nanog mailing list archives
Re: I don't need no stinking firewall!
From: "Dobbins, Roland" <rdobbins () arbor net>
Date: Mon, 11 Jan 2010 06:15:35 +0000
On Jan 11, 2010, at 12:56 PM, George Bonser wrote:
One would probably have a load balancer of some sort in front of those machines. That is the device that would be fielding any DoS.
Yes, and as you've noted previously, it should be protected via stateless ACLs in hardware capable of handling mpps, S/RTBH, flow-spec, IDMS, whatever. And of course the load-balancer should also be fronted by a reverse-proxy cache farm, if the servers in question are Web servers.
I have a feeling you are talking about relatively small amounts of traffic.
I believe that these comments were more along the lines of 'servers can better handle this that stateful firewalls', not ruling out the use of load-balancers, reverse-proxy caches, etc. as appropriate. ----------------------------------------------------------------------- Roland Dobbins <rdobbins () arbor net> // <http://www.arbornetworks.com> Injustice is relatively easy to bear; what stings is justice. -- H.L. Mencken
Current thread:
- Re: I don't need no stinking firewall!, (continued)
- Re: I don't need no stinking firewall! harbor235 (Jan 09)
- Re: I don't need no stinking firewall! Dobbins, Roland (Jan 09)
- Re: I don't need no stinking firewall! harbor235 (Jan 09)
- Re: I don't need no stinking firewall! Dobbins, Roland (Jan 09)
- Re: I don't need no stinking firewall! Dobbins, Roland (Jan 09)
- Re: I don't need no stinking firewall! Michael K. Smith (Jan 10)
- RE: I don't need no stinking firewall! George Bonser (Jan 10)
- Re: I don't need no stinking firewall! Randy Bush (Jan 10)
- Re: I don't need no stinking firewall! Brian Keefer (Jan 10)
- RE: I don't need no stinking firewall! George Bonser (Jan 10)
- Re: I don't need no stinking firewall! Dobbins, Roland (Jan 10)
- RE: I don't need no stinking firewall! George Bonser (Jan 10)
- Re: I don't need no stinking firewall! Warren Kumari (Jan 13)
- Re: I don't need no stinking firewall! Dobbins, Roland (Jan 13)
- Re: I don't need no stinking firewall! Bill Stewart (Jan 14)
- Re: I don't need no stinking firewall! Joe Maimon (Jan 14)
- Re: I don't need no stinking firewall! Valdis . Kletnieks (Jan 08)
- Re: I don't need no stinking firewall! Joe Greco (Jan 08)
- Re: I don't need no stinking firewall! James Hess (Jan 10)
- Re: I don't need no stinking firewall! Dobbins, Roland (Jan 10)
- Re: I don't need no stinking firewall! William Herrin (Jan 10)