3 ms·
The problem is when you are not able to "eat" the whole DDoS without filling your link/links to your ISP/s. Then it does not matter how god you are at dropping
by ventris 7y ago
The problem is when you are not able to "eat" the whole DDoS without filling your link/links to your ISP/s. Then it does not matter how god you are at dropping at the edge of your datacenter, or what solution you are using.
- zzzcpan 7y agoWhile you can't block volumetric attacks on the server, this is something a hosting provider can help you with. Some have automatic volumetric DDoS detection and protection, like OVH, and some might be able to ask upstreams, internet exchanges to completely block all UDP traffic for certain subnets or even setup completely custom firewall rules, effectively preventing volumetric attacks from filling links within their global networks and of course from reaching your server. But you are still left with non-volumetric attacks that you need to use a firewall for, maybe even with some scripting to gather statistics and whitelist known good IPs and IP subnets in case of an attack. Maybe with mitigations on, for example, frontend web servers to avoid overloading much slower backends, databases, etc.
- cpncrunch 7y agoAlso, even if the attack is small enough to block using iptables, you still have to have someone on call 24x7, and then spend time to figure out which ports/ips need blocked. If you use OVH or similar provider that has built-in DDoS protection, the mitigation will all happen automatically.
- NightlyDev 7y agoThat's of course true, but bandwidth is usually not the problem with eg. SYN attacks. Iptables is there to ensure you can handle as many packets as possible per second, not bandwidth.