Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Does Pfsense Block 2-3 gbit Ddos on this hardware

    Scheduled Pinned Locked Moved Hardware
    10 Posts 5 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      thresh
      last edited by

      Hello,

      Sometimes i get ddos attack (2-3 gbit ).
      Can i block that attack with pfsense ?

      My Hardware :
      e3-1230v3 or e3-1225v3 CPU
      10gbe NIC
      8 or 16 or 32 gb ram
      and i have 10gbe uplink

      i will reject all protocol except UDP
      I just block some ip adress range like xx.xx.xx.xx/24

      Well, does pfsense block 2-3 gbit attack on this senario ?
      Sorry for my English
      Thanks

      1 Reply Last reply Reply Quote 0
      • T
        thresh
        last edited by

        Ups

        1 Reply Last reply Reply Quote 0
        • K
          kejianshi
          last edited by

          I'm not sure - Why don't you make a VM with similar resources available to the actual hardware you propose to buy and see if it handles it.?

          If thats possible for you.  Or you could pull your current drive, set it aside, install a new drive for pfsense test and if it doesn't work as you like, reinstall old drive and boot?

          I'd guess there are lots of ways to try it without losing your current configuration in the process.

          1 Reply Last reply Reply Quote 0
          • T
            thresh
            last edited by

            what about uptime for customer ? Our network 7/24 active :( That is risk for us. If pfsense can block 2-3 gbit ddos i will put out our mikrotik send mail our customer and put pfsense for security

            1 Reply Last reply Reply Quote 0
            • S
              Supermule Banned
              last edited by

              Thats what VM's are for ;)

              And no pfsense doesnt block 2-3gbit DDoS if the target is behind the box.

              It can break as easily as 20mbit of traffic if the attack is done right…

              1 Reply Last reply Reply Quote 0
              • T
                toomeek
                last edited by

                Can You try the following and report results?
                <<assuming 53="" attack="" on="" udp="">></assuming>
                System: Advanced: Firewall and NAT -> increase Firewall Maximum States value to something like 500000 or more
                same for Firewall Maximum Table Entries
                on Firewall: Rules -> WAN add a rule:
                proto: IPv4 UDP
                destination host: IP of target server behind firewall
                destination port: DNS (53)
                description: NAT DNS antiDOS
                enable Advanced Options and set:
                Maximum number of unique source hosts: 5
                Maximum state entries this rule can create: 20
                Maximum state entries per host: 2
                Adjust values to Your uplink.

                1 Reply Last reply Reply Quote 0
                • D
                  doktornotor Banned
                  last edited by

                  @TooMeeK:

                  Maximum state entries this rule can create: 20
                  Maximum state entries per host: 2

                  Can as well pull the cable…

                  1 Reply Last reply Reply Quote 0
                  • S
                    Supermule Banned
                    last edited by

                    You want people to not beeing able to get to your servers??

                    Maximum number of unique source hosts: 5
                    Maximum state entries this rule can create: 20
                    Maximum state entries per host: 2

                    1 Reply Last reply Reply Quote 0
                    • T
                      toomeek
                      last edited by

                      @Supermule:

                      You want people to not beeing able to get to your servers??

                      READ again: Adjust values to Your uplink.
                      And not SERVERS but server. This is only example for slow link, one DNS server.

                      Or maybe just give better example, huh?

                      1 Reply Last reply Reply Quote 0
                      • D
                        doktornotor Banned
                        last edited by

                        @thresh:

                        Sometimes i get ddos attack (2-3 gbit ).
                        Can i block that attack with pfsense ?

                        No.

                        @TooMeeK:

                        READ again: Adjust values to Your uplink.

                        Should not run DNS on WAN in the first place. For any other server that needs to be accessible, the suggested values are just not usable.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.