How to Defend Your VPS Against Small DDoS Attacks with DDoS Deflate (2026 Guide)
Let's be honest: hosting your own website on a VPS is amazing. You get full control, better performance, and the satisfaction of running everything yourself. But there's one thing that keeps every site owner up at night: โDDoS attacksโ.
If you've ever woken up to find your site unreachable, your server maxed out, or your inbox full of downtime alerts, you know exactly what I'm talking about.
Here's the brutal truth: โmost individual site owners and small webmasters can't afford enterprise-grade DDoS protection.โ The big cloud providers charge hundreds or thousands of dollars a month for proper anti-DDoS services โ and for many people running a personal blog, a small business site, or a side project, that's just not in the budget.
But here's the good news: โyou don't have to be completely defenseless.โ There are simple, free tools you can install on your VPS that can block small to medium DDoS and CC attacks automatically. One of the best and most well-known is โDDoS Deflateโ.
This guide will show you exactly what it is, how it works, how to install and configure it, and โ importantly โ what it can't do, so you know its limits.

First: What Exactly Is DDoS Deflate?
โDDoS Deflateโ is a lightweight, free, open-source shell script designed to protect Linux servers from small-scale DDoS attacks.
Here's how it works, in plain English:
- Every minute (or whatever interval you set), it checks how many active connections each IP address has to your server;
- If any single IP has more connections than your threshold, it automatically โbans that IPโ using your firewall (iptables or APF);
- After a set period of time (default 600 seconds / 10 minutes), it automatically unbans the IP;
- It can even send you an email alert every time it bans someone.
Think of it like a bouncer at the door of a club. If one person tries to crowd the entrance with 200 of their friends, the bouncer kicks them out for 10 minutes.
It's simple, it's elegant, and it works surprisingly well against โconnection flood attacks, basic CC attacks, and other low-to-medium volume DDoS attemptsโ.
What DDoS Deflate Is Not
Before we go further, let's be realistic about what this tool can and can't do:
โ โWhat it's good at:โ
- Blocking single-IP connection floods
- Stopping basic CC attacks from small botnets
- Reducing server load from repeated abusive connections
- Giving you some protection for free, with zero cost
โ โWhat it CAN'T do:โ
- Stop a massive volumetric DDoS attack that fills your entire bandwidth pipe
- Protect against sophisticated multi-IP, distributed attacks from thousands of unique IPs
- Replace proper upstream DDoS protection from your hosting provider
โBottom line:โ DDoS Deflate is a first line of defense โ like a lock on your front door. It won't stop a tank, but it will keep out 90% of casual troublemakers.
Before You Install: Check If You Actually Need It
You might be wondering, "How do I know if I'm under attack?" Here are some common signs:
- Your website is suddenly very slow or completely unreachable;
- Server load (CPU / RAM) is spiking for no obvious reason;
- You see hundreds or thousands of connections from the same IP in your logs;
- Your hosting provider sends you an alert about high traffic / bandwidth;
netstatshows hundreds of connections in SYN_RECV or ESTABLISHED state.
You can quickly check how many connections each IP has with this command:
netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -nr | head -20
If you see a single IP with 100+ connections to port 80/443, there's a good chance you're being attacked โ and DDoS Deflate can probably help.
Step 1: Installing DDoS Deflate
Installation is straightforward. It's a single shell script that sets everything up for you.
โ ๏ธ โNote:โ The original DDoS Deflate project on Google Code is no longer maintained. The installation method below is the classic version, which still works fine on most Linux distros. For a more up-to-date fork, you may want to check GitHub โ but the classic version is simple and well-tested.
Download and run the installer:
wget http://myvps-scripts.googlecode.com/files/deflate.sh
chmod +x deflate.sh
./deflate.sh
The script will:
- Create the
/usr/local/ddos/directory - Install the main ddos.sh script
- Set up the default configuration file
- Add a cron job to run every minute
- Create a whitelist file for IPs you never want to ban
That's it โ it takes about 10 seconds.
Step 2: Configuring DDoS Deflate
The main configuration file lives at /usr/local/ddos/ddos.conf. Let's walk through each setting so you know what to change.
