20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours

Drew Weaver drew.weaver at thenap.com
Mon Jul 20 15:57:14 UTC 2015


Has anyone else seen a massive amount of illegitimate UDP 1720 traffic coming from China being sent towards IP addresses which provide VoIP services?

I'm talking in the 20-30Gbps range?

The first incident was yesterday at around 13:00 EST, the second incident was today at 09:00 EST.

I'm assuming this is just another DDoS like all others, but I would be interested to hear if I am not the only one seeing this.

On list or off-list is fine.

Thanks,
-Drew




More information about the NANOG mailing list