Please use syslog to log all event logs, then the Firewall log may show which kind of ddos attack it is.

I think maybe the issue is caused by syn flood or udp flood, the default threshold value is too low.

Default:

Syn Flood – Threshold   50, Timeout 10.
UDP Flood – Threshold 150, Timeout 10.

Increase the threshold:

Syn Flood – Threshold  250, Timeout 10.
UDP Flood – Threshold  500, Timeout 10.