aggregation & table entries

Patrick W Gilmore patrick at ianai.net
Thu Oct 14 20:34:28 UTC 2004


On Oct 14, 2004, at 4:27 PM, Daniel Roesen wrote:

>> Yes, these restrictions are a huge pain in the rear end but a denial 
>> of
>> service without even the possibility to tell where the packets come
>> from is MUCH worse.
>
> What you actually want to know is what the ingress interfaces for the
> flows are. And if the ingress interface is not a p2p interface, from
> which peer. For both problems quite effective solutions do exist
> (ok, not really for the latter, but this is highly vendor specific).

No, what I really want to know is the source IP.


> Given that most DDoSses are mounted via huge zombie collections, there
> is not much point in knowing the real source IPs.

Didn't we cover this?

Yes, there are zombie armies launching DDoS from "real" IP addresses.  
But that does not mean there are no spoofed-source attacks any more.

-- 
TTFN,
patrick




More information about the NANOG mailing list