

Dude, I do not pretend understand the inner machinations of a Lemmy mod. Rule 3 seems a blanket coverage for a lot of threads. But, I’m still out here repeating your recommends. Seems like it would be a jammy server for Docker containers at a good price.


Why are you getting packet flooding? DDoS? MAC address table overflows? Unknown unicast traffic? Broadcast storms? Multicast flooding? Undetermined? Ntopng will detect packet flooding, and it can be configured to send out notifications. Maybe Wireshark, tho it does have a learning curve and doesn’t send out notifications that I know of. Do you have a stand alone firewall like pFsense or Opnsense? Both Snort and Suricata are IDS/IPS that can block based on rule sets.