5 ms·
We're getting about 500k packets per second, 500mbps to 1.5gbps peak, it's a synflood from a botnet. Typically we can IP hop and null-route the old IP's. That u
by rantfoil 16y ago
We're getting about 500k packets per second, 500mbps to 1.5gbps peak, it's a synflood from a botnet. Typically we can IP hop and null-route the old IP's. That usually buys us about a day until the botnet phones home to get the new IP's, at which point we just hop again. Since our DNS TTL is only 5 minutes at most we are down 5 minutes.
TODAY, the attackers hopped IP's to our new IP immediately. So they appear to be learning. But then again, so are we.
Gigenet's anti-DDoS service has helped us a ton here and is now serving as our front door IP to block the synflood. They've been really responsive.
- nroach 16y agoAny suggestions for customers with DNS names pointing to posterous blogs? Are we going to need to follow you on each hop?
- weaksauce 16y agoDo all the caching name servers respect the TTL though?
- rantfoil 16y agoThey better. So far so good.
- wwortiz 16y agoI really wish setting DNS TTL's to 5 minutes meant that browsers and everything else (OS caching) would respect that but sadly in my experience it doesn't. Surprising that it works so well for you.
- axod 16y agoGigenet's service looks interesting. They don't provide pricing though. I'm guessing it's not cheap? Is it based on the bandwidth they'd have to use?
- avar 16y agoRelying on a DNS TTL of 5 minutes doesn't work everywhere. Some ISPs will forcefully reset any TTL below 24 hours to 24h.
- thaumaturgy 16y agoAT&T/sbcglobal being one.
- sabat 16y agoAbsolutely true, and completely ridiculous. What, DNS bandwidth is too high? Please.
- avar 16y agoWell, not following the RFCs is bad, but I can see why they do it. Most people using low TTLs probably don't know what they're doing, and if you're a big ISP having to constantly make recursive queries hurts page load times for your customers, who'll blame you.
- deleted 16y ago[deleted]