DDoS mitigation recommendations

Tony Varriale tvarriale at comcast.net
Fri Jan 29 04:59:22 UTC 2010

----- Original Message ----- 
From: "Tom Sands" <tsands at rackspace.com>
Cc: <nanog at nanog.org>
Sent: Thursday, January 28, 2010 6:01 AM
Subject: Re: DDoS mitigation recommendations

>> -----Original Message-----
>> From: David Freedman [mailto:david.freedman at uk.clara.net] 
>> Sent: Tuesday, January 26, 2010 8:17 AM
>> To: nanog at nanog.org
>> Subject: Re: DDoS mitigation recommendations
>>> Arbor stuff comes to mind and works very well in our experiences....
>> Arbor++
> We've already done an initial trial with the Arbor device, and it does 
> work well.  Our biggest sticking point with it is that it lacks the 
> granular level of visibility and control that we've been used to and 
> often needed to tweak profiles.  Basically, it does what it's supposed 
> to well, but you really can't tell what that is, and if it's not 
> catching all of a DDoS you have little insight as to what's being missed 
> or control to correct it.
> Thank you,
> Tom Sands
> Chief Network Engineer
> Rackspace

Out of curiousity, what's your baseline or "that we've been used"?


More information about the NANOG mailing list