Back to chaining: I ran the numbers on AlexWei's five-tier stack. Three parallel chains, DNS failover, 30s TTL. Monthly cost is zero but the orchestration is a part-time job. You need health checks that fail over before the nullroute propagates. I used Nagios. It worked. I do not miss it.
Looking for dDoS mitigation that works on sub-$10 VPS
Nagios in 2024 is wild but respect
Here in Brazil the problem is different. Contabo's Mumbai peer is actually decent but any DDoS and they nullroute the whole /24. My neighbor got hit and I went down too. Now I use Vultr São Paulo as front, same city, 3ms. But the price...
I use RackNerd Los Angeles $10/year plan. Unmetered bandwidth but no DDoS protection. For my blog it is enough. If I get attacked I just change DNS and wait. Not good for business.
RackNerd unmetered is a myth. Read the AUP: "excessive use of network resources" is grounds for suspension. They don't define the number. Nobody does.
This. "Unmetered" in budget hosting means "we won't bill you per GB" not "use the full port 24/7." Every AUP has that escape hatch. I've written them.
What about BuyVM's DDoS filtering? $3.50/mo for the slice plus $3 for filtering in Vegas. That's under $10 total.
BuyVM filtering is Layer 4, not volumetric. For a 5Gbps spike it still nullroutes upstream and you wait for the filter to engage. Fine for slowloris, useless for UDP floods or real volumetric. Source: their own wiki, last I checked.
I am using Hetzner cloud in Falkenstein. 4.51 EUR for CX11. Their DDoS protection is included but only for attacks under 1Gbps. Above that they nullroute same as Contabo.
Confirmed. Hetzner's page says "automatic DDoS mitigation" but the fine print is "common attack patterns" and they reserve nullroute for volumetric. Same game, different logo.