با سلام،
بنده روی سرور هتزنر با حملات DDoS مواجه هستم که باعث اختلال در سرویسها شده است. لطفاً راهنمایی بفرمایید که چه راهکاری برای مقابله با این حملات پیشنهاد میدهید و آیا امکان نصب یک آنتیدیداس مناسب روی سرور وجود دارد؟ از طریق fail2ban و iptable مسدود سازی انجام شد اما همچنان مورد حمله قرار میگیرد
حملات از نوع زیر می باشد که هتزنر ایمیل ارسال کرده :
Dear CLient,
we have recognized an big attack on your server which we also mitigated.
It was an TCP SYN attack on destination port 22.
We can see also UDP attempts and a lot of packets with source port0.
You can use the Firewall to drop unwanted traffic and ports.
We have indications that your server has been attacked. Those responsible for this have been asked to solve the issue and to give us a statement on the cause of the attack.
This is an information email only and does not require any further action on your part.
Important note:
When replying to us, please leave the abuse ID [AbuseID:F6D06B:18] unchanged in the subject line.
Please note that we do not provide telephone support in our department. If you have any questions, please send them to us by opening a new ticket via Robot.
> Direction IN
> Internal 138.201.19.90
> Threshold Packets 200,000 packets/s
> Sum 60,370,000 packets/300s (201,233 packets/s), 11,343 flows/300s (37 flows/s), 73.592 GByte/300s (2,009 MBit/s)
> External 157.240.0.63, 195,000 packets/300s (650 packets/s), 30 flows/300s (0 flows/s), 0.215 GByte/300s (5 MBit/s)
> External 157.240.251.63, 115,000 packets/300s (383 packets/s), 19 flows/300s (0 flows/s), 0.138 GByte/300s (3 MBit/s)
> External 157.240.253.63, 85,000 packets/300s (283 packets/s), 15 flows/300s (0 flows/s), 0.097 GByte/300s (2 MBit/s)
> External 17.253.57.202, 50,000 packets/300s (166 packets/s), 3 flows/300s (0 flows/s), 0.070 GByte/300s (1 MBit/s)
> External 157.240.252.63, 50,000 packets/300s (166 packets/s), 10 flows/300s (0 flows/s), 0.061 GByte/300s (1 MBit/s)
> External 93.114.135.93, 35,000 packets/300s (116 packets/s), 2 flows/300s (0 flows/s), 0.049 GByte/300s (1 MBit/s)