When volumetric Distributed Denial of Service (DDoS) attacks hit internet-facing servers in Pakistan—such as DNS amplification attacks, UDP reflection floods, or SYN floods exceeding 10 million packets per second (Mpps)—standard Linux firewall architectures quickly fail.
Traditional Netfilter engines (iptables and even basic nftables) process packets relatively late in the kernel network stack, after sk_buff allocation, socket lookups, and connection tracking (conntrack). Under high packet rates, CPU cores become saturated with ksoftirqd software interrupts, causing severe packet drops and system unresponsiveness.
To filter traffic before kernel socket overhead, systems engineers turn to Traffic Control (tc) with the flower classifier.
tc-flower provides fine-grained, line-rate packet classification directly at the ingress queue. Even more powerfully, modern Enterprise SmartNICs (NVIDIA Mellanox ConnectX-5/6, Intel E810) can offload tc-flower filter rules directly into network card hardware ASICs, dropping malicious traffic at line rate with zero CPU utilization!
In this guide, we break down how to configure tc-flower filtering and enable hardware offloads on Dedicated Servers in Pakistan.
Understanding tc-flower in the Linux Kernel Datapath
Incoming Packet (Physical Fiber Interface)
│
▼
[SmartNIC Hardware ASIC]
│ (tc-flower skip_sw hardware offload rule match?)
├── MATCH: [HARDWARE DROP!] (Zero CPU cycles used!)
│
▼ (Passes to Host Driver)
[Ingress qdisc (tc / cls_flower)]
│
├── Soft Match: [SOFTWARE DROP] (Bypasses Netfilter / conntrack!)
│
▼ (Standard Kernel Network Path)
[Netfilter / iptables / IP Stack]
By filtering traffic at the ingress qdisc using cls_flower, the Linux kernel evaluates packet headers (L2 MAC, L3 IP, L4 Port, TCP Flags) before conntrack state tables allocate memory, keeping the server responsive even under heavy DDoS attack.
Step 1: Adding Ingress Qdisc to the Network Interface
Before adding classifier rules, attach an ingress queuing discipline (qdisc) to your network interface (e.g., eth0 or ens1f0np0):
# Add ingress queuing discipline
sudo tc qdisc add dev eth0 ingress
Verify that the ingress qdisc is active:
tc qdisc show dev eth0
Step 2: Rate Limiting & Blocking Malicious Protocols via tc-flower
Rule 1: Drop All Incoming UDP Amplification Traffic (NTP, DNS, Memcached)
Attackers frequently exploit open NTP (port 123) and Memcached (port 11211) servers for massive volumetric reflection attacks. To drop all incoming UDP packets originating from these amplification source ports:
# Drop UDP traffic originating from port 11211 (Memcached Reflection)
sudo tc filter add dev eth0 ingress protocol ip prio 1 flower \
ip_proto udp \
src_port 11211 \
action drop
# Drop UDP traffic originating from port 123 (NTP monlist reflection)
sudo tc filter add dev eth0 ingress protocol ip prio 1 flower \
ip_proto udp \
src_port 123 \
action drop
Rule 2: Mitigate SYN Floods with tc Police Rate Limiting
Instead of dropping all new TCP connections, use police actions to rate limit TCP SYN packets to 5,000 packets per second, dropping excess burst traffic:
# Rate limit TCP SYN packets to 5000/s with a 1000-packet burst
sudo tc filter add dev eth0 ingress protocol ip prio 2 flower \
ip_proto tcp \
tcp_flags 0x02/0x02 \
action police rate 5000pps burst 1000pkts drop
Step 3: Enabling Hardware Offload (skip_sw) on Enterprise SmartNICs
If your server is equipped with a SmartNIC (such as an NVIDIA Mellanox ConnectX-5 or ConnectX-6 Dx), you can instruct the Linux kernel to push the filter rules directly into the NIC’s ASIC hardware tables using the skip_sw flag:
# Verify SR-IOV and switchdev support on the network interface
ethtool -k eth0 | grep tc-offload
# Output: hw-tc-offload: on
Add an offloaded hardware drop rule:
# The 'skip_sw' flag pushes the rule strictly to hardware ASIC
sudo tc filter add dev eth0 ingress protocol ip prio 1 flower \
skip_sw \
ip_proto udp \
src_port 53 \
action drop
If the card supports the rule, the filter executes entirely on the network adapter. Even a 40Gbps DNS flood will be discarded directly inside the NIC ASIC without generating a single CPU interrupt!
Step 4: Monitoring Filter Statistics in Real Time
Inspect packet drops and line-rate execution metrics:
# View active tc-flower filters and drop counters
sudo tc -s filter show dev eth0 ingress
Sample output:
filter protocol ip pref 1 flower chain 0
filter protocol ip pref 1 flower chain 0 handle 0x1
ethertype ipv4
ip_proto udp
src_port 11211
not_in_hw
action order 1: gact action drop
random type none pass val 0
index 1 ref 1 bind 1 installed 420 sec used 2 sec
Action statistics:
Sent 1420582910 bytes 12450892 pkt (dropped 12450892, overlimits 0 requeues 0)
backlog 0b 0p requeues 0
Notice the statistics: over 12.4 million malicious packets were dropped cleanly at the ingress boundary before consuming host CPU or memory resources!
Combining tc-flower with Enterprise Bare Metal
While Cloud VPS instances handle moderate traffic shaping, achieving true line-rate hardware offload requires bare-metal access to PCIe network adapters.
Deploying on high-performance Dedicated Servers gives you direct access to enterprise network hardware, sub-millisecond packet processing, and custom carrier-grade DDoS defenses.
Protect Your Infrastructure with NextGen Bare Metal
Defend your web platforms and database clusters against volumetric DDoS attacks. NextGen Dedicated Servers in Pakistan feature enterprise SmartNIC hardware, 10Gbps unmetered uplinks, and custom BGP mitigation.
