ddos attack blog
Hal Murray
hmurray at megapathdsl.net
Fri Feb 14 23:00:34 UTC 2014
> I was being a bit extreme, I don't expect UDP to be blocked and there are
> valid uses for NTP and it needs to pass. Can you imagine the trading
> servers not having access to NTP?
Sure.
They could setup internal NTP servers listening to GPS. Would it be as good
overall as using external servers? Probably not, but it might be good
enough. I doubt if it would be very high on any trading floors list of nasty
problems.
They could arrange to poke holes through the generic UDP block - whitelist
the few known cases where UDP traffic is expected. Would it be a pain to
administer? Probably, but I'll bet it could be made to work.
--
These are my opinions. I hate spam.
More information about the NANOG
mailing list