3 ms·
Most volumetric attacks are UDP reflection based, and relatively simple to filter out at the network level using ACL's. When using decent network gear, these ca
by hhw 8y ago
Most volumetric attacks are UDP reflection based, and relatively simple to filter out at the network level using ACL's. When using decent network gear, these can be filtered at line rate using ASICs. These comprise the vast majority of real-world DDoS attacks.
Having the ability to protect against more focused attacks with HAProxy could be very useful in those few instances where volumetric attacks are not being used.