Hi mates,
I have a problem with a CP 16200 running in cluster that have overloaded by small DDoS.
As you can see, connections are around 113k (limit is 200k, so aggressive aging is not activated), incoming bandwidth should be around 200Mbit/s and all 43 workers are at 100%. There are no interface drops, 4x SNDs are at about 30%.
Attack is TCP- HTTPS and all connections are out of state, so firewall is dropping them with First packet isn't SYN.
Devices are running R81.10 with JHF109 and following blades enabled: Firewall, VPN, Mobile Access, Application Control, IPS, Identity Awareness, AntiBot, Monitoring.
Usually device is handling about 1Gbit traffic with 70k connections in normal days.
Recommendations in sk112241 are reviewed and applied but still device is almost not responding during such attack.
What could be the reason that it is so easy overloaded?
Thanks,
Dilian