[177257] in North American Network Operators' Group
Re: DDOS solution recommendation
daemon@ATHENA.MIT.EDU (Roland Dobbins)
Sun Jan 11 08:53:34 2015
X-Original-To: nanog@nanog.org
From: "Roland Dobbins" <rdobbins@arbor.net>
To: nanog@nanog.org
Date: Sun, 11 Jan 2015 20:51:59 +0700
In-Reply-To: <22194530.1736.1420983994911.JavaMail.mhammett@ThunderFuck>
Errors-To: nanog-bounces@nanog.org
On 11 Jan 2015, at 20:46, Mike Hammett wrote:
> Enough people blackhole the attacking IPs, those IPs are eventually
> going to have a very limited view of the Internet.
TCAMs have limits.
Not all networks practice anti-spoofing.
Not all networks have any visibility whatsoever into their network
traffic.
Not all networks have security teams.
Again, it would probably be advisable to do some reading before you
start telling those of us who've been working on this set of problems
for the last couple of decades that it's simple, and that we don't know
what we're doing.
-----------------------------------
Roland Dobbins <rdobbins@arbor.net>