20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours

Curtis Maurand cmaurand at xyonet.com
Tue Jul 21 12:09:56 UTC 2015


DNS is still largely UDP.

--Curtis

On 7/20/2015 5:40 PM, Ca By wrote:
> Folks, it may be time to  take the next step and admit that UDP is too
> broken to support
>
> https://tools.ietf.org/html/draft-byrne-opsec-udp-advisory-00
>
> Your comments have been requested
>
>
>
> On Mon, Jul 20, 2015 at 8:57 AM, Drew Weaver <drew.weaver at thenap.com> wrote:
>
>> Has anyone else seen a massive amount of illegitimate UDP 1720 traffic
>> coming from China being sent towards IP addresses which provide VoIP
>> services?
>>
>> I'm talking in the 20-30Gbps range?
>>
>> The first incident was yesterday at around 13:00 EST, the second incident
>> was today at 09:00 EST.
>>
>> I'm assuming this is just another DDoS like all others, but I would be
>> interested to hear if I am not the only one seeing this.
>>
>> On list or off-list is fine.
>>
>> Thanks,
>> -Drew
>>
>>

-- 
Best Regards
Curtis Maurand
Principal
Xyonet Web Hosting
mailto:cmaurand at xyonet.com
http://www.xyonet.com




More information about the NANOG mailing list