The original config (and the modified one too!) uses states to keep track of open connections. The state table however, is by default limited to 10000 entries (FreeBSD 10.1 amd64), which could lead to problems during medium-/large-scale attacks, since new connections will be dropped once the table is full.
I usually use the following memory pool limits for PF:
set limit { states 100000, frags 20000, src-nodes 100000, table-entries 200000 }
Raising the table-entries limit is also a good idea if you have dynamically filled tables of "bad hosts", same goes for src-nodes.
It's also recommended to have a few whitelisted static IPs, whose traffic is passed unconditionally and stateless.
e.g.:
table <ovh> const { 213.186.33.13, 213.186.50.100 }
pass in quick on $ext_if from <ovh> to any no state