synflood mode consequences nmap'ing when in synflood mode: all ports reported as open can't see attacker's IP in the state table it's spoofed anyway unfollowed up upon SYNs not showing up in pflow export