While firewalls and stateful devices such as VPN gateways, IDPS, and load balancers are pivotal in defending our networks, they are, unfortunately, not immune to DDoS attacks.The vulnerability lies in the fact that these devices were never engineered to thwart DDoS attacks, notably those inducing TCP state exhaustion attacks. Consequently, industry guidelines strongly advocate for the deployment of stateless DDoS protection ahead of the firewall. This strategic placement not only shields the firewall but also safeguards other stateful devices and the services they protect from debilitating downtime.
Click to enlarge image