Thanks for u suggestion
@trialotto
They are some kids and they are just jealous for my service. but the problem is cause my company has no protection for ddos'ers
So now i have talk with one friend and they has give me this script called "DDos Deflate" Is not Admin Ahead Extension!
Some times ddos is 100MB/s some times 2-3 GB/s, And they has ddosing me on port 22,80,21
They start 1 day ago when my server has been up without firewall, fail2ban and modsecurity,
Some times they has ddossing me on port 80 and all domains hosted by me was down!
after this they start to ddosing me on port 21 and 22. and i login on my server via serial console and i shut it down
today i start to work with it
as i say i have install this script Ddos deflate, csf + one script for iptables.
i have install psad and i have block others to use "ping" or "nmap" on server ip.
but i'm learning how to create one filter for fail2ban and psad, example if is and report from psad if anyone has try to scan server port fail2ban will make it ban
i have read this post
http://webmasters.stackexchange.com/questions/30821/fail2ban-port-scanning
i have write on fail2ban conf this
failregex = PORT DENIED: .* SRC=<HOST> but is not working for now.
also i have active all jails for fail2ban
failure numbers "1"
modsecurity ON
i have change my server ip. and for all domains hosted by me i'm using ipv6 not ipv4. cause they don't know how to ddos ipv6

also i have read some posts on google, for ddos protection example some people can install a proxy on my server to protect me. but i have one server from OVH which is with anti DDos and i'm reading on google maybe i find a way how to do this with my server.
My server is up for now. and i hope to stay up!
And Sorry for bad english!