Hello , i am searching to protect from syn floods from spoof addresses since i bought routerboard CCR1036-12G-4S without any luck.
When syn attack comes to mikrotik after 50mbit (prox 5000pps/sec) cpu goes crazy and makes device unaccesible. I found some articles witch is block whole new reqests when syn attack comes. So it wont help becuse all network already unaccesible with that rules below : http://wiki.mikrotik.com/wiki/DoS_attack_protection
Try to analyze the TCP Packets, and search a scheme. Seems that the Packets are with len 0 or 1, then you can easy drop this. On my 1100 AH with 1,5 GB RAM i can block in this case 100k pps. But then is CPU @ 95%