It looks like part of the traffic is being dropped due to some buffer or hash table being full. The traffic is really clean-cut, kernel counters would have to be examined in order to pin this down. Is this a SYN flood only or mixed with real traffic? Is real traffic being dropped in a way that services are severely disrupted (TCP connections in particular)? I can see ICMP drops, one would expect that under heavy load such as this (input queue is full). Also, the CPU seems to be stressed out while trying to grab the traffic. Did you run the same with pfSense, and if so how did that differ?Thanks,Franco