7mo ago
Not sure
Jenkins
Jenkins7mo ago
to use a port other than 25565 you'd need SRV records
Bruhdows
BruhdowsOP7mo ago
if SRV record leaks the port. Yeah
Jenkins
Jenkins7mo ago
it will you can't hide the port that's impossible
Bruhdows
BruhdowsOP7mo ago
They're still DDoSing so I can try setting up the VPS and try to check it out
ProGamingDk
ProGamingDk7mo ago
question, do you know if its a layer 7 attack? so minecraft focused because the vps dont have the game protection
Bruhdows
BruhdowsOP7mo ago
Not sure Yeah
Jenkins
Jenkins7mo ago
It does ......
Bruhdows
BruhdowsOP7mo ago
They should make some more affordable options ngl (atleast for the Gaming series) Like
ProGamingDk
ProGamingDk7mo ago
no? they have additional filters for their game servers.
Bruhdows
BruhdowsOP7mo ago
No description
Jenkins
Jenkins7mo ago
No description
Jenkins
Jenkins7mo ago
They say it on their page literally It is on the general Anti DDoS infastructure The game servers do not have extra protection for Java
ProGamingDk
ProGamingDk7mo ago
oh interesting, dont remember that always being the case but /shrug/ could check if its a layer 7 bedrock attack if he uses geyser?
Jenkins
Jenkins7mo ago
Nope, doesn't he drops all udp traffic
ProGamingDk
ProGamingDk7mo ago
ah
Bruhdows
BruhdowsOP7mo ago
They're still DDoSing so I will set the VPS back up and see from what it's coming from
ProGamingDk
ProGamingDk7mo ago
if they are ddosing the vps, cant you just check there?
Jenkins
Jenkins7mo ago
we were they're attacking from other ovh servers it looks like
ProGamingDk
ProGamingDk7mo ago
ah thats why ovh vac doesnt apply to internal traffic afaik
Bruhdows
BruhdowsOP7mo ago
Gotta love OVH 🔥
Bruhdows
BruhdowsOP7mo ago
No description
Jenkins
Jenkins7mo ago
LOL
Bruhdows
BruhdowsOP7mo ago
I can't even go into rescue mode it just died.
Jenkins
Jenkins7mo ago
ovh site do be like that it is the slowest and most unresponsive thing I have ever seen
Bruhdows
BruhdowsOP7mo ago
What "running tasks"?
No description
Bruhdows
BruhdowsOP7mo ago
It's crazy The users that DDoS are promoting some Minecraft server yk
Bruhdows
BruhdowsOP7mo ago
and someone in chat said this: xD
No description
Bruhdows
BruhdowsOP7mo ago
They're arabic btw
Jenkins
Jenkins7mo ago
is your server cracked by any chance if I remember correctly yes?
Bruhdows
BruhdowsOP7mo ago
Mhm
Jenkins
Jenkins7mo ago
yeah makes sense
Bruhdows
BruhdowsOP7mo ago
This is against the rules here right?
Jenkins
Jenkins7mo ago
Yeah, but not really about topics like this
Bruhdows
BruhdowsOP7mo ago
Well, I shouldn't but it's practically the only way to gain members specifically in Poland
ProGamingDk
ProGamingDk7mo ago
to be fair cracked makes bot attacks easier
Jenkins
Jenkins7mo ago
Well, these clearly aren't bot attacks so I've never seen a 10Gbps bot attack I get your pain, same in Turkey lmao
Bruhdows
BruhdowsOP7mo ago
Yeah
Jenkins
Jenkins7mo ago
Well anyways
piggy
piggy7mo ago
@Jenkins
libdeflate has reached level 10! Roles Added: Level 10
Jenkins
Jenkins7mo ago
You can stay on Neo for now and nag OVH in the meantime
Bruhdows
BruhdowsOP7mo ago
I guess
Jenkins
Jenkins7mo ago
They take down internal attacks quickly if you do manage to nag them enough
Bruhdows
BruhdowsOP7mo ago
Wondering when my VPS will come back to life tho
Jenkins
Jenkins7mo ago
Is your VPS running on prod Or are you directly Neoing your dedi
Bruhdows
BruhdowsOP7mo ago
Neoing the dedi :sunglas:
Jenkins
Jenkins7mo ago
alright lol
Bruhdows
BruhdowsOP7mo ago
Well even their chat does not work properly An agent will be with you shortly :sunglas: They will probably redirect me to another ticket.
