06-25-2021 06:36 AM
Dear all !
With my Cisco N9K FX switch (v9.3), I would like to make sure that if there is an IP that sends more than X Gbps to an IP on my network, drop the source IP.
It would help me to avoid some ddos attacks with ACLs. Anyone have an idea? How to do a dynamic ACL?
Are there other effective blocking methods possible?
Thanks
Axel
06-25-2021 06:57 AM
nexus control plane do this way
06-25-2021 06:58 AM
Thanks, can you know how to do that and apply to my VLAN ?
Thanks
06-25-2021 07:02 AM
Control plane policing to protect the control plane of Cisco IOS routers and switches itself against reconnaissance and denial-of-service (DoS) attacks, not for traffic "through" the device. If it's transit traffic, use QoS?
06-25-2021 07:13 AM
Hello,
I want to protect from ddos my customers. I'have 100Gbps in uplink but I want to protect some customers with only drop ip source automatically if they send more than 80 Mb/s to my customers.
06-25-2021 08:09 AM - edited 06-25-2021 08:11 AM
I was in impression you like to to protect the switch with DDoS attacks, but if you looking Data devices connected on the switch.
Most of the nexus are in DC environment, they do not directly expose to Internet - Most of the DC environment protected with FW
IDS / IPS is the best option here, rather limited on switch ( still you can have ACL
example :
https://networkbitbucket.wordpress.com/2017/06/30/qos-acls-on-the-nexus-7k-platform/
06-25-2021 08:12 AM
Hi
Yes, but actually I use N9K for my edge router because I need to augmente capacity instead filtering of my network ^^. But now, i'have the capacity, so I check if can I do anything with my nexus for that.
But yes, I understand I must use a firewall
But I'm afraid that the firewall's CPU will overload in the event of an attack.
Do you have an idea of a model that is inexpensive and that would do the job?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide