Hello!
I got DDoS on my router (RB751G-2hnd) from ether1 port.
I could fix it only after 10 hours of DDoS by adding a rule into firewall.
All of this time router had 100% loaded CPU.
After this on ports with 192.168/16 subnet:
1. Router response on only 1 of 20-30 pings with 2000-3000ms time.
2. Winbox works very-very slow.
3. All packets that from or to 192.168/16 subnet flow very-very slow or dont flow.
CPU have 0-3% load.
I didnt anything except adding one rule into firewall that drop all packets from evil IP.
Removing this rule doesnt help.
I have this config:
ether1 - gateway to the internet with dhcp client
ether2-ether4 - switch with 192.168/16 subnet
ether5-wlan1 are bridged, it have 172.16.1/24 subnet
On ether5 and over wifi the router works perfect.
Entry in Winbox by MAC-address works perfect (from all ports).
Full reset and restoring backup didnt help.
Firmware 6.22.