How to Defend Your VPS Against Small DDoS Attacks with DDoS Deflate (2026 Guide)
Let's be honest: hosting your own website on a VPS is amazing. You get full control, better performance, and the satisfaction of running everything yourself. But there's one thing that keeps every site owner up at night: DDoS attacks.
If you've ever woken up to find your site unreachable, your server maxed out, or your inbox full of downtime alerts, you know exactly what I'm talking about.
Here's the brutal truth: most individual site owners and small webmasters can't afford enterprise-grade DDoS protection. The big cloud providers charge hundreds or thousands of dollars a month for proper anti-DDoS services — and for many people running a personal blog, a small business site, or a side project, that's just not in the budget.
But here's the good news: you don't have to be completely defenseless. There are simple, free tools you can install on your VPS that can block small to medium DDoS and CC attacks automatically. One of the best and most well-known is DDoS Deflate.
This guide will show you exactly what it is, how it works, how to install and configure it, and — importantly — what it can't do, so you know its limits.

First: What Exactly Is DDoS Deflate?
DDoS Deflate is a lightweight, free, open-source shell script designed to protect Linux servers from small-scale DDoS attacks.
Here's how it works, in plain English:
- Every minute (or whatever interval you set), it checks how many active connections each IP address has to your server;
- If any single IP has more connections than your threshold, it automatically bans that IP using your firewall (iptables or APF);
- After a set period of time (default 600 seconds / 10 minutes), it automatically unbans the IP;
- It can even send you an email alert every time it bans someone.
Think of it like a bouncer at the door of a club. If one person tries to crowd the entrance with 200 of their friends, the bouncer kicks them out for 10 minutes.
It's simple, it's elegant, and it works surprisingly well against connection flood attacks, basic CC attacks, and other low-to-medium volume DDoS attempts.
What DDoS Deflate Is Not
Before we go further, let's be realistic about what this tool can and can't do:
✅ What it's good at:
- Blocking single-IP connection floods
- Stopping basic CC attacks from small botnets
- Reducing server load from repeated abusive connections
- Giving you some protection for free, with zero cost
❌ What it CAN'T do:
- Stop a massive volumetric DDoS attack that fills your entire bandwidth pipe
- Protect against sophisticated multi-IP, distributed attacks from thousands of unique IPs
- Replace proper upstream DDoS protection from your hosting provider
Bottom line: DDoS Deflate is a first line of defense — like a lock on your front door. It won't stop a tank, but it will keep out 90% of casual troublemakers.
Before You Install: Check If You Actually Need It
You might be wondering, "How do I know if I'm under attack?" Here are some common signs:
- Your website is suddenly very slow or completely unreachable;
- Server load (CPU / RAM) is spiking for no obvious reason;
- You see hundreds or thousands of connections from the same IP in your logs;
- Your hosting provider sends you an alert about high traffic / bandwidth;
netstatshows hundreds of connections in SYN_RECV or ESTABLISHED state.
You can quickly check how many connections each IP has with this command:
netstat -ntu | awk '{print $5}' | cut -d: -f1 | sort | uniq -c | sort -nr | head -20
If you see a single IP with 100+ connections to port 80/443, there's a good chance you're being attacked — and DDoS Deflate can probably help.
Step 1: Installing DDoS Deflate
Installation is straightforward. It's a single shell script that sets everything up for you.
⚠️ Note: The original DDoS Deflate project on Google Code is no longer maintained. The installation method below is the classic version, which still works fine on most Linux distros. For a more up-to-date fork, you may want to check GitHub — but the classic version is simple and well-tested.
Download and run the installer:
wget http://myvps-scripts.googlecode.com/files/deflate.sh
chmod +x deflate.sh
./deflate.sh
The script will:
- Create the
/usr/local/ddos/directory - Install the main ddos.sh script
- Set up the default configuration file
- Add a cron job to run every minute
- Create a whitelist file for IPs you never want to ban
That's it — it takes about 10 seconds.
Step 2: Configuring DDoS Deflate
The main configuration file lives at /usr/local/ddos/ddos.conf. Let's walk through each setting so you know what to change.
