nanog mailing list archives

Re: 20-30Gbps UDP 1720 traffic appearing to originate from CN in last 24 hours


From: Ca By <cb.list6 () gmail com>
Date: Mon, 20 Jul 2015 14:40:27 -0700

Folks, it may be time to  take the next step and admit that UDP is too
broken to support

https://tools.ietf.org/html/draft-byrne-opsec-udp-advisory-00

Your comments have been requested



On Mon, Jul 20, 2015 at 8:57 AM, Drew Weaver <drew.weaver () thenap com> wrote:

Has anyone else seen a massive amount of illegitimate UDP 1720 traffic
coming from China being sent towards IP addresses which provide VoIP
services?

I'm talking in the 20-30Gbps range?

The first incident was yesterday at around 13:00 EST, the second incident
was today at 09:00 EST.

I'm assuming this is just another DDoS like all others, but I would be
interested to hear if I am not the only one seeing this.

On list or off-list is fine.

Thanks,
-Drew




Current thread: