[182860] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: GoDaddy : DoS :: Contact

daemon@ATHENA.MIT.EDU (Roland Dobbins)
Mon Aug 3 09:26:13 2015

X-Original-To: nanog@nanog.org
From: "Roland Dobbins" <rdobbins@arbor.net>
To: nanog@nanog.org
Date: Mon, 03 Aug 2015 20:26:06 +0700
In-Reply-To: <B2808195-0458-4A4A-9D07-94B72813743F@beckman.org>
Errors-To: nanog-bounces@nanog.org


On 3 Aug 2015, at 7:56, Mel Beckman wrote:

> BGP is no help in these situations, unless you use a BGP-based DDoS 
> protection service.

Anyone can set up S/RTBH on their transit-/peering-edge routers, even if 
they aren't using BGP for routing.

Likewise flowspec, on routers which support it.

If attack volume is high, it still may flood the link, but keeping the 
traffic off one's own core and off the actual target(s) of the attack 
are still very worthwhile.

-----------------------------------
Roland Dobbins <rdobbins@arbor.net>

home help back first fref pref prev next nref lref last post