Back to articles
Technology Insight

Securing Your VPS: Deploying BunkerWeb WAF with Docker to Combat Port Scanning and Application-Layer DDoS

May 30, 2026

Introduction to Modern VPS Security Challenges

In the contemporary digital landscape, Virtual Private Servers (VPS) serve as the backbone for countless business applications, e-commerce platforms, and corporate portals. However, their public-facing nature makes them primary targets for cyber threats. Among the most pervasive and damaging of these threats are automated port scanning and Application-Layer Distributed Denial of Service (Layer 7 DDoS) attacks.

Port scanning acts as the reconnaissance phase for hackers, systematically probing your VPS to discover open ports and exploitable vulnerabilities. Once an entry point or weakness is identified, malicious actors can launch sophisticated application-layer DDoS attacks. Unlike volumetric attacks that attempt to overwhelm network bandwidth, Layer 7 attacks mimic legitimate user traffic to consume server resources (such as CPU, RAM, and database connections), ultimately rendering your business services unavailable to genuine customers.

To mitigate these risks effectively without complex manual firewall scripting, modern enterprises are turning to Web Application Firewalls (WAF). BunkerWeb emerges as a premier, open-source WAF solution designed to be highly secure, efficient, and seamlessly integrated with containerized environments via Docker. This guide provides a comprehensive blueprint for deploying BunkerWeb to protect your VPS infrastructure.

Why Choose BunkerWeb WAF for Your Business Infrastructure?

BunkerWeb is not just another reverse proxy; it is a security-first web server built on top of Nginx, engineered specifically to automate the protection of web applications. Here is why it stands out for business VPS environments:

  • Docker-Native Integration: BunkerWeb integrates flawlessly with Docker and Docker Compose. It can automatically detect new containers and apply security configurations dynamically, reducing operational overhead.
  • Automated Threat Mitigation: Out of the box, it features built-in protection against common web vulnerabilities (OWASP Top 10), automated let's Encrypt SSL management, and behavioral analysis to detect anomalies.
  • Advanced Anti-DDoS and Anti-Scanning Capabilities: It includes native integration with bad IP reputation lists, automated blacklisting, rate limiting, and challenge-response mechanisms (like reCAPTCHA or cookie validation) to thwart bots while letting human users pass.
  • Resource Efficiency: Designed to run in lightweight containers, BunkerWeb introduces minimal latency and resource consumption, making it ideal for cost-effective VPS deployments.

Prerequisites for Deployment

Before proceeding with the deployment, ensure your environment meets the following baseline requirements:

  1. A VPS running a clean installation of a modern Linux distribution (e.g., Ubuntu 22.04 LTS or Debian 12).
  2. A registered domain name with A/AAAA records correctly pointing to your VPS public IP address.
  3. Docker and Docker Compose installed on the system.
  4. Root or sudo administrative privileges on the server.

Step-by-Step Architecture and Implementation

Step 1: Preparing the Network and Directory Structure

To isolate your web traffic and ensure secure communication between the WAF and your backend applications, it is best practice to create a dedicated Docker network. Connect to your VPS via SSH and execute the following command:

docker network create bunkerweb-net

Next, organize your project files by creating a dedicated directory for your BunkerWeb configuration:

mkdir -p /opt/bunkerweb && cd /opt/bunkerweb

Step 2: Configuring the Docker Compose Environment

Create a docker-compose.yml file within the directory. This file will define the BunkerWeb instance and a sample backend business application (in this case, an Nginx container representing your web service) linked via our secure network.

