DDoS Packet-Per-Second (Mpps), Gbps Bandwidth & WAF Rate-Limit Calculator (2026)

Model L3/L4 volumetric DDoS floods (SYN, UDP amplification, Ethernet framing overhead) and calculate optimal Cloudflare WAF & Nginx burst rate-limiting rules for L7 HTTP floods.

DDoS Packet-Per-Second (Mpps), Gbps & WAF Rate-Limit Calculator — Interactive Console
Runs locally in your browser • Instant output
Wire-Rate Packet Throughput
14.88 Mpps
Million packets/sec (incl. 20B L1 overhead)
10GbE NIC Saturation
100%
Upstream link exhaustion ratio
Required Spoofed Botnet Uplink
17.99 Mbps
Via NTP (556x) amplification
Cloudflare WAF Custom Rule & Rate Limiting Expression
# Cloudflare Rate Limiting Rule (Exceeds 50 req/10s per IP)
Expression : (http.request.uri.path contains "/login" or http.request.method eq "POST") and (cf.threat_score gt 14 or not ip.geoip.country in {"US" "GB" "IN"})
Action     : Managed Challenge (or Block for 600s)
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![DDoS Packet-Per-Second (Mpps), Gbps & WAF Rate-Limit Calculator](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/ddos-pps-bandwidth-waf-calculator/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/ddos-pps-bandwidth-waf-calculator/">DDoS Packet-Per-Second (Mpps), Gbps & WAF Rate-Limit Calculator — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: DDoS Packet-Per-Second (Mpps), Gbps & WAF Rate-Limit Calculator

Quick Answer & 2026 Technical Summary (ddos pps gbps calculator)Updated 2026 Standard

Although a minimum Ethernet frame is 64 bytes (512 bits), IEEE 802.3 requires a 7-byte preamble, a 1-byte Start Frame Delimiter (SFD), and a 12-byte minimum Inter-Frame Gap (IFG) between every packet on the wire. That adds 20 bytes (160 bits) of Layer-1 overhead per packet, totaling 84 bytes (672 bits). Dividing 10,000,000,000 bps by 672 bits/packet yields exactly 14,880,952 packets per second (14.88 Mpps). Use this interactive ddos pps gbps calculator above to test packets per second to gbps converter, ethernet wire rate 64 byte mpps, and udp amplification factor calculator locally in your browser with zero server uploads.

Target Keyword Spec: ddos pps gbps calculator | Modules: True Wire-Rate Mpps ↔ Gbps Converter • UDP Reflection & Amplification Simulator • Router CPU vs Pipe Saturation Bottleneck Analyzer
Primary Focus: ddos pps gbps calculator
Core Capability: packets per second to gbps converter
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
True Wire-Rate Mpps ↔ Gbps Converterpackets per second to gbps converterAccounts for the mandatory 20-byte IEEE 802.3 Ethernet Layer-1 overhead (7B...Network & Scrubbing Center Capacity Planning
UDP Reflection & Amplification Simulatorethernet wire rate 64 byte mppsModel spoofed-source reflection vectors across DNS (54x), NTP monlist (556....Application Layer (L7) API & Login Rate Limiting
Router CPU vs Pipe Saturation Bottleneck Analyzerudp amplification factor calculatorCompare attack Gbps and Mpps against your uplink bandwidth and firewall/ASI...CEH DDoS Architecture & Incident Post-Mortem Analysis
Execution & Privacy Architecture100% Client-Side WebCrypto / JS Sandbox0 Bytes Sent to External ServersSafe for internal SOC & authorized lab artifacts
NIST SP 800-53 / OWASP AlignmentOWASP ASVS v4.0.3 / NIST CSF 2.0Deterministic Rule & Header VerificationMaps findings to actionable hardening controls
Cryptographic & Entropy StandardSHA-256 / AES-256-GCM / Argon2id≥ 128-bit Effective Security MarginMeets 2026 post-quantum & zero-trust baselines
In-Depth ZerosUniverse Tutorial

What is a DDoS Attack? L3/L4/L7 Floods & Mitigation Guide

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use DDoS Packet-Per-Second (Mpps), Gbps & WAF Rate-Limit Calculator

01

Select Attack Vector Preset or Custom Packet Size

Choose 64-Byte TCP SYN Flood, DNS Amplification, NTP Monlist, or custom packet length (64 to 1518 bytes) and packet rate (kpps/Mpps).

02

Set Your Uplink Capacity & Firewall Mpps Ceiling

Select your network interface speed (1 Gbps, 10 Gbps, 40 Gbps, 100 Gbps) and stateful firewall packet-processing rating.

