• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

syn Flooding attack.

Scheduled Pinned Locked Moved Firewalling
11 Posts 4 Posters 1.0k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    sahan
    last edited by Mar 10, 2020, 8:54 AM

    Hi friends ,
    i configured pf sense as Multi-wan load balancer.
    From last Wednesday the system received Syn flood attack ,it consumed my all the bandwidth on my routers.Not only that the overall network has been slowed.The attack was hit to my OpenVPN access server in my DMZ
    the flood was directly attacked to the Openvpn Access server(port 1194 may be). And what is the vulnerability of this case.
    so how can i prevent this attack from the pf-sense.
    appreciate replies..!☺

    Screenshot_2020-03-07 Flood Alert to all devices.png

    J 1 Reply Last reply Mar 10, 2020, 10:56 AM Reply Quote 0
    • J
      JKnott @sahan
      last edited by Mar 10, 2020, 10:56 AM

      @sahan

      Assuming you've got pfSense next to your Internet connection, nothing. PfSense is your protection for your network.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      1 Reply Last reply Reply Quote 0
      • S
        sahan
        last edited by Mar 10, 2020, 11:23 AM

        This post is deleted!
        1 Reply Last reply Reply Quote 0
        • S
          sahan
          last edited by Mar 10, 2020, 11:25 AM

          My network basically like this
          Untitled Diagram.jpg

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator
            last edited by Mar 10, 2020, 11:25 AM

            @sahan said in syn Flooding attack.:

            it consumed my all the bandwidth on my routers

            You can not protect against a volumetric attack at your device.. The attack has to be addressed upstream of your pipe..

            If the pipe is full the pipe is full, there is nothing you can do at your end of the pipe..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 1
            • S
              sahan
              last edited by Mar 10, 2020, 11:27 AM

              so how to mitigate this attack from my network
              what is your suggestion

              1 Reply Last reply Reply Quote 0
              • N
                NogBadTheBad
                last edited by Mar 10, 2020, 11:28 AM

                @johnpoz said in syn Flooding attack.:

                u can not protect against a volumetric attack at your device.. The attack has to be addressed upstream of your pipe..
                If the pipe is full the pipe is full, there is nothing you can do at your end of the pipe..

                Talk to your ISP, needs to be fixed further up the chain.

                Andy

                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                1 Reply Last reply Reply Quote 1
                • J
                  johnpoz LAYER 8 Global Moderator
                  last edited by Mar 10, 2020, 11:30 AM

                  You need to get with your ISP on a volumetric attack, unless your advertising your own network space and could use a method of RTBH (Remotely-triggered Blackholing)...

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 1
                  • S
                    sahan
                    last edited by Mar 10, 2020, 11:34 AM

                    ok ill contact my ISP
                    thanks lot my friends 😍

                    1 Reply Last reply Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator
                      last edited by Mar 10, 2020, 11:34 AM

                      Keep in mind that ddos protection from your ISP normally comes with some sort of cost..

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      S 1 Reply Last reply Mar 10, 2020, 11:44 AM Reply Quote 0
                      • S
                        sahan @johnpoz
                        last edited by Mar 10, 2020, 11:44 AM

                        @johnpoz ok thanx 😉

                        1 Reply Last reply Reply Quote 0
                        11 out of 11
                        • First post
                          11/11
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                          This community forum collects and processes your personal information.
                          consent.not_received