#Is it possible to fully disable ddos protection, that triggered by vpn connection?

59 messages · Page 1 of 1 (latest)

keen matrix
#

Is it possible to fully disable ddos protection, that triggered by vpn connection?

silver horizon
#

No

#

Use TCP VPN or another tunneling protocol on top of your UDP VPN

#

VAC might cut some UDP VPNs when you are under attack if the connection speed exceeds X mbps

keen matrix
silver horizon
#

You can whitelist with allow rule, but VAC can likewise override your rules to protect the network.

#

If your VPN traffic looks similar enough to the attack, it can cut it.

#

You can use traffic control to limit each client to 30 Mbps during attacks if you must run UDP VPN on a server that gets Bombarded with ddos

keen matrix
#

for UDP it shows "UDP" for tcp + tls it shows "FRAGMENT

odd scroll
#

If your server is a dedicated one, and your usage trigger our system, we can adjust our filter to better suit your needs.
But do not use a VPS as a VPN service.

silver horizon
#

^ Yeah, forgot this one

#

If its dedicated server, open support ticket and ask for adjustment

#

They can apply various levels on control over the backend anti-ddos decisions

keen matrix
silver horizon
#

Why dont you run TCP vpn though if its just dev access?

odd scroll
#

I understand, is it a dedicated server?
If yes, do a PCAP file, and send it in a ticket to our support.

odd scroll
silver horizon
#

Its shared system

odd scroll
# keen matrix VPS

Then our system will continue to block your server, as the treshold can't be changed on the VPS.

silver horizon
#

If you have VPS, change VPN protocol to TCP or limit your UDP VPN speeds during ddos attack

#

No way around it

odd scroll
silver horizon
#

Its UDP fragment which is being listed in your security center

#

Not TCP fragment

#

VPN is also fragmented UDP most of the times, so thats why it can also get filtered at certain tresholds

#

Your options are:

#
  1. Rate limit your vpn with traffic control to 20-30 Mbps per client if you must use UDP VPN
#
  1. Change vpn protocol to TCP
#
  1. Get a dedicated server instead which can be adjusted for you
keen matrix
#

I guess clients should be notified about this issue on "order" page

silver horizon
keen matrix
silver horizon
silver horizon
#

Would you prefer that? Plenty people offer it during attacks for their customers.

#

xD

keen matrix
#

I'd prefer to disable it at all

silver horizon
#

The server would lose internet during attacks then sir

keen matrix
#

As i remember it was optional some time ago.

odd scroll
silver horizon
#

Generic udp openvpn does not trigger VAC no matter how much traffic you push through

#

Same with wireguard

#

You need to use some pretty custom stuff for VAC to get triggered if there are no attacks ongoing against you

#

The above limitations apply when you are under active attack

keen matrix
#

wireguard works fine but not available for part of the required devices

silver horizon
#

Which devices does wireguard not work with?

keen matrix
#

OEM thin clients

#

maybe will try to create wireguard-wireguard gateway then

silver horizon
#

Your setup is way too custom

#

You need to understand that, you can't expect stuff like that to work out of box in the cheapest hosting option of third party company

#

OVHCloud tests their stuff for various use cases, including VPNs

#

If you wish to make stuff like this work, theres gonna be workarounds involved

#

This is not limited to ovhcloud

keen matrix
#

client ip whitelist or summary of 1gb connection was expected actually

silver horizon
#

Chances are, some competitors might not even offer this many solutions, but instead demand that you buy a more expensive service.

#

In short, you have plenty of options listed in this chat.