4 ms·
Yeah, our DNS provider Zerigo had a nasty DDOS attack over Sunday that many sites got caught up in, including us. As you can imagine, mitigating DDOS on a name
by dotBen 14y ago
Yeah, our DNS provider Zerigo had a nasty DDOS attack over Sunday that many sites got caught up in, including us.
As you can imagine, mitigating DDOS on a nameserver is tricky due to the nature of the requests coming in - harder to Deep Packet Inspect and scrub, or easily identify patterns of bad traffic access to zero-route.
- neilwillgettoit 14y ago1. third party zone transfers 2. Anycast DNS 3. Use more than one provider. 4. warm spares that are not in delegation until needed.
- dotBen 14y agoYup, we're switching to multiple providers. The fact that there were already multiple geographically redundant IPs should have averted most issues, but someone made a highly-coordinated attack on the provider at all their IPs. We learn and move on. I wonder how many other startups are going as far as using DNS from multiple providers? I still see many startups using Go Daddy for their DNS... :/