Secure your API from DDoS attacks with NGINX and fail2ban

Hi everyone!

Last week our production environment API was attacked by a DDoS attack. I wrote a blog post detailing how we fixed it by using NGINX and fail2ban.

If you have any suggestions or it worked for you, please let me know! I'm not an expert, so I will gladly take suggestions.



2 thoughts on “Secure your API from DDoS attacks with NGINX and fail2ban”

  1. Great article. You might also explore the fail2ban rules for ipset, I’m not sure if iptables-multiport make use of ipset.

  2. How would you alter your configuration if you need to watch a few different log files? I usually have a per-site error.log.


Leave a Comment