We got DDOS'd a while ago in our data centre. It turns out an ex employee we let go (performance related) paid (yes, actually paid) some people in German (we're in Australia) to fire off a DDOS against our servers from where ever their bots were.. Our upstream net provider blocked it for us. Yes: 1000's of IPs - because they used ICMP flooding - so they blocked ICMP traffic to us, upstream. Something we couldn't do ourselves but the ISP could do for us.
So it's not such a stupid suggestion at all. Of course, had they all launched port 80 TCP connections against us, yes, we would have been in serious trouble but I suppose we could have asked them to block non-Australian traffic for the day or until it stopped - overseas traffic is really not a big deal for us.
And for the record, the guy who kicked the whole thing off, we didn't bother to press charges, even though he bragged about it on Facebook (without first unfriending me, the idiot) because, thanks to the ISP, his efforts largely failed and we got some revenge when he tried to use us as a reference (and we were his only employers, so far).