UDP Flood handling
Mauro Marazzi <[email protected]> 4 Nov 2003 09:40:35 -0000
| Newsgroups | gmane.comp.security.incident-handling |
|---|---|
| Message-ID | <[email protected]> |
Hi again. I've tried and tested UDP Flood 2 (Foundstone). Is there any wa= y to block an udp flood directed to a Red Hat DNS Server? I could do it o= n my Cisco router, but I have already implemented some rate limits and I = could not add any other line. If I will drop the packet directly on the D= NS server, will my bandwidth in any case used on my POS interface, so red= ucing the available overall bandwidth? And last, why any UDP flood I have= received has taken right of way my legal traffic: an example; I have 75 = Mbps, and the legitimate traffic is of 70 Mbps. When an UDP flood of 20 M= bps(target 53) arrive, it takes 20 Mbps and not the remaining 5 Mbps. So = my legitimate traffic will be decreased of 15 Mbps.=0D =0D Any reply will be appreciated.=0D =0D Regards,=0D =0D Mauro Marazzi=0D Responsabile Divisione Wan, System & IT Security=0D Netsystem.com S.p.A.