Feature Request: better SYN flood DDOS protection

I’m dealing with a B One which is under attack from a DDOS SYN flood style attack.

Although the Peplink Firewall claims to block thes sorts of attacks, they are still getting through.

Here’s a macOS bash script to diagnose the attack, counting the # of connections stuck in the SYN_RCVD state:

SYN Flood Logger for macOS
Edit: I have a nice bash script, but the forum software is giving me 403 errors when I try to include it.  Likely it doesn't allow some of the keywords in the script?  Please send me a PM if you want a copy.

Here is the output of this script on a server under attack:

./syn_flood_logger.sh
--------------------------------------------
Connections stuck in SYN_RCVD
--------------------------------------------
IP Address         Connections  Country
--------------------------------------------
165.154.8.10       16           India
128.14.226.122     21           Taiwan
91.124.18.144      15           The Netherlands
152.32.181.65      17           United Arab Emirates
101.36.97.173      15           United Kingdom
169.197.113.233    14           United Kingdom
107.150.105.104    18           United States
23.93.33.203       10           United States

In the past, I was able to stop this attack using Regional blocking: Link as the attack was originating from a single country (Brazil).

However, as you can see now, the attack is coming from all over the globe (I suspect residential proxies are being used).

Feature Request

  • Improve the built-in DDOS protection rules to catch and block these sorts of attacks
  • Allow us to customize these rules, for example “If _____ SYN packets are received from the same IP within ____ seconds, block the IP for _____ seconds”
  • Add logging so we can see when this DDOS protection is working
9 Likes

good feature requests. In the mean time, i would block all traffic except from your country. I have all traffic except US traffic blocked. works well

1 Like

i hope you have firewall rull incoming block all enabled plus DDOS protection on and i heard mixed brand equipment can cause it too if internal but your external could you only allow certain ips through you trust like certain apps if in app list im woundering if that would help

Other thing you can do is use something like control D or even other dns providers that block incoming and outgoing connections to those servers or even worst yet change ip addresses as well make sure UPNP is off as well do not use it

You should change your topology on how that server is shown to the WAN.

Change any default ports and use custom ports.

A lot of times ports are opened or the firewall is 100% capable of blocking but customers don’t understand how to properly mitigate or know the full scale of their topology,

If your using a balance One that’s a small branch router which means it can’t be that complex.

The device does have logging and you can also open a. Ticket with peplink support directly if you have a prime care license for questions.

You should also have better inbound firewall rules to block everything except the white listed IPs you allow vs letting everything come in.

Also blocking everything from everywhere except US traffic is also a good move.

If not your going to get his with Bots all the time especially if your server or have DNS Ip’s exposed to the WAN. Iran, Chinese and Russia bots are horrible now days.