nanog mailing list archives

Re: syn flood attacks from NL-based netblocks


From: "Valdis Klētnieks" <valdis.kletnieks () vt edu>
Date: Mon, 19 Aug 2019 14:27:33 -0400

On Mon, 19 Aug 2019 21:18:49 +0300, T�ma Gavrichenkov said:

If you're doing load balancing for *outgoing* traffic — and in exactly the
same manner as you do with incoming — then maybe.

On the other hand, your servers should probably be doing non-loadbalanced
outbound on a different IP address than the inbound load balancer, and thus the
syn-ack should have zero trouble getting back to the box it thought the syn
came from.

Attachment: _bin
Description:


Current thread: