29.07.2011, 16:47
iptables, or in particular a firewall which works with iptables, such as csf or apf, can block both standard security attacks, such as brute force, and DoS attacks if configured correctly, however that's all Linux only. The only way to protect against large scale DDoS attacks is either to have a large amount of bandwidth at use (and hope that no one goes over it when they attack you), or to invest in costly external firewall equipment.