Some DDoS's are easy to block via iptables- attackers who aren't very clever will have the same UA on all of their bots, and they are easy to block via a combination of tailing your domlogs, and adding bad ips to an iptables listing. Many don't set a user agent, making it much easier.
Floods that consist of holding open http server connections for long periods of time can be combated by throwing MaxClients to something large (about 5000) and setting keepalive to something low, like around 5 seconds (if you're using Apache, similar probably holds true for other http servers).
You can usually use string blocking via iptables, but these will still hold the connection open until the client times out, and you might have to resort to the above in conjunction (raise MaxClients, etc.). Usually, I try to mitigate via IP addresses before string blocking.
Rarely will I see an attack that will require a nullroute upstream. If you're worried about those, you will need to seek professional services. In most cases, you can mitigate at the server level easily. Also, ngrep is your friend.