nanog mailing list archives

Re: DDoS mitigation recommendations


From: Christopher Morrow <morrowc.lists () gmail com>
Date: Thu, 28 Jan 2010 11:55:34 -0500

On Thu, Jan 28, 2010 at 10:00 AM, Jeffrey Lyon
<jeffrey.lyon () blacklotus net> wrote:
IntruGuard is highly customizable both from the GUI and CLI with the
engineer's assistance. Its the highest performance, reasonably priced box
that we've tried so far.

'highest performance' == 100mbps on a 1gbps copper interface? or
sessions setup/second? or remote-addresses tracked? or ?

-chris


Jeff

On Jan 28, 2010 7:02 AM, "Tom Sands" <tsands () rackspace com> wrote:


-----Original Message-----
From: David Freedman [mailto:david.freedman () uk clara net] Sent: Tues...
We've already done an initial trial with the Arbor device, and it does work
well.  Our biggest sticking point with it is that it lacks the granular
level of visibility and control that we've been used to and often needed to
tweak profiles.  Basically, it does what it's supposed to well, but you
really can't tell what that is, and if it's not catching all of a DDoS you
have little insight as to what's being missed or control to correct it.



Thank you,

Tom Sands
Chief Network Engineer
Rackspace

Confidentiality Notice: This e-mail message (including any attached or
embedded documents) is intend...



Current thread: