r00igev@@r
Honorary Master
- Joined
- Dec 14, 2009
- Messages
- 15,643
- Reaction score
- 14,158
- Location
- Draadloos Bantha poo doo in 4ways
DD has Arbor. Have they brought that online on your IPs or path IPs???
South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.

They are utilizing it along with netscout - how ever we are hitting limits.DD has Arbor. Have they brought that online on your IPs or path IPs???
Lots of cheap IP camera's are involved - check previous post for number of unique IP'sIs this the common old amplification attack using fragmented packets? Also is it incoming on International?
Typically its a DDOS vendor who phones up to scrub it for you.![]()
Is this the common old amplification attack using fragmented packets? Also is it incoming on International?
Typically its a DDOS vendor who phones up to scrub it for you.![]()
Probably on 10gbs? Would need to go to an international scrubbing centre like Voxility or black hole on international edge.They are utilizing it along with netscout - how ever we are hitting limits.
Well at least its not the Mikrotiks this time.Lots of cheap IP camera's are involved - check previous post for number of unique IP's
Don't know as I've never tested it on extremely high congestion. But fq_codel and bbr will help in congested situations. The linux config is two lines. Should default that on all servers.Quick question @r00igev@@r - does using the BBR algorithm on a server typically help with a scenario like this when the network its on is being DDoSd?
Firewall products aren't capable of dealing with amplification attacks. The methods are upstream black holing or using a scrubbing centre. A scrubbing centre is basically a stack of a hundreds of servers that strips the amplification traffic in layers as a single layer cannot handle the load. I think its about 100k IPs per layer so 1M requires 10 layers.****. That's a massive attack. Isn't there a firewall product out there to stop these attacks? Or is it just too expensive for you?
You can phone me. Happy to chat.Thanks for all the responses, suggestions and support within this thread.
Fair enough. As a follow-up question: can a small to midsized ISP afford a scrubbing centre or blackholing solution large enough to hold off a 30gbps attack?Firewall products aren't capable of dealing with amplification attacks. The methods are upstream black holing or using a scrubbing centre. A scrubbing centre is basically a stack of a hundreds of servers that strips the amplification traffic in layers as a single layer cannot handle the load. I think its about 100k IPs per layer so 1M requires 10 layers.
No to the scrubbing centre as that is expensive but the blackholing is handled by the upstream Tier 1. Some have APIs for it such as Cogent. You can program that using https://fastnetmon.com/Fair enough. As a follow-up question: can a small to midsized ISP afford a scrubbing centre or blackholing solution large enough to hold off a 30gbps attack?
Cloudflare had a free one for a single server. Basically, point your DNS authoritative to them and have them scrub it.Azure has "special" DDOS protection but look at the price
Eish wena !!!!!!!!!!!!!!!
View attachment 1387344
3kUSD per month? That is not expensive at all, especially if you consider the revenue losses incurred per minute of downtime as a result of a DDoS attack.Azure has "special" DDOS protection but look at the price
Eish wena !!!!!!!!!!!!!!!
View attachment 1387344