Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    How to limit number of states from external ips to one specific internal IP?

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 2 Posters 765 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      rmm
      last edited by

      We've been getting DDoS attacks lately.  RCP SYN floods from 300,000+ random IP addresses, meaning 300,000+ state table entries from random IPs to one specific IP on our network.

      We find that blackholing the target IP helps, but until we notice it the state table can fill up and that causes other issues.

      How can I place a limit on the number of states that can be created from any number of external addresses to one specific internal address?

      The settings I see seem to limit the number of states involving the source IP…

      Thanks,

      1 Reply Last reply Reply Quote 0
      • P Offline
        phil.davis
        last edited by

        You should be able to have a pass rule on WAN from source any, destination "specific IP on your network" and then in the Advanced Features, Advanced Options section choose things like:

        • Maximum state entries this rule can create
        • Maximum number of unique source hosts

        Those should let you limit the "passed" state entries created.

        Of course, you can't tell it to let the genuine connections through and block just the DDOS ones!

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • R Offline
          rmm
          last edited by

          That would probably wiork. for some cases here…

          But what if I don't know which local IP it will be?  I'd like to set a limit of, say, 10,000 states per internal IP address regardless of the remote IPs.

          1 Reply Last reply Reply Quote 0
          • P Offline
            phil.davis
            last edited by

            If you do not have hundreds of internal servers, then you can make a rule for each internal server IP as destination. That is work to setup if you have a lot of web servers, so others feel free to add suggestions.

            As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
            If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.