Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    syn Flooding attack.

    Firewalling
    4
    11
    998
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • sahanS
      sahan
      last edited by

      Hi friends ,
      i configured pf sense as Multi-wan load balancer.
      From last Wednesday the system received Syn flood attack ,it consumed my all the bandwidth on my routers.Not only that the overall network has been slowed.The attack was hit to my OpenVPN access server in my DMZ
      the flood was directly attacked to the Openvpn Access server(port 1194 may be). And what is the vulnerability of this case.
      so how can i prevent this attack from the pf-sense.
      appreciate replies..!โ˜บ

      Screenshot_2020-03-07 Flood Alert to all devices.png

      JKnottJ 1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott @sahan
        last edited by

        @sahan

        Assuming you've got pfSense next to your Internet connection, nothing. PfSense is your protection for your network.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • sahanS
          sahan
          last edited by

          This post is deleted!
          1 Reply Last reply Reply Quote 0
          • sahanS
            sahan
            last edited by

            My network basically like this
            Untitled Diagram.jpg

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              @sahan said in syn Flooding attack.:

              it consumed my all the bandwidth on my routers

              You can not protect against a volumetric attack at your device.. The attack has to be addressed upstream of your pipe..

              If the pipe is full the pipe is full, there is nothing you can do at your end of the pipe..

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 1
              • sahanS
                sahan
                last edited by

                so how to mitigate this attack from my network
                what is your suggestion

                1 Reply Last reply Reply Quote 0
                • NogBadTheBadN
                  NogBadTheBad
                  last edited by

                  @johnpoz said in syn Flooding attack.:

                  u can not protect against a volumetric attack at your device.. The attack has to be addressed upstream of your pipe..
                  If the pipe is full the pipe is full, there is nothing you can do at your end of the pipe..

                  Talk to your ISP, needs to be fixed further up the chain.

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  1 Reply Last reply Reply Quote 1
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    You need to get with your ISP on a volumetric attack, unless your advertising your own network space and could use a method of RTBH (Remotely-triggered Blackholing)...

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 1
                    • sahanS
                      sahan
                      last edited by

                      ok ill contact my ISP
                      thanks lot my friends ๐Ÿ˜

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        Keep in mind that ddos protection from your ISP normally comes with some sort of cost..

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        sahanS 1 Reply Last reply Reply Quote 0
                        • sahanS
                          sahan @johnpoz
                          last edited by

                          @johnpoz ok thanx ๐Ÿ˜‰

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.