How to control external tcp connections

hi, i deploy DestinationRule to my ingressgw (HTTP2), but i found that the connection between external client and ingressgw is not limited by DestinationRule parameters, so my question is how to protect ingressgw from being attacked by external client to make a lot of tcp connections with ingressgw to consume up socket description resource