CCR1072 firewall connection tracking max-entries: 1048576

Follow the guidelines here. With the DDoS rules in place along with rubbish traffic being dropped in the raw table, the conn_track table will never get flooded.

http://forum.mikrotik.com/t/how-to-edge-router-and-bng-optimization-for-isps/150007/1