Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


In this Discussion

New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

XDP/eBPF DDoS filtering on VPS nodes: how do you avoid false positives across tenants?

Hey all,

I run a small hosting setup in Switzerland, mostly VPS. Big volumetric attacks are scrubbed upstream, and we run our own XDP/eBPF filtering on the nodes for what gets through, including SYN cookies.

The hard part isn't dropping packets, it's doing it without breaking legit traffic. One customer runs a web stack, the next one WireGuard, DNS or a game server, so any generic rule ends up hurting someone.

Curious how other providers handle it:

  • Per-IP / per-customer profiles, or global rules plus exceptions?
  • Always-on filtering, or rules that only kick in above a threshold?
  • UDP: blanket drop of common amplification source ports, or something smarter?
  • Do you let customers tweak their own rules from the panel?
  • Native XDP in the NIC driver or generic mode, and any NIC you'd avoid?

Happy to share what we've learned so far, including the mistakes.

Comments

Sign In or Register to comment.