nanog mailing list archives

Re: Growing DoS attacks


From: Joe Abley <jabley () automagic org>
Date: Thu, 17 Jan 2002 09:22:11 -0500


On Thu, Jan 17, 2002 at 10:05:45AM +0100, Vincent Gillet wrote:

jared () puck Nether net disait :

    Something that people may want to consider doing is
that assuming you are using hardware/software that can support
rate-limit of specific packet types/rates, you could
generate some rate-limits to limit specific types of traffic
to various ranges.

rate-limite and/or traffic filtering may be available on some
box (GSR) but cannot run concurently with other feature (NetFlow).

I seem to have just found out that ACLs and sampled NetFlow can
both be configured concurrently on routers running IOS >= 12.0(18)S.
This is in theory, not something I have tried (yet), and may depend
on the specific LCs you have in your router.

I don't know if/where the feature has been implemented on other
release trains.


Joe


Current thread: