Syn Flood attack / DOS, offline for 48+ hrs.
I have been under a Syn Flood attack for over 48 hours. I have read through all the forums and tried everything I can think of. I am running ensim and the IP address that is being targeted is the primary IP for the server. We changed the IP address yesterday which stopped the attack for a little over 12 hours, but it is back again on the new IP.IP tables has done nothing. running APF which is doing nothing. The attack is showing up from 1,000's of different IPs.
What kind of hardware can be put into place? What are my options here?
Any help or useful suggestions?
Thanks,
Reller8