Outbound DDoS attacks and IP spoofing

Hi

I am having issues with some clients that have clients on their server boxes who send outbound spoofed DDoS attacks. The major issue with the DDoS attacks outbound is they can generate 150k pps and this causes my router CPU to go to 100% and eventually it reboots itself and crashes.

I would like a way to stop the increased packets from crashing my router or at least a way to filter out the illegitimate traffic using firewall rules, if this is the best route then what exact firewall rules should I use?

My router: CCR1036-8G-2S+

I appreciate any help.