nanog mailing list archives

Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours


From: Colin Johnston <colinj () gt86car org uk>
Date: Mon, 20 Jul 2015 19:04:27 +0100

route block china range whole of and/or firewall block china range whole of

then contact gov and tell them trade talks need to involve china engaging with incident teams and abuse teams

colin
Sent from my iPhone

On 20 Jul 2015, at 16:57, Drew Weaver <drew.weaver () thenap com> wrote:

Has anyone else seen a massive amount of illegitimate UDP 1720 traffic coming from China being sent towards IP 
addresses which provide VoIP services?

I'm talking in the 20-30Gbps range?

The first incident was yesterday at around 13:00 EST, the second incident was today at 09:00 EST.

I'm assuming this is just another DDoS like all others, but I would be interested to hear if I am not the only one 
seeing this.

On list or off-list is fine.

Thanks,
-Drew



Current thread: