This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

How To Block NTP-based DDoS attacks
#10
RE: How To Block NTP-based DDoS attacks
(09-15-2014, 08:21 PM)Me.B Wrote: DDOS should be mitigated mostly at routers and upstream not at servers level as even if you keep dropping packets you will be receiving so much data that your upstream will be dead.

If you have a 100 MB/S uplink and you get a 1GB/s attack wich gets common with NTP amplification you will off so quickly even if you drop ALL the packets or the attack port is closed.

If you want DDOS use an ISP that have such protection.

M B

For those of you who live in a fantasy world and have high level ISPs that will do this for you, that's great. For the rest of us in lower end colo's and with tier C ISP's who are small businesses who don't have million dollar budgets, this is not a practical solution. 

I called my colo and they did nothing. And that is the case for most everyone else who doesn't have tier A Verizon service. The reality in this world is that you have to solve your own problems because your ISP won't do it for you.

I don't care how big the attack is. They attacked me at 10GB/s and I still survived it and the firewall successfully blocked it. All the firewall has to do is immediately shut down and drop the packets to free up the circuit. Yes, you will run slower during the attack but nothing is going offline.

It is amazing that there is so much mis-information about DDOS attacks out there. THEY CAN BE STOPPED WITH THE RIGHT FIREWALLS. 
Reply
Thanks given by:


Messages In This Thread
How To Block NTP-based DDoS attacks - by MET4LG0D - 09-14-2014, 10:16 PM
RE: How To Block NTP-based DDoS attacks - by Me.B - 09-15-2014, 12:47 AM
RE: How To Block NTP-based DDoS attacks - by Me.B - 09-15-2014, 08:21 PM
RE: How To Block NTP-based DDoS attacks - by smccarthy945 - 09-16-2014, 03:08 AM
RE: How To Block NTP-based DDoS attacks - by Me.B - 09-16-2014, 03:29 AM

Forum Jump:


Users browsing this thread: 1 Guest(s)