nanog mailing list archives

Re: Dyn DDoS this AM?


From: Daniel Ankers <md1clv () md1clv com>
Date: Sat, 22 Oct 2016 17:20:38 +0100

On 22 October 2016 at 16:40, marcel.duregards--- via NANOG <nanog () nanog org>
wrote:

What about BCP38+84 on 30 tier-1 instead of asking/hoping 55k others
autonomous-system having good filters in place ?


The originating ISPs are in a far better position to check that traffic
isn't from spoofed address ranges than transit networks are.  The best
thing to do is to ask EVERY network to do what they can, not just the few
biggest ones.

Any size ISP can be hit by and hurt by DDoS attacks, so every size ISP
should be doing what they can to make sure they are not either the source
or the victim of those attacks.

Dan


Current thread: