On 3 Aug 2015, at 7:56, Mel Beckman wrote:
BGP is no help in these situations, unless you use a BGP-based DDoS
protection service.
Anyone can set up S/RTBH on their transit-/peering-edge routers, even if
they aren't using BGP for routing.
Likewise flowspec, on routers which support it.
If attack volume is high, it still may flood the link, but keeping the
traffic off one's own core and off the actual target(s) of the attack
are still very worthwhile.
-----------------------------------
Roland Dobbins <rdobb...@arbor.net>