Now he reads the article... No, you can run BGP just on your edge, doesn't need to include provider. On Apr 26, 2016 13:41, "Satish Patel" <[email protected]> wrote:
> Roland, > > Let's say I like your S/RTBH but does it require my ISP support this? > > On Tue, Apr 26, 2016 at 1:54 PM, Roland Dobbins <[email protected]> > wrote: > > On 27 Apr 2016, at 0:50, Satish Patel wrote: > > > >> Does cisco has config like following apply ACL base on criteria > > > > > > Cisco has QoS. > > > > But you really aren't being smart about this. Why not use S/RTBH on your > > edge router to simply block the sources, since they aren't spoofed? > > > > Export NetFlow from your edge router to an open-source > collection/analysis > > system, so that you can see the sources. > > > > But you do know that most UDP reflection/amplification attacks are > > high-volume, yes? So, your transit pipe may still be filled up due to > sheer > > bps. > > > > > > ----------------------------------- > > Roland Dobbins <[email protected]> > > _______________________________________________ > > cisco-nsp mailing list [email protected] > > https://puck.nether.net/mailman/listinfo/cisco-nsp > > archive at http://puck.nether.net/pipermail/cisco-nsp/ > _______________________________________________ > cisco-nsp mailing list [email protected] > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
