Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DDoS attack - need help!

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 4 Posters 854 Views 6 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F Offline
      Feche
      last edited by

      Hi there, I have a pfSense instance that has 1gbps symetric connection - I host game servers and recently I have a problem with one gameserver:

      A random person attacks the server port (31128 in this case) and the pfSense instance hangs up - State table size goes over 2 million connections and CPU usage stays at 20%~ (6 core CPU) and WAN inbound is around 15mbps.

      From what I've seen, the attack is UDP and only on that port but there are thousands of IP's on the log so I cannot block them manually - that's why I have installed pfBlockerNG but I still have this issue, seems like it is not blocking the attack.

      Any help please? Thanks!

      chpalmerC 1 Reply Last reply Reply Quote 0
      • chpalmerC Offline
        chpalmer @Feche
        last edited by

        @feche

        You cannot block DDOS at the firewall level efficiently. That has to be done upstream.

        It isn't cheap.

        Triggering snowflakes one by one..
        Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

        bingo600B 1 Reply Last reply Reply Quote 0
        • bingo600B Offline
          bingo600 @chpalmer
          last edited by bingo600

          @chpalmer said in DDoS attack - need help!:

          @feche

          That has to be done upstream.

          Keyword "DDOS Scrubbing" by ISP

          It isn't cheap.

          Agree

          If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

          pfSense+ 23.05.1 (ZFS)

          QOTOM-Q355G4 Quad Lan.
          CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
          LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ Online
            johnpoz LAYER 8 Global Moderator @bingo600
            last edited by johnpoz

            If its a state exhaustion attack, that can be sometime mitigated at the firewall.. Are you trying to block countries they are coming from? Not sure what your tying to do with pfblocker.

            Your going to have to show us what your trying to do with pfblocker.. Do you have a list of known bad IPs that are being used in the attack, a list of ASNs? IP ranges? IPs from countries? Create your alias that lists the ips you want to block and put it in front of your port forward on your wan rules.

            IPS could be used to filter traffic based on some signature that distinguishes good traffic from bad traffic to the same port.

            But as stated if its a volumetric attack - there is nothing you can do on the firewall.. A volumetric attack has to be mitigated upstream of your pipe, be it 1gig, 10gig or 100 even..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 25.07 | Lab VMs 2.8, 25.07

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.