nanog mailing list archives
Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours
From: Jared Mauch <jared () puck Nether net>
Date: Tue, 21 Jul 2015 08:43:08 -0400
On Tue, Jul 21, 2015 at 08:09:56AM -0400, Curtis Maurand wrote:
DNS is still largely UDP.
Water is also still wet :) - but you may not be doing 10% of your links as UDP/53. DNS can also use TCP as well, including sending more than one query in a pipelined fashion. The challenge that Cameron is trying to document here is when seeing large volumes of UDP it becomes necessary to do something to keep the network up. This response is frustrating for those of us who prefer to have a unfiltered e2e network but maintaining the network as up in the face of these adverse conditions is important. - Jared
--Curtis On 7/20/2015 5:40 PM, Ca By wrote:Folks, it may be time to take the next step and admit that UDP is too broken to support https://tools.ietf.org/html/draft-byrne-opsec-udp-advisory-00 Your comments have been requested On Mon, Jul 20, 2015 at 8:57 AM, Drew Weaver <drew.weaver () thenap com> wrote:Has anyone else seen a massive amount of illegitimate UDP 1720 traffic coming from China being sent towards IP addresses which provide VoIP services? I'm talking in the 20-30Gbps range? The first incident was yesterday at around 13:00 EST, the second incident was today at 09:00 EST. I'm assuming this is just another DDoS like all others, but I would be interested to hear if I am not the only one seeing this. On list or off-list is fine. Thanks, -Drew-- Best Regards Curtis Maurand Principal Xyonet Web Hosting mailto:cmaurand () xyonet com http://www.xyonet.com
-- Jared Mauch | pgp key available via finger from jared () puck nether net clue++; | http://puck.nether.net/~jared/ My statements are only mine.
Current thread:
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours, (continued)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Christopher Morrow (Jul 20)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours ML (Jul 20)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Colin Johnston (Jul 20)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Valdis . Kletnieks (Jul 20)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours James Milko (Jul 20)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Ca By (Jul 20)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Curtis Maurand (Jul 21)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Jared Mauch (Jul 21)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Rafael Possamai (Jul 21)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Pavel Odintsov (Jul 21)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Rafael Possamai (Jul 21)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Pavel Odintsov (Jul 21)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Mike Hammett (Jul 21)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Rafael Possamai (Jul 21)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Jared Mauch (Jul 21)
- Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Curtis Maurand (Jul 21)
- RE: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours Tony Wicks (Jul 20)