[182510] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24

daemon@ATHENA.MIT.EDU (Drew Weaver)
Mon Jul 20 11:56:43 2015

X-Original-To: nanog@nanog.org
From: Drew Weaver <drew.weaver@thenap.com>
To: "nanog@nanog.org" <nanog@nanog.org>
Date: Mon, 20 Jul 2015 15:57:14 +0000
Errors-To: nanog-bounces@nanog.org

Has anyone else seen a massive amount of illegitimate UDP 1720 traffic comi=
ng from China being sent towards IP addresses which provide VoIP services?

I'm talking in the 20-30Gbps range?

The first incident was yesterday at around 13:00 EST, the second incident w=
as today at 09:00 EST.

I'm assuming this is just another DDoS like all others, but I would be inte=
rested to hear if I am not the only one seeing this.

On list or off-list is fine.

Thanks,
-Drew


home help back first fref pref prev next nref lref last post