Open it with your favorite editor:
nano /usr/local/ddos/ddos.conf
Here's what you'll see, and what each option means:
##### Paths of the script and other files
PROGDIR="/usr/local/ddos"
PROG="/usr/local/ddos/ddos.sh"
IGNORE_IP_LIST="/usr/local/ddos/ignore.ip.list"
CRON="/etc/cron.d/ddos.cron"
APF="/etc/apf/apf"
IPT="/sbin/iptables"
These are just file paths. You can leave these as-is unless you have a non-standard setup.
##### frequency in minutes for running the script
##### Caution: Every time this setting is changed, run the script with --cron
##### option so that the new frequency takes effect
FREQ=1
FREQ=1 means the script runs every 1 minute. For most people, 1 minute is fine. If you want it to check more frequently, you can set it lower — but 1 minute is usually a good balance between responsiveness and resource usage.
##### How many connections define a bad IP? Indicate that below.
NO_OF_CONNECTIONS=150
This is the most important setting. It defines the connection threshold — any IP with more than this many concurrent connections gets banned.
- 150 is the default and is generally safe;
- If you have a high-traffic site, you might want to raise this to 200 or 300 to avoid banning legitimate users (e.g., people on corporate networks with shared IPs);
- If you're getting hammered, lower it to 50–100 — but be careful about false positives;
- For a normal WordPress site, 150 is a good starting point.
##### APF_BAN=1 (Make sure your APF version is at least 0.96)
##### APF_BAN=0 (Uses iptables for banning ips instead of APF)
APF_BAN=0
Set this to 0 unless you specifically use APF (Advanced Policy Firewall). Most VPS setups use iptables directly, so APF_BAN=0 is the right choice. This tells DDoS Deflate to ban IPs using iptables rules.
##### KILL=0 (Bad IPs aren't banned, good for interactive execution of script)
##### KILL=1 (Recommended setting)
KILL=1
Keep this at 1. Setting it to 0 runs in "dry run" mode — it detects bad IPs but doesn't actually ban them. Useful for testing, not for production.
##### An email is sent to the following address when an IP is banned.
##### Blank would suppress sending of mails
EMAIL_TO="root"
Enter your email address here to get an alert every time an IP is banned. If you don't want emails, leave it blank or set it to "".
Pro tip: If you get attacked a lot, you might want to leave this blank to avoid getting spammed with hundreds of ban notifications.
##### Number of seconds the banned ip should remain in blacklist.
BAN_PERIOD=600
How long (in seconds) an IP stays banned before being automatically unbanned. Default is 600 seconds = 10 minutes.
- For persistent attackers, you could raise this to 3600 (1 hour) or even 86400 (1 day);
- 10 minutes is a good default because most attacks move on after a few minutes anyway;
- Shorter ban periods also reduce the chance of accidentally banning legitimate users for too long.
Step 3: Whitelist Your Own IPs
The last thing you want is to accidentally ban yourself. Make sure to add your own IP, your server's IP, and any other trusted IPs to the whitelist.
Edit the whitelist file:
nano /usr/local/ddos/ignore.ip.list
Add one IP per line:
127.0.0.1
your.own.ip.address
your.server.ip.address
If you have a dynamic IP at home, be careful — you might get banned and locked out of your own server. It's a good idea to have console or VNC access as a backup, just in case.
Step 4: Testing It Out
Once you've configured everything, DDoS Deflate will run automatically every minute via cron. But you should test it to make sure it's working.
To manually run the script and see what it would do:
/usr/local/ddos/ddos.sh
To view currently banned IPs in iptables:
iptables -L INPUT -v -n
Or specifically check the DDoS Deflate chain:
iptables -L D_DOS -v -n
To manually unban an IP:
iptables -D D_DOS -s 192.168.1.1 -j DROP
(Replace 192.168.1.1 with the actual IP.)
