automatic rtbh trigger using flow data

Baldur Norddahl baldur.norddahl at gmail.com
Sun Sep 2 00:18:08 UTC 2018


fre. 31. aug. 2018 17.16 skrev Hugo Slabbert <hugo at slabnet.com>:

>
>
> I would love an upstream that accepts flowspec routes to get granular
> about
> drops and to basically push "stateless ACLs" upstream.
>
> _keeps dreaming_
>
>
>
We just need a signal to drop UDP for a prefix. The same as RTBH but only
for UDP. This would prevent all volumetric attacks without the end user
being cut off completely.

Besides from some games, VPN and VoIP, they would have an almost completely
normal internet experience. DNS would go through the ISP servers and only
be affected if the user is using a third party service.

Regards

Baldur
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.nanog.org/pipermail/nanog/attachments/20180902/7257a7ca/attachment.html>


More information about the NANOG mailing list