Jenkins
Jenkins7mo ago
If they tell you to buy a game protected dedi just remind them that they advertise java protection as built-in
Bruhdows
BruhdowsOP7mo ago
Yeah Trying to nag OVH today
Jenkins
Jenkins7mo ago
is OVH on drugs
No description
Jenkins
Jenkins7mo ago
when since is debian 12 deprecated
Bruhdows
BruhdowsOP7mo ago
Hahaha I've had the same with Ubuntu 24 'We are experiencing longer wait times, thank you for your patience.' 😭
Jenkins
Jenkins7mo ago
that always happens I get a response within 1-2 mins sometimes 4
Bruhdows
BruhdowsOP7mo ago
Or the employee is avoiding me :tf: Nothin No response litterary
Jenkins
Jenkins7mo ago
did they answer? retype the message the message you send before the ticket is accepted by someone isn't seen idk why, seems to be a bug with their system
Bruhdows
BruhdowsOP7mo ago
It's still at
Bruhdows
BruhdowsOP7mo ago
No description
Jenkins
Jenkins7mo ago
oh lmao just wait for someone to pick up
Bruhdows
BruhdowsOP7mo ago
Yeah I will be actually considering Minekube Connect for now
Jenkins
Jenkins7mo ago
What protection do they even have? @ProGamingDkdon't you have drama with them? i think they were very sketchy
ProGamingDk
ProGamingDk7mo ago
fly.io well they wanted to do a marketplace for selfhosters, which was weird and you can only not get ads if you get the premium plan
Jenkins
Jenkins7mo ago
oh? i think that is not that good??
ProGamingDk
ProGamingDk7mo ago
its where they host they also only have like 2 pops (iirc), not sure if thats anycasted,
Bruhdows
BruhdowsOP7mo ago
No description
Jenkins
Jenkins7mo ago
does fly.io have a free plan or something looks interesting
Bruhdows
BruhdowsOP7mo ago
and looks cool the site overall
Jenkins
Jenkins7mo ago
That means nothing
Bruhdows
BruhdowsOP7mo ago
Yeah
ProGamingDk
ProGamingDk7mo ago
hosts call hetzners ddos protection advanced so like
Bruhdows
BruhdowsOP7mo ago
But it looks cool :sunglas:
ProGamingDk
ProGamingDk7mo ago
nothing new...
Bruhdows
BruhdowsOP7mo ago
Damn
Jenkins
Jenkins7mo ago
but german quality 🔥 how bad is hetzner ddos prot actually
ProGamingDk
ProGamingDk7mo ago
TTM is not great antiddos is eh
Bruhdows
BruhdowsOP7mo ago
German price 🔥 I didn't really test it
Bruhdows
BruhdowsOP7mo ago
No description
Bruhdows
BruhdowsOP7mo ago
"Less than 10 minutes of outage is expected" fly.io moment
ProGamingDk
ProGamingDk7mo ago
hetzners default notification is fx 200k packets a second
Bruhdows
BruhdowsOP7mo ago
That's probably why
Bruhdows
BruhdowsOP7mo ago
No description
Jenkins
Jenkins7mo ago
Customer service maintenance 😭
Bruhdows
BruhdowsOP7mo ago
Check this out @ProGamingDk :tf:
ProGamingDk
ProGamingDk7mo ago
its all ai
Jenkins
Jenkins7mo ago
they really are opening up the humans and fixing them or some shit XD
Bruhdows
BruhdowsOP7mo ago
Can't they just say something "Customer Support is in maintenace. Click here for more info"
No description
Jenkins
Jenkins7mo ago
Customer Service Status
Welcome to Customer Service's home for real-time and historical data on system performance.
