nanog mailing list archives
Re: Filter NTP traffic by packet size?
From: Peter Phaal <peter.phaal () gmail com>
Date: Sat, 22 Feb 2014 19:22:57 -0800
Brocade demonstrated how peering exchanges can selectively filter large NTP reflection flows using the sFlow monitoring and hybrid port OpenFlow capabilities of their MLXe switches at last week's Network Field Day event. http://blog.sflow.com/2014/02/nfd7-real-time-sdn-and-nfv-analytics_1986.html On Sat, Feb 22, 2014 at 4:43 PM, Chris Laffin <claffin () peer1 com> wrote:
Has anyone talked about policing ntp everywhere. Normal traffic levels are extremely low but the ddos traffic is very high. It would be really cool if peering exchanges could police ntp on their connected members.On Feb 22, 2014, at 8:05, "Paul Ferguson" <fergdawgster () mykolab com> wrote: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256On 2/22/2014 7:06 AM, Nick Hilliard wrote:On 22/02/2014 09:07, Cb B wrote: Summary IETF response: The problem i described is already solved by bcp38, nothing to see here, carry on with UDPudp is here to stay. Denying this is no more useful than trying to push the tide back with a teaspoon.Yes, udp is here to stay, and I quote Randy Bush on this, "I encourage my competitors to block udp." :-p - - ferg - -- Paul Ferguson VP Threat Intelligence, IID PGP Public Key ID: 0x54DC85B2 -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.22 (MingW32) Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/ iF4EAREIAAYFAlMIynoACgkQKJasdVTchbJsqQD/ZVz5vYaIAEv/z2kbU6kEM+KS OQx2XcSkU7r02wNDytoBANVkgZQalF40vhQED+6KyKv7xL1VfxQg1W8T4drh+6/M =FTxg -----END PGP SIGNATURE-----
Current thread:
- Re: Filter NTP traffic by packet size?, (continued)
- Re: Filter NTP traffic by packet size? Cb B (Feb 21)
- Re: Filter NTP traffic by packet size? Seth Mattinen (Feb 21)
- Re: Filter NTP traffic by packet size? Saku Ytti (Feb 22)
- Re: Filter NTP traffic by packet size? Carsten Bormann (Feb 22)
- Re: Filter NTP traffic by packet size? Cb B (Feb 22)
- Re: Filter NTP traffic by packet size? Carsten Bormann (Feb 22)
- Re: Filter NTP traffic by packet size? Randy Bush (Feb 22)
- Re: Filter NTP traffic by packet size? Nick Hilliard (Feb 22)
- Re: Filter NTP traffic by packet size? Paul Ferguson (Feb 22)
- Re: Filter NTP traffic by packet size? Chris Laffin (Feb 22)
- Re: Filter NTP traffic by packet size? Peter Phaal (Feb 22)
- Re: Filter NTP traffic by packet size? Chris Laffin (Feb 23)
- Re: Filter NTP traffic by packet size? Mikael Abrahamsson (Feb 23)
- Re: Filter NTP traffic by packet size? Peter Phaal (Feb 23)
- Re: Filter NTP traffic by packet size? sthaug (Feb 23)
- Re: Filter NTP traffic by packet size? Lukasz Bromirski (Feb 23)
- Re: Filter NTP traffic by packet size? Mikael Abrahamsson (Feb 23)
- Re: Filter NTP traffic by packet size? George William Herbert (Feb 23)
- Re: Filter NTP traffic by packet size? Royce Williams (Feb 23)
- Re: Filter NTP traffic by packet size? Royce Williams (Feb 23)
- Re: Filter NTP traffic by packet size? joel jaeggli (Feb 23)