Guys, I'm having DDOS attacks on my network and when it occurs, the packet rates (p/s) are above 7000 for the IPs that are being attacked. I have the contrack table disabled.
Would anyone know how to provide a solution so that I can identify the attacking IPs using "packet rates(p/s)" to add them to a blacklist and block them using the raw table?