Jenkins
Jenkins7mo ago
You can sign up for updates if you care about that
Bruhdows
BruhdowsOP7mo ago
I've clicked on that 😭
Bruhdows
BruhdowsOP7mo ago
No description
Bruhdows
BruhdowsOP7mo ago
What is that link
Jenkins
Jenkins7mo ago
funny (rickroll)
Bruhdows
BruhdowsOP7mo ago
and it does not preview cus discord.com
Jenkins
Jenkins7mo ago
(i rickrolled you back) Yeah, it's a remnant of another easter egg they just didn't remove you were able to access it by enabling an experiment
Bruhdows
BruhdowsOP7mo ago
That's cool
Jenkins
Jenkins7mo ago
wait....
No description
Jenkins
Jenkins7mo ago
@ProGamingDk can you verify please do they NOT HAVE HTTPS ON THEIR STATUS PAGE 😭 THEY ACTUALLY DON'T WTF
ProGamingDk
ProGamingDk7mo ago
can confirm they dont
Jenkins
Jenkins7mo ago
i'm crying
Bruhdows
BruhdowsOP7mo ago
OVH is doomed.
Bruhdows
BruhdowsOP7mo ago
Any ideas?
ProGamingDk
ProGamingDk7mo ago
arent you currently using neoprotect hows that going
Jenkins
Jenkins7mo ago
Did OVH respond?
Bruhdows
BruhdowsOP7mo ago
It's okay, but the limitations are crazy My server exceeds 6 TB traffic before month ends and the the only upgrade is 3x the value
ProGamingDk
ProGamingDk7mo ago
which thing do you have? well plan remoteshield or just mc?
Bruhdows
BruhdowsOP7mo ago
Neo mc Customs are 100 euros and up
ProGamingDk
ProGamingDk7mo ago
oh have fun with the company plan if you ever get that their fair use is funny
Bruhdows
BruhdowsOP7mo ago
It's just unreasonable I pay less for my Dedi
Jenkins
Jenkins7mo ago
Yeah... Nag OVH They will fix it
Bruhdows
BruhdowsOP7mo ago
Papyrus.vip seems cool, they use Cloudflare Spectrum and for 30 euros/month you get Unlimited Bandwith (didn't read tos yet)
ProGamingDk
ProGamingDk7mo ago
oh im more talking about the fair use amount they also ddos other hosts owner is a dingus
Bruhdows
BruhdowsOP7mo ago
They need
ProGamingDk
ProGamingDk7mo ago
etc
Bruhdows
BruhdowsOP7mo ago
Damn
ProGamingDk
ProGamingDk7mo ago
also shutdown for like 2 years because cloudflare wasnt happy about enterprise being resold mcprohostings ddosprot service also died for external projects due to it iirc
Bruhdows
BruhdowsOP7mo ago
Also I was considering UltaHost. But theirs AntiDDoS seems more website based Damn this thread is going crazy 😂 3 people and like 305 messages alr Seems like they fixed their support :tf:
Eric Blockchaincreek.com
Hey we just deployed our new anti ddos for some servers! Feel free to check us out! https://servcity.org/
Servcity
ServCity | Affordable and Fast Gameservers with Anti-DDoS
Servcity offers affordable DDoS Protected Gameservers running on the latest Ryzen 9 CPUs from AMD, for example the R9 7950X. Minecraft, VPS, and more.
