Can multi_accept be on cause this? I have now set multi_accep to off and set up the Nginx again as a reverse proxy. The attack is not ongoing now, so can't tell immediately if that setting helps/not Posted at Nginx Forum: https://forum.nginx.org/read.php?2,282613,282646#msg-282646