To see recent ban activity, check your email (if you set EMAIL_TO) or check your syslog:
grep -i ddos /var/log/syslog | tail -20
Important Limitations (Please Read This)
I want to be completely honest with you. DDoS Deflate is a great free tool, but it has real limits. Here's what it cannot protect you against:
1. Volumetric Attacks (Bandwidth Floods)
If an attack is big enough to fill your server's entire network pipe (e.g., a 10Gbps attack hitting a 1Gbps port), nothing on your server can stop it — because the traffic is already clogging the pipe before it even reaches your machine.
For these kinds of attacks, you need upstream DDoS protection from your hosting provider or a service like Cloudflare.
2. Truly Distributed Attacks with Thousands of Unique IPs
DDoS Deflate works by banning individual IPs that make too many connections. If the attack is coming from 10,000 different IPs each making 5 connections, DDoS Deflate won't catch them because no single IP exceeds the threshold.
This is why it works well against small botnets and script kiddies, but not against large, sophisticated DDoS attacks.
3. Application-Layer Attacks That Mimic Real Users
Smart attackers can craft attacks that look exactly like legitimate traffic — with real browser headers, normal request rates per IP, and distributed IPs. These are much harder to detect with simple connection-counting.
For those, you need more sophisticated tools like:
- fail2ban (for log-based pattern detection)
- ModSecurity / WAF (web application firewall)
- Cloudflare or other CDN/WAF services
Bonus: Additional Ways to Harden Your VPS
DDoS Deflate is a great start, but here are a few more free things you can do to harden your VPS against attacks:
1. Use a CDN Like Cloudflare
Putting your site behind Cloudflare (the free plan works!) means all traffic goes through their network first. They absorb DDoS attacks, cache static content, and hide your real server IP.
This is the single most effective thing you can do for free.
2. Install Fail2Ban
Fail2Ban monitors your server logs (SSH, web server, etc.) and automatically bans IPs that show malicious behavior — like repeated failed login attempts or known attack patterns.
It's complementary to DDoS Deflate:
- DDoS Deflate = catches connection flood attacks
- Fail2Ban = catches brute-force and application-layer attacks
3. Keep Everything Updated
Most attacks exploit known vulnerabilities. Keeping your OS, web server, PHP, database, and CMS (WordPress, etc.) up to date eliminates the easiest attack vectors.
4. Use Your Host's Built-in DDoS Protection
Many VPS providers include at least basic DDoS protection for free. Check what your host offers — you might already have 5–10Gbps of protection you didn't know about.
5. Disable Unnecessary Services
Every open port and running service is a potential attack surface. Turn off anything you don't need — fewer things running = fewer things to attack.
Final Thoughts: Free Protection vs. Paid Protection
Let's end with some real talk about cost vs. value.
Free tools like DDoS Deflate, Fail2Ban, and Cloudflare's free plan will stop the vast majority of casual attacks — script kiddies, bored teenagers, small botnets, random vulnerability scanners. For most personal sites and small businesses, this is more than enough.
But if you're running a business that makes real money, and a few hours of downtime would cost you hundreds or thousands of dollars, then investing in proper DDoS protection from your hosting provider is absolutely worth it. A few extra dollars a month for guaranteed protection could save you from a catastrophic outage.
You don't have to choose one or the other. Run DDoS Deflate on your server and use Cloudflare and make sure your host has upstream protection. Layered defense is always better than a single solution.
Start with the free stuff. If and when you outgrow it, upgrade.
💻 Looking for a VPS with built-in DDoS protection?
sixcvm offers high-performance KVM VPS with free 20Gbps baseline DDoS protection included with every plan — so you get upstream protection plus the freedom to add your own tools like DDoS Deflate for layered security.
- 🛡️ Free 20Gbps DDoS protection — included with all plans, no extra charge;
- ⚡ NVMe SSD storage — fast disk I/O for better performance under load;
- 🌐 Optimized routes — low latency for visitors worldwide;
- 🔓 Full root access — install DDoS Deflate, fail2ban, or any other security tool you want;
- 👨💻 24/7 technical support — if you run into trouble, we're here to help;
- 💰 3-day money-back guarantee — try it risk-free.



