On 04/26/2016 10:54 AM, Roland Dobbins wrote:


But you really aren't being smart about this. Why not use S/RTBH on your edge router to simply block the sources, since they aren't spoofed?

Export NetFlow from your edge router to an open-source collection/analysis system, so that you can see the sources.


On that point, do you have any recommendations for such a collection/analysis system that actually works and is comprehensible?
Thanks.

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to