Originally Posted by win32sux
The way I understood it, he's not accepting any connections at all.
The iptables rule he posted would send all packets (regardless of protocol) to DROP.
Exactly, I DROP anything on INPUT. You could try it and observe the CPU.
Netfilter consumes very much processor trying to drop such a great amount of traffic.
It drops on INPUT but the packets still traverse PREROUTING chain, then comes the routing decision ant then it gets dropped.
A second problem is that in such a case all your downstream traffic is consumed by the flooded packets. Is this right?