New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
XDP/eBPF DDoS filtering on VPS nodes: how do you avoid false positives across tenants?
Mystral_Hosting
Member
in General
Hey all,
I run a small hosting setup in Switzerland, mostly VPS. Big volumetric attacks are scrubbed upstream, and we run our own XDP/eBPF filtering on the nodes for what gets through, including SYN cookies.
The hard part isn't dropping packets, it's doing it without breaking legit traffic. One customer runs a web stack, the next one WireGuard, DNS or a game server, so any generic rule ends up hurting someone.
Curious how other providers handle it:
- Per-IP / per-customer profiles, or global rules plus exceptions?
- Always-on filtering, or rules that only kick in above a threshold?
- UDP: blanket drop of common amplification source ports, or something smarter?
- Do you let customers tweak their own rules from the panel?
- Native XDP in the NIC driver or generic mode, and any NIC you'd avoid?
Happy to share what we've learned so far, including the mistakes.
Comments
dont do of which u have not researched simple