Please use syslog to log all event logs, then the Firewall log may show which kind of ddos attack it is.
I think maybe the issue is caused by syn flood or udp flood, the default threshold value is too low.
Syn Flood – Threshold 50, Timeout 10.
UDP Flood – Threshold 150, Timeout 10.
Increase the threshold:
Syn Flood – Threshold 250, Timeout 10.
UDP Flood – Threshold 500, Timeout 10.