Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Sigbjorn
Advisor

DTLS Amplification DDoS Attack on Citrix ADC and Citrix Gateway

Hi,

I'm sure you're all aware of this attack by now, more details can be found on Citrix webpage: https://support.citrix.com/article/CTX289674

 

We have upgraded our environments and enabled "Hello Verify Request", but even so, there amount of actors attempting to abuse this is filling our connection tables and causing issues for our legitime traffic.

Disabling DTLS altogther seems like the best solution so far, as they give up faster, but we still see connection spikes from time to time and would like to know how we can handle it better.

Are there any IPS signatures, or other ways to throttle the udp/443 traffic from the threat actors abusing this?

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

You can definitely rate limit these inbound connections using fw samp/sam erdos or similar.
Other than that, I'm not aware of a specific action you can take here.

0 Kudos
Chris_Atkinson
Employee
Employee

Geo policy/blocking might also help depending on the specific origins of what you're seeing.

 

 

0 Kudos