How to Block SYN Flood Attack using Mikrotik Router Firewall Filter Rules Configuration

preview_player
Показать описание
How to Block SYN Flood Attack using Mikrotik Router Firewall Filter Rules Configuration.
Рекомендации по теме
Комментарии
Автор

this is NOT a syn flood detection. This rule blocks any connection from IP, if they exceed defined rate. But what if the connection is valid? It gets blocked as well! Syn Flood is typical situation, where SYN packet is sent, but nothing else (server has to wait and waste resources). This rule counts all connections, including valid ones.

vecernik
Автор

Very good examples. But I think that in this case better instead of action = drop use the action = tarpid

abuszek