Report this

What is the reason for this report?

DDoS protection

Posted on June 23, 2021

Ive seen that DO doesnt provide DDoS protection for droplets but is there any way I can protect my droplet from DDoS attacks without using cloudflare? I saw that IP tables hadnt really helped for some people. Any ideas?



This textbox defaults to using Markdown to format your answer.

You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!

These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.

Hi @Filice,

So one thing is using a CDN like CloudFlare, the other is using a good firewall.

Having said that, Using only Iptables should be enough. This exact question has been discussed here as well:

https://www.digitalocean.com/community/questions/does-digital-ocean-have-a-dos-protection-stragegy

Additionally,

You can check the tutorial on how to mitigate DDoS attacks with CloudFlare (if you decide to use it)

https://www.digitalocean.com/community/tutorials/how-to-mitigate-ddos-attacks-against-your-website-with-cloudflare

You can also check the Cloud Firewalls:

DigitalOcean Cloud Firewalls, which are free of charge.

DigitalOcean Cloud Firewalls are a network-based, stateful firewall service for Droplets provided at no additional cost. Cloud firewalls block all traffic that isn’t expressly permitted by a rule, in other words, the traffic is blocked before it even reaches your Droplets, which means less load to your Droplets.

Hope that this helps!

Hello there,

Quick update here. I’m excited to share that DigitalOcean has introduced a new feature in response to the valuable feedback we’ve received from users like you: DigitalOcean DDoS Protection:

https://www.digitalocean.com/products/ddos-protection

Here are some key points about this new offering:

  1. Cost: DigitalOcean DDoS Protection is available at no additional cost. That’s right, it’s a free service for all users!

  2. Coverage: The protection extends to a range of DigitalOcean resources including:

    • Droplets
    • Kubernetes
    • Managed Databases
    • Load Balancers
    • Reserved IPs
  3. Protection Layers: This service provides protection primarily at the Network (layer 3) and Transport (layer 4) layers of the OSI model. Please note that Application layer (layer 7) DDoS Protection is currently not supported.

  4. Latency Concerns: One of the standout features of this service is that mitigation takes place entirely within the DigitalOcean network. This means that data traffic doesn’t leave our network for mitigation, ensuring that your applications experience no additional latency.

  5. Overall Benefit: DigitalOcean DDoS Protection is an always-on service designed to defend your DigitalOcean cloud resources against a range of generalized, network-layer DDoS attacks. This ensures that your apps and websites run smoothly, without the threat of potential disruptions from such attacks.

Best,

Bobby

The developer cloud

Scale up as you grow — whether you're running one virtual machine or ten thousand.

Get started for free

Sign up and get $200 in credit for your first 60 days with DigitalOcean.*

*This promotional offer applies to new accounts only.