Eric Blockchaincreek.com
Or let me know if you wanna do any testing 🙂
Bruhdows
BruhdowsOP7mo ago
Yeah, but would it be possible to proxy connections? Most hosts disallow it. As I am looking for a DDoS protection for my Dedicated server
Game_Time
Game_Time7mo ago
We use hetzener with neoprotect and blocked those kids We only had one issue where they were attacking an old backend IP of ours, but that’s been fixed What plan are you using? The 90 euro plan should be perfect That’s what we’re using
ProGamingDk
ProGamingDk7mo ago
how many players do you have? i dont like their fair use / company plan player suggestion "200-1000 players" "above 200-500 players you generally need a custom deal for bandwidth costs"
Game_Time
Game_Time7mo ago
100~
Bruhdows
BruhdowsOP7mo ago
Same right now
Game_Time
Game_Time7mo ago
Then what issue are you guys having? Hetzener or OVH? You were talking about Ovh before They likely have your backend IP and are attacking it if on hetzener
Bruhdows
BruhdowsOP7mo ago
Yeah cus I was proxying OVH connections to my Hetzner dedi Actually no, my dedi is fully protected with tailscale and i've tried netstat too (only proxy connections)
Game_Time
Game_Time7mo ago
You sure? We thought we secured it as well but then neoprotect people found our IP relatively easily lmao
Bruhdows
BruhdowsOP7mo ago
Yeah, otherwise it would be ddosed all the time right now
Game_Time
Game_Time7mo ago
They don’t ddos all the time For us they’ve been ddosing our old primairy IP and saturating the connection Just waiting on hetzener to remove it
Bruhdows
BruhdowsOP7mo ago
Seems like the same issue, just for my OVH vps.
ProGamingDk
ProGamingDk7mo ago
cant you use the web firewall and block everything to that ip? so it doesnt hit your machine saturating the connection
Game_Time
Game_Time7mo ago
Yes we have done that. It still seems to be able to saturate the connection Not sure why or how, but neoprotect ppl also recommended to remove it Don’t know why either
Bruhdows
BruhdowsOP7mo ago
I could, but it's multipile servers(vps) and the rules are limited
ProGamingDk
ProGamingDk7mo ago
i was talking to game time about his old ip being attacked
Bruhdows
BruhdowsOP7mo ago
Ah sorry
ProGamingDk
ProGamingDk7mo ago
i had to get a hetzner ip changed for a client who's previous sys-admin got the ip leaked on censys, was like 22 euros + setup 😭
Game_Time
Game_Time7mo ago
Exactly It’s so expensive bro 😭
ProGamingDk
ProGamingDk7mo ago
tbf they will have to recycle the ip meaning some unlucky bloak can be attacked
Bruhdows
BruhdowsOP7mo ago
The best way is block all connections, add all neoprotects ips and use tailscale.
Game_Time
Game_Time7mo ago
No description
ProGamingDk
ProGamingDk7mo ago
also the ip is in the same subnet
Eric Blockchaincreek.com
We offer that as well What location of OVH do you use?
Bruhdows
BruhdowsOP7mo ago
Germany Closest to my Dedi
Eric Blockchaincreek.com
That would be possible then our location is in NL We can just get you a proxy or a tunnel
Bruhdows
BruhdowsOP7mo ago
Cool, could you give me a quote? I would like a test server for like 48h so I could test the ping differenceand everything if that's possible
Eric Blockchaincreek.com
Yeah sure is it fine to sent you a dm and go over the details?
Bruhdows
BruhdowsOP7mo ago
Yeah, i will send a friend request Guess what
Bruhdows
BruhdowsOP7mo ago
.
No description
Jenkins
Jenkins7mo ago
Well that sucks Honestly what are the chances the lag spikes are something else
Bruhdows
BruhdowsOP7mo ago
Well I've had no problems after switching to neoprotect
Jenkins
Jenkins7mo ago
Maybe it is the bandwith being filled up? Like, not because of a ddos attack, just naturally becuse the server literally only has 500mbps
Bruhdows
BruhdowsOP7mo ago
That's possible Cus it does not crash It just lags a ton
Jenkins
Jenkins7mo ago
It could be that honestly
Bruhdows
BruhdowsOP7mo ago
For now I am waiting for reanimation of my VPS 😭
Jenkins
Jenkins7mo ago
Wait why
Bruhdows
BruhdowsOP7mo ago
it just died and I can't restart, reinstall or anything
Bruhdows
BruhdowsOP7mo ago
No description
Bruhdows
BruhdowsOP7mo ago
No description
Jenkins
Jenkins7mo ago
LOL
Bruhdows
BruhdowsOP7mo ago
Also i've seen some xProtect thingy from XCord That allows to blacklist asns and shit

Did you find this page helpful?