danfra
Member
OP
- Joined:
- Jun 2024
- Posts:
- 159
- From:
- Frankfurt, DE
40 Gbps volumetric, mixed UDP reflection and TCP SYN flood. Target was a €7 KVM in OVHcloud's Vint Hill zone.
Timeline:
- T+0: traffic spike detected by their edge
- T+12s: automatic nullroute lifted, traffic diverted to scrubbing
- T+45s: clean traffic back on GRE tunnel to my VPS
- T+3min: attack peaked at 39.7 Gbps, held for 8 minutes
- T+11min: attacker gave up
Filtering layers: 1) Anycast sinkhole for >30 Gbps, 2) XDP-based SYN cookie validation, 3) rate limit per /24. No false positives on my end. SSH stayed up, HTTP latency went from 18ms to 34ms during peak.
For context, my last provider nullrouted me for 4 hours on a 12 Gbps attack. This is the first time I've seen sub-minute mitigation on a budget plan without paying for a separate DDoS IP.
mitigated 800Gbps before breakfast
pieter_rtm
Member
- Joined:
- Jul 2024
- Posts:
- 195
- From:
- Rotterdam, NL
To be honest, we got lucky the attack was so dumb.
What fired:
- Edge trigger: 5 Gbps over baseline, anycast withdraw to scrubbing POPs
- XDP layer dropped 94% of SYNs without hitting conntrack
- UDP reflection: source port validation + payload length heuristics
- Remaining 6% passed to userspace filter, then GRE back to hypervisor
Specs on that $7 plan:
- 1 vCPU (E5-2680v4, fair share)
- 1 GB RAM
- 20 GB NVMe (rdma disabled, ~800 MB/s seq)
- 1 IPv4 + /64 IPv6
- 1 Gbps port, 2 TB monthly
- DDoS: included, no separate "protected IP" upsell
The GRE tunnel adds ~0.3 ms. As said, we don't do scrubbing in Amsterdam itself. Traffic goes to Frankfurt or London depending on RTT. During this event Frankfurt took 78% of the dirty pipe.
Dry fact: that attack cost us roughly 11 EUR in transit overage. We ate it.
https://www.ovhcloud.com/en/vps/
Containers before it was cool