[191637] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Krebs on Security booted off Akamai network after DDoS attack

daemon@ATHENA.MIT.EDU (Jon Lewis)
Fri Sep 23 21:25:11 2016

X-Original-To: nanog@nanog.org
Date: Fri, 23 Sep 2016 21:24:58 -0400 (EDT)
From: Jon Lewis <jlewis@lewis.org>
To: "Patrick W. Gilmore" <patrick@ianai.net>
In-Reply-To: <C3E81DD5-E2A8-428B-B90B-92E18CD9119F@ianai.net>
Cc: NANOG list <nanog@nanog.org>
Errors-To: nanog-bounces@nanog.org

On Fri, 23 Sep 2016, Patrick W. Gilmore wrote:

> Is CloudFlare able to filter Layer 7 these days? I was under the 
> impression CloudFlare was not able to do that.
>
> There have been a lot of rumors about this attack. Some say reflection, 
> others say Layer 7, others say .. other stuff. If it is Layer 7, how are 
> you going to ˙˙step in front of the cannon˙˙? Would you just pass 
> through all the traffic?

Anycast + load balancers + high powered varnish?

----------------------------------------------------------------------
  Jon Lewis, MCP :)           |  I route
                              |  therefore you are
_________ http://www.lewis.org/~jlewis/pgp for PGP public key_________

home help back first fref pref prev next nref lref last post