DDoS attack filtering

Job ID: 31189483

Budget: £20 – £250 GBP

I need to configure packet fitering that can be effective against DDoS attacks. I have 2 web server VMs hosted in two different physical servers. OS is windows server 2019. Hyper-v replica is set between vms. Failover to another virtual IP address need to be intitiated once the web server in production is overwhelmed by DDoS traffic. This can be linked to 70 percent of CPU or network utilisation. A script need to be written for that.
Furthermore, filtering should be triggered to filter the traffic going to the new destination web server (new virtual ip that would redirect traffic to the second physical server).
The network has pfsense router and firewall implemented. However, any fitering open source tool is accepted if it shows efficiency.
DDoS attacks in this experiment are tcp syn flood, udp flood, and http flood.