We run a fairly large game server hosting company with about 60 machines running Server 2008, and DDoS attacks something we have been dealing with for a long time. Unfortunately, due to the prices of the market, there is no way that us or any other company could feasibly put hardware firewalls in all of our datacenters.
Our course of action has always been to just contact the datacenter, and they null route the IP address/Port for 24 hours. This of course is a very unappealing way of dealing with the issue, especially for our clients.
From what I understand, a software Firewall will only complicate the issues of a DDoS attack. I have read some about hardening the TCP/IP stack, but it sounds like there isn't much that can be done from Server 2008 to help with this.
Is there anything we can do?