Drop filter doesn't work

It goes through a router ddos attack . firewall detects packets , but the built-in DNS continues to send responses. Please help me.