Skip to main content

One doc tagged with "syn-flood"

View all tags

DDoS protection

Limit denial-of-service attacks with RouterOS firewall rules: count new connections per source and destination with dst-limit, put pairs that exceed the rate on address lists and drop them in the raw table. Covers how the detection works, its limits, protecting the router itself, SYN floods with TCP SYN cookies and why SYN-ACK floods are dropped as invalid.