Quote Originally Posted by Kewitt View Post
Filtering out traffic is pretty easy on any firewall that is why pass doss attacks come and go and we end user never really notice them.
This seems to be something different or a really wide spread Doss attack.
A properly executed DDoS attack is not easily handled by a firewall. By the time the packets reach the firewall it is already too late to filter them out.
It is not handling the packets that is the main problem, but the deluge of packets that will overflow the network connections causing real traffic to be dropped.