I'm running stretch on a Pi 3B+ with a ZTE H268A router. I'm getting heap of TCP SYNs from maybe 20 IPv4 addresses. My SYN,ACK response is apparently ignored and the Pi does try retransmission which is making things worse.
This Pi is running a web server so I do need port forwarding on the router. I've tried blocking some of the IP addresses both in the router and also using iptables in the Pi. But neither of these seem to have any effect on the SYN packets.
Does anybody know how I can disable retransmission of the SYN,ACK packets ? Or how to get iptables to ignore SYNs from these addresses ?