Hi, On Tue, Jul 05, 2016 at 09:26:39PM +0000, Mack McBride wrote: > For an IX, you might be better off with something like a white box switch > running custom code.
Well, I'm not the IX operator, I'm just a participant - and it's tremendously
helpful to know for sure *who* is sending you that extra 10G traffic that
is filling your link with spoofed-source traffic -> read: some sort of MAC
referencing (MAC acct or netflow-with-MAC) is needed.
People have suggested using passive fiber TAPs and offload MAC acct to
a PC, but that's totally non-scalable when you go to multi-10G connections...
(Other vendors do not particularily excel in this space either)
gert
--
USENET is *not* the non-clickable part of WWW!
//www.muc.de/~gert/
Gert Doering - Munich, Germany [email protected]
fax: +49-89-35655025 [email protected]
signature.asc
Description: PGP signature
_______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