Open it with your favorite editor:
nano /usr/local/ddos/ddos.conf
Here's what you'll see, and what each option means:
##### Paths of the script and other files
PROGDIR="/usr/local/ddos"
PROG="/usr/local/ddos/ddos.sh"
IGNORE_IP_LIST="/usr/local/ddos/ignore.ip.list"
CRON="/etc/cron.d/ddos.cron"
APF="/etc/apf/apf"
IPT="/sbin/iptables"
These are just file paths. You can leave these as-is unless you have a non-standard setup.
##### frequency in minutes for running the script
##### Caution: Every time this setting is changed, run the script with --cron
##### option so that the new frequency takes effect
FREQ=1
โFREQ=1โ means the script runs every 1 minute. For most people, 1 minute is fine. If you want it to check more frequently, you can set it lower โ but 1 minute is usually a good balance between responsiveness and resource usage.
##### How many connections define a bad IP? Indicate that below.
NO_OF_CONNECTIONS=150
โThis is the most important setting.โ It defines the connection threshold โ any IP with more than this many concurrent connections gets banned.
- โ150โ is the default and is generally safe;
- If you have a high-traffic site, you might want to raise this to 200 or 300 to avoid banning legitimate users (e.g., people on corporate networks with shared IPs);
- If you're getting hammered, lower it to 50โ100 โ but be careful about false positives;
- For a normal WordPress site, 150 is a good starting point.
##### APF_BAN=1 (Make sure your APF version is at least 0.96)
##### APF_BAN=0 (Uses iptables for banning ips instead of APF)
APF_BAN=0
โSet this to 0 unless you specifically use APF (Advanced Policy Firewall).โ Most VPS setups use iptables directly, so APF_BAN=0 is the right choice. This tells DDoS Deflate to ban IPs using iptables rules.
##### KILL=0 (Bad IPs aren't banned, good for interactive execution of script)
##### KILL=1 (Recommended setting)
KILL=1
Keep this at โ1โ. Setting it to 0 runs in "dry run" mode โ it detects bad IPs but doesn't actually ban them. Useful for testing, not for production.
##### An email is sent to the following address when an IP is banned.
##### Blank would suppress sending of mails
EMAIL_TO="root"
Enter your email address here to get an alert every time an IP is banned. If you don't want emails, leave it blank or set it to "".
โPro tip:โ If you get attacked a lot, you might want to leave this blank to avoid getting spammed with hundreds of ban notifications.
##### Number of seconds the banned ip should remain in blacklist.
BAN_PERIOD=600
How long (in seconds) an IP stays banned before being automatically unbanned. Default is โ600 seconds = 10 minutesโ.
- For persistent attackers, you could raise this to 3600 (1 hour) or even 86400 (1 day);
- 10 minutes is a good default because most attacks move on after a few minutes anyway;
- Shorter ban periods also reduce the chance of accidentally banning legitimate users for too long.
Step 3: Whitelist Your Own IPs
The last thing you want is to accidentally ban yourself. Make sure to add your own IP, your server's IP, and any other trusted IPs to the whitelist.
Edit the whitelist file:
nano /usr/local/ddos/ignore.ip.list
Add one IP per line:
127.0.0.1
your.own.ip.address
your.server.ip.address
If you have a dynamic IP at home, be careful โ you might get banned and locked out of your own server. It's a good idea to have console or VNC access as a backup, just in case.
Step 4: Testing It Out
Once you've configured everything, DDoS Deflate will run automatically every minute via cron. But you should test it to make sure it's working.
To manually run the script and see what it would do:
/usr/local/ddos/ddos.sh
To view currently banned IPs in iptables:
iptables -L INPUT -v -n
Or specifically check the DDoS Deflate chain:
iptables -L D_DOS -v -n
To manually unban an IP:
iptables -D D_DOS -s 192.168.1.1 -j DROP
(Replace 192.168.1.1 with the actual IP.)