03

Inspect L2 Payload vs L1 Wire-Rate Bandwidth

Compare actual Ethernet wire utilization (including Preamble and Inter-Frame Gap) and check whether your link fails on bandwidth or PPS.

04

Generate L7 Nginx & Cloudflare Rate-Limit Configs

Enter your normal per-IP request rate to copy ready-to-deploy `limit_req_zone` and Cloudflare WAF mitigation blocks.

Key Capabilities & Technical Architecture

True Wire-Rate Mpps ↔ Gbps Converter

Accounts for the mandatory 20-byte IEEE 802.3 Ethernet Layer-1 overhead (7B Preamble + 1B SFD + 12B Inter-Frame Gap) revealing why 64-byte minimum frames saturate 10GbE at 14.88 Mpps.

UDP Reflection & Amplification Simulator

Model spoofed-source reflection vectors across DNS (54x), NTP monlist (556.9x), CLDAP (56x), SSDP (30x), and Memcached UDP (51,000x) to see how small botnet uplinks saturate upstream links.

Router CPU vs Pipe Saturation Bottleneck Analyzer

Compare attack Gbps and Mpps against your uplink bandwidth and firewall/ASIC packet-forwarding ceiling to pinpoint whether the pipe or state table fails first.

L7 WAF & Nginx limit_req Rule Generator

Input your peak legitimate user RPS and burst duration to generate copy-ready Nginx `limit_req_zone` directives and Cloudflare WAF Rate Limiting expressions.

Practical Use Cases

Network & Scrubbing Center Capacity Planning

Determine why a 10 Gbps NIC or stateful firewall drops traffic during a 6.72 Gbps small-packet TCP SYN flood that exceeds 10 Million Packets Per Second.

Application Layer (L7) API & Login Rate Limiting

Calculate safe request-per-second thresholds and burst buckets so flash crowds pass without friction while credential-stuffing and HTTP/2 Rapid Reset floods are throttled.

CEH DDoS Architecture & Incident Post-Mortem Analysis

Translate cloud provider DDoS mitigation reports (Mpps, Gbps, RPS) into exact packet sizes and botnet amplification math.

Frequently Asked Questions (FAQs)

Why is the maximum packet rate of a 10 Gbps Ethernet link 14.88 Mpps for 64-byte packets?+

Although a minimum Ethernet frame is 64 bytes (512 bits), IEEE 802.3 requires a 7-byte preamble, a 1-byte Start Frame Delimiter (SFD), and a 12-byte minimum Inter-Frame Gap (IFG) between every packet on the wire. That adds 20 bytes (160 bits) of Layer-1 overhead per packet, totaling 84 bytes (672 bits). Dividing 10,000,000,000 bps by 672 bits/packet yields exactly 14,880,952 packets per second (14.88 Mpps).

Why do small-packet TCP SYN floods crash firewalls even when bandwidth is under 20%?+

Routers, load balancers, and stateful firewalls must inspect headers, perform routing lookups, and allocate conntrack state-table entries for every individual packet. A 2 Mpps flood of 64-byte SYN packets consumes only ~1.34 Gbps of wire bandwidth, but easily exhausts CPU interrupts and state tables on hardware rated for high throughput with 1500-byte packets.

How does a UDP Reflection and Amplification DDoS attack work?+

In a reflection/amplification attack, the attacker sends small UDP requests with a spoofed source IP (set to the victim's IP address) to open third-party UDP servers (such as DNS resolvers, NTP servers, or misconfigured Memcached instances). Because UDP has no three-way handshake to verify the source IP, those servers send massive multi-kilobyte responses directly to the victim, multiplying the attacker's bandwidth by 50x to 51,000x.

What is the difference between L3/L4 volumetric floods and L7 HTTP floods?+

L3/L4 attacks (ICMP floods, UDP amplification, TCP SYN floods) target network pipes and TCP/IP stack state tables measured in Gbps and Mpps. L7 attacks complete a valid TCP/TLS handshake and send legitimate-looking HTTP/HTTPS requests (measured in Requests Per Second, RPS) targeting expensive backend database queries, search endpoints, or login APIs.

How does BCP38 (RFC 2827) help defeat reflection DDoS attacks?+

BCP38 is Network Ingress Filtering implemented by ISPs at the network edge. It drops any outbound packet whose source IP address does not belong to the customer's assigned prefix, preventing botnet nodes from spoofing a victim's IP address to trigger UDP reflection.