normally the wg should autoblok syn flood generating IPs, if it really fails i would advise riorey
Main Topics
Browse All TopicsHello,
My server is currently being attacked by HTTP flood attack. It comes from distribution of spoofed IPs. My X-Peak Watchguard was doing well but the problem is the attacked had consumed a lot of bandwidth and still my website becomes inaccessible. I have subscribed for only 30MB instead the attacked was consumed in range of 100MB-150MB.
My question is :-
1. Since the ISP can't do anything to help me for at least route bad traffic to the blackhole, if there any hardware could block SYN attack and in the same time save my bandwidth instead of preventing from upstream provider?
2. I'm thinking to try using the Ddos mitigation services that provide proxy IP. Which one has provided competitive prices & good support instead of Prolexic (this one is absolutely under my budget)? Provider from East Asia region is much preferred.
Thanks for GOOD answers.
This question is in progress.
Our experts are working on an answer right now.
Sign up for immediate access to the solution once it becomes available.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
I have good experiences with Junipers SSG series when internal servers are flooded. Even the small SSG5 is good enough if you only have 30 Mb connection.
However, a serious and normal ISP would take this incident and help you with this. And the spoofed IP addresses, are they in the private IP range or public? Anyway, a good designed and configured ISP network, should block spoofed IP address in their routers, killing unwanted traffic as early as possible. In worst case, you have to change your IP address.
Business Accounts
Answer for Membership
by: The_KingPosted on 2009-04-19 at 10:25:56ID: 24179814
you can try toughening up your TCP/IP stack as described in the following link en-us/libr ary/aa3023 63.aspx
/DenialOfS erviceAtta ck/
http://msdn.microsoft.com/
and there is some more good info here
http://www.tcpiq.com/tcpIQ
sorry I couldnt help more hope you succeed