To see recent ban activity, check your email (if you set EMAIL_TO) or check your syslog:
grep -i ddos /var/log/syslog | tail -20
Important Limitations (Please Read This)
I want to be completely honest with you. DDoS Deflate is a great free tool, but it has real limits. Here's what it cannot protect you against:
1. Volumetric Attacks (Bandwidth Floods)
If an attack is big enough to fill your server's entire network pipe (e.g., a 10Gbps attack hitting a 1Gbps port), โnothing on your server can stop itโ โ because the traffic is already clogging the pipe before it even reaches your machine.
For these kinds of attacks, you need โupstream DDoS protectionโ from your hosting provider or a service like Cloudflare.
2. Truly Distributed Attacks with Thousands of Unique IPs
DDoS Deflate works by banning individual IPs that make too many connections. If the attack is coming from 10,000 different IPs each making 5 connections, DDoS Deflate won't catch them because no single IP exceeds the threshold.
This is why it works well against small botnets and script kiddies, but not against large, sophisticated DDoS attacks.
3. Application-Layer Attacks That Mimic Real Users
Smart attackers can craft attacks that look exactly like legitimate traffic โ with real browser headers, normal request rates per IP, and distributed IPs. These are much harder to detect with simple connection-counting.
For those, you need more sophisticated tools like:
- โfail2banโ (for log-based pattern detection)
- โModSecurity / WAFโ (web application firewall)
- โCloudflare or other CDN/WAF servicesโ
Bonus: Additional Ways to Harden Your VPS
DDoS Deflate is a great start, but here are a few more free things you can do to harden your VPS against attacks:
1. Use a CDN Like Cloudflare
Putting your site behind Cloudflare (the free plan works!) means all traffic goes through their network first. They absorb DDoS attacks, cache static content, and hide your real server IP.
โThis is the single most effective thing you can do for free.โ
2. Install Fail2Ban
Fail2Ban monitors your server logs (SSH, web server, etc.) and automatically bans IPs that show malicious behavior โ like repeated failed login attempts or known attack patterns.
It's complementary to DDoS Deflate:
- โDDoS Deflateโ = catches connection flood attacks
- โFail2Banโ = catches brute-force and application-layer attacks
3. Keep Everything Updated
Most attacks exploit known vulnerabilities. Keeping your OS, web server, PHP, database, and CMS (WordPress, etc.) up to date eliminates the easiest attack vectors.
4. Use Your Host's Built-in DDoS Protection
Many VPS providers include at least basic DDoS protection for free. Check what your host offers โ you might already have 5โ10Gbps of protection you didn't know about.
5. Disable Unnecessary Services
Every open port and running service is a potential attack surface. Turn off anything you don't need โ fewer things running = fewer things to attack.
Final Thoughts: Free Protection vs. Paid Protection
Let's end with some real talk about cost vs. value.
โFree tools like DDoS Deflate, Fail2Ban, and Cloudflare's free planโ will stop the vast majority of casual attacks โ script kiddies, bored teenagers, small botnets, random vulnerability scanners. For most personal sites and small businesses, this is more than enough.
โBut if you're running a business that makes real money,โ and a few hours of downtime would cost you hundreds or thousands of dollars, then investing in proper DDoS protection from your hosting provider is absolutely worth it. A few extra dollars a month for guaranteed protection could save you from a catastrophic outage.
โYou don't have to choose one or the other.โ Run DDoS Deflate on your server and use Cloudflare and make sure your host has upstream protection. Layered defense is always better than a single solution.
Start with the free stuff. If and when you outgrow it, upgrade.
๐ป โLooking for a VPS with built-in DDoS protection?โ
โsixcvmโ offers high-performance KVM VPS with โfree 20Gbps baseline DDoS protectionโ included with every plan โ so you get upstream protection plus the freedom to add your own tools like DDoS Deflate for layered security.
- ๐ก๏ธ โFree 20Gbps DDoS protectionโ โ included with all plans, no extra charge;
- โก โNVMe SSD storageโ โ fast disk I/O for better performance under load;
- ๐ โOptimized routesโ โ low latency for visitors worldwide;
- ๐ โFull root accessโ โ install DDoS Deflate, fail2ban, or any other security tool you want;
- ๐จโ๐ป โ24/7 technical supportโ โ if you run into trouble, we're here to help;
- ๐ฐ โ3-day money-back guaranteeโ โ try it risk-free.


