Hello,
We're experiencing major TCP SYN attacks lately, aimed at a public webserver that we host with a DNAT. The IIS is really taking a beating, although we have the TCP SYN Flood Protection setting (source address) as low as 5pps! We've also turned out country blocking and only alowing traffic from Skandinavia and the US.
Is there anything else we can do out of the UTM point of view so secure the webserver? I'm tried setting it up with WAF, but some functionality is lost and must be solved first. Would WAF "solve" the problem with TCP SYN or just pass it down to the IIS anyways?
Any help would be much appreciated.
Best Regards,
szo850
This thread was automatically locked due to age.