nanog mailing list archives

Re: DDoS using port 0 and 53 (DNS)


From: "Dobbins, Roland" <rdobbins () arbor net>
Date: Wed, 25 Jul 2012 16:39:13 +0000


On Jul 25, 2012, at 9:52 PM, Joel Maslak wrote:

In addition to the fragments, these packets might also be non-TCP/UDP (ICMP, GRE, 6to4 and other IP-IP, etc).

NetFlow will report the correct protocol number.

-----------------------------------------------------------------------
Roland Dobbins <rdobbins () arbor net> // <http://www.arbornetworks.com>

          Luck is the residue of opportunity and design.

                       -- John Milton



Current thread: