I have single PUBLIC ip on WAN interface of Mikrotik.
From yesterday I am continuously being hit by various public ip with UDP attack. this results in WAN link usage to 100% and chocking.
the src and dst ports (udp) are different. I tried to block ports, i tried to block source ip's in INPUT/FORWARD chains but still no use.
If I will ask my ISP to change the IP, they will but still its no solution, attack can come to new ip as well sooner or later.
in my LAB, i used 'UDP Unicorn' tool to FLOOd my mikrotik & it simply flooded mikrotik. no rules are blocking the UDP traffic. even i tried bandwidth limiting those pkts.
What is the real solution to this problem ? How can I block such UDP attack?