funsec mailing list archives

Re: UltraDNS: Internet Security Shield?


From: Paul Vixie <paul () vix com>
Date: Thu, 20 Oct 2005 03:03:55 +0000

# > Reading this as a DNS guy, I understood it to mean that the DNS servers 
# > will actually somehow differentiate the DNS queries coming from the ...
# 
# How are they going to differentiate between the attacking machine and a non
# attacking machine? I would like to know this - and I guess most of the
# people On this list.

ultra installs anycast mirrors inside the walls of the participating isp's.
those isp's do not advertise routes to these outside their net, and so any
traffic, including attack traffic, reaching such servers has to originate
within the participating isp's.  nonparticipating isp's use normal servers
that are reachable by the global internet.

i thought their web page was pretty clear on this.
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: