Look, if the packets are reaching your firewall there is nothing else to do but drop them if you don't want to let them trough. Stop thinking that there is some magical "DDOS protection" that can be implemented with a firewall, such thing does not exist.