UDP Flood handling

Mauro Marazzi <[email protected]> 4 Nov 2003 09:40:35 -0000
Newsgroups gmane.comp.security.incident-handling
Message-ID <[email protected]>

Hi again. I've tried and tested UDP Flood 2 (Foundstone). Is there any wa=
y to block an udp flood directed to a Red Hat DNS Server? I could do it o=
n my Cisco router, but I have already implemented some rate limits and I =
could not add any other line. If I will drop the packet directly on the D=
NS server, will my bandwidth in any case used on my POS interface, so red=
ucing the available overall bandwidth? And last, why any UDP flood I have=
 received has taken right of way my legal traffic: an example; I have 75 =
Mbps, and the legitimate traffic is of 70 Mbps. When an UDP flood of 20 M=
bps(target 53) arrive, it takes 20 Mbps and not the remaining 5 Mbps. So =
my legitimate traffic will be decreased of 15 Mbps.=0D
 =0D
Any reply will be appreciated.=0D
 =0D
Regards,=0D
 =0D
Mauro Marazzi=0D
Responsabile Divisione Wan, System & IT Security=0D
Netsystem.com S.p.A.