Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    ISP DDoS Protection

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 4 Posters 693 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      e066377
      last edited by e066377

      I work for an ISP company, and for last 2 days our SSG network is under DDoS attack and users are complaining about very slow Internet access with high packet drop rate. We have been using pfSense for ipsec vpn connection between ISP and main telecom company and now we need to put all network behind a firewall if it is possible to protect network from DDoS attacks. Can we use pfSense for this job, what firewall rules we should add?

      Thanks.

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        A firewall is not any protection against DDoS.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • E
          e066377
          last edited by

          Thanks Derelict,

          I think we need not firewall rules but policy rules for DDoS.

          1 Reply Last reply Reply Quote 0
          • chpalmerC
            chpalmer
            last edited by

            You need your upstream provider to help you mitigate the attack.

            Have you been in contact with them?

            Triggering snowflakes one by one..
            Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

            1 Reply Last reply Reply Quote 0
            • E
              e066377
              last edited by

              Hi chpalmer,
              Yes, but their DDoS protection service is too expensive, they ask 2000 dollars per month.

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                If your pipe is full, it is full. There is nothing you can do about that after the traffic is already in the pipe.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • bmeeksB
                  bmeeks
                  last edited by bmeeks

                  This seems to be a very popular misconception -- that a firewall at the endpoint can stop or mitigate a DDoS attack.

                  A little bit of Google research, if you are new to network protection and security, would go a long way toward understanding what a DDoS actually is, what the symptoms are and where it must be remediated.

                  Hint -- it's not with a firewall at your end of the connection. It's at your ISP's end of the connection, and if you are an ISP, it's at the higher tier ISP or bandwidth provider's endpoint that you are connected to for your Internet connection. Your upstream provider has to stop putting the DDoS traffic into your connection pipe. Once all those DDoS packets are in your Internet pipe, as @Derelict said, your pipe is full and that's that -- nothing a firewall at your end can do then.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.