I'm sure you're all aware of this attack by now, more details can be found on Citrix webpage: https://support.citrix.com/article/CTX289674
We have upgraded our environments and enabled "Hello Verify Request", but even so, there amount of actors attempting to abuse this is filling our connection tables and causing issues for our legitime traffic.
Disabling DTLS altogther seems like the best solution so far, as they give up faster, but we still see connection spikes from time to time and would like to know how we can handle it better.
Are there any IPS signatures, or other ways to throttle the udp/443 traffic from the threat actors abusing this?