[160102] in North American Network Operators' Group
box against dos/ddos
daemon@ATHENA.MIT.EDU (Piotr)
Thu Jan 31 09:38:16 2013
Date: Thu, 31 Jan 2013 15:37:41 +0100
From: Piotr <piotr.1234@interia.pl>
To: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
Hi,
I looking some box (vendor, model), which i can put out of the
main/product network, which can analyze packets netflow,sflow,syslog
from bgp router(s) and after discover some anomaly it can do some
action, for example:
- Box have bgp session with bgp router and advertise attacked ip prefix
with some community. Bgp router set next-hop for this prefix to /dev/null
Normal traffic via bgp router is about 1G/s in and 10G/s out
What is worth of looking and what you suggest ?
thanks for help,
Piotr