I've been terribly busy in the last couple of days as one of my servers seems to be under constant DDoS attack by multiple IPs from Russia.
I managed to keep the server alive for about two days but today when I went to work it got overloaded (according to my host that monitors the servers and autoreboots the RAM filled) and rebooted twice. (its a Dual Opteron, 4GB, CentOS 4.5 box)
I am using APF (Advanced policy firewall) with a custom set of rules and DoS protection turned on. It does work but still stresses the server.
The questions are:
1) What other setup of tools you use for protection in Linux?
2) Any tips that could improve stability even under heavy load?
I am asking here since solutions from the admins in managed support of my host suggest either a hardware Cisco firewall or moving to better hardware (Dual Quad Core Xeon) both of which are pretty costly.