Open the file with your preferred text editor (e.g., nano docker-compose.yml) and insert the following configuration:

version: '3.8'

services:
  bunkerweb:
    image: bunkerity/bunkerweb:1.5.8
    container_name: bunkerweb
    ports:
      - "80:8080"
      - "443:8443"
    volumes:
      - bw_data:/data
    environment:
      - SERVER_NAME=[www.yourdomain.com](https://www.yourdomain.com) yourdomain.com
      - SERVE_FILES=no
      - USE_REVERSE_PROXY=yes
      - REVERSE_PROXY_URL=/
      - REVERSE_PROXY_HOST=http://backend-app:80
      - AUTO_LETS_ENCRYPT=yes
      - [email protected]
      - USE_ANTI_SCAN=yes
      - ANTI_SCAN_COUNT=10
      - ANTI_SCAN_DURATION=60
      - USE_LIMIT_REQ=yes
      - LIMIT_REQ_RATE=20r/s
      - LIMIT_REQ_BURST=40
      - BAD_BEHAVIOR_THRESHOLD=10
    networks:
      - bunkerweb-net

  backend-app:
    image: nginx:alpine
    container_name: backend-app
    networks:
      - bunkerweb-net

volumes:
  bw_data:

networks:
  bunkerweb-net:
    external: true

Note: Replace yourdomain.com and [email protected] with your actual domain and contact email address to ensure successful SSL certificate generation.

Deep Dive into Security Parameters

Understanding the environment variables configured above is critical for tuning the WAF to your business's specific traffic profile:

1. Anti-Scanning Configurations

The parameter USE_ANTI_SCAN=yes activates BunkerWeb's proactive defense against port and directory scanners. When a bot attempts to access non-existent pages or scan for vulnerabilities, the WAF tracks the frequency. Under ANTI_SCAN_COUNT=10 and ANTI_SCAN_DURATION=60, if an IP generates 10 distinct 404 errors within 60 seconds, BunkerWeb flags it as a scanner and automatically blocks the source IP at the application level.

2. Layer 7 DDoS and Rate Limiting

Application-layer DDoS attacks aim to overwhelm web servers with massive request volumes. We mitigate this using USE_LIMIT_REQ=yes. The LIMIT_REQ_RATE=20r/s policy restricts any single IP address to a maximum of 20 requests per second under normal conditions, while LIMIT_REQ_BURST=40 allows temporary bursts up to 40 requests to accommodate media-heavy page loads without degrading legitimate user experience.

3. Global Reputation and Bad Behavior Tracking

The BAD_BEHAVIOR_THRESHOLD=10 setting works in tandem with internal anomaly detection algorithms. If a client triggers multiple minor security violations (such as anomalous user-agents, suspicious headers, or minor injection patterns), their internal score increments. Reaching the threshold results in an instant, automated temporary ban, keeping your VPS resources safe.

Deploying and Validating the WAF

With the configuration file properly tuned, launch your containerized security stack using the following command:

docker compose up -d

Verify that the containers are running smoothly by checking the logs and status:

docker compose ps

BunkerWeb will automatically communicate with Let's Encrypt to provision a trusted, free SSL certificate for your domain. Within a few minutes, navigating to [https://yourdomain.com](https://yourdomain.com) will display your backend application safely proxied behind the WAF.

Best Practices for Ongoing Business Operations

Deploying BunkerWeb is a massive step forward, but maintaining an optimal security posture requires ongoing attention:

  • Regular Automated Updates: Ensure your Docker images are updated regularly to patch newly discovered vulnerabilities. Use tools like Watchtower or scheduled cron jobs to pull the latest stable BunkerWeb releases.
  • Log Analysis and Auditing: Monitor container logs frequently to audit blocked IPs and identify potential false positives. This data is invaluable for tuning rate limits as your business scaling changes traffic patterns.
  • Layered Security Architecture: A WAF protects layers 7 and part of layer 4. For absolute resilience, combine BunkerWeb with hardware-level cloud firewalls (offered by your VPS provider) to drop non-web traffic (such as SSH on port 22) from unauthorized IP addresses entirely.

Conclusion

Protecting corporate digital assets no longer requires enterprise-level budgets or a dedicated team of security engineers. By combining the agility of Docker with the robust, automated defenses of BunkerWeb WAF, business owners and system administrators can effectively shield their VPS infrastructure from malicious port scans and application-layer DDoS attacks. Implement this architecture today to ensure your services remain secure, performant, and highly available for your clients.

Securing Your VPS: Deploying BunkerWeb WAF with Docker to Combat Port Scanning and Application-Layer DDoS | DPTCloud