06-28-2017 08:54 PM - edited 03-05-2019 08:46 AM
Hello all,
I'm looking for some DDOS mitigation help. I've setup some blackhole services with my BGP peers and i'd like to see if anyone has a way to proactively null route possible incoming and outgoing ddos attacks. Aside from having a system like nagios alerting me my port is dead or worse it cannot reach the switch due to ping timeout. What can i setup to automate null routing of an ip traversing DDOS like traffic.
Any links or ideas would be great.
Thanks in advance for all your answers!
-Tom
06-29-2017 06:41 PM
You will need a commercial product to do that. You would also have to be very brave to automate something like that.
As long as you have some monitoring to show top hosts, top flows and top ports you should be able to block anything nasty quickly - that's assuming it doesn't match valid traffic that you can not block.
06-29-2017 08:39 PM
Can you name some products to shove me in the right direction? I don't even know where to start
07-02-2017 11:43 AM
Arbor Networks is pretty popular.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide