On Aug 8, 2010, at 5:18 AM, bas wrote:

> And then decided to remove the IP address from the server (or shut it down)


Why not S/RTBH or IDMS or even ACLs, instead of completing the DDoS for the 
attacker?  Any of those techniques wouldn't result in high CPU on your 
infrastructure.

-----------------------------------------------------------------------
Roland Dobbins <[email protected]> // <http://www.arbornetworks.com>

    Injustice is relatively easy to bear; what stings is justice.

                        -- H.L. Mencken




_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to