Re: UDP Flood handling

"Juan Carlos Davila" <[email protected]> Tue, 4 Nov 2003 17:18:27 -0600
Newsgroups gmane.comp.security.incident-handling
Message-ID <007401c3a329$f42f40f0$0f010196@laplaboratorio>
www.packeteer.com

Soluciotions of bandwidth administrator.

 Hemac Teleinformatica
 Ing. Juan Carlos Davila Ortiz
 Ingenieria
 Chapultepec # 710   Col. Moderna
 3616-3824 Guadalajara, Jal.
 [email protected]
----- Original Message -----
From: "Mauro Marazzi" <[email protected]>
To: <[email protected]>
Sent: Tuesday, November 04, 2003 3:40 AM
Subject: UDP Flood handling


>
>
> Hi again. I've tried and tested UDP Flood 2 (Foundstone). Is there any way
to block an udp flood directed to a Red Hat DNS Server? I could do it on my
Cisco router, but I have already implemented some rate limits and I could
not add any other line. If I will drop the packet directly on the DNS
server, will my bandwidth in any case used on my POS interface, so reducing
the available overall bandwidth? And last, why any UDP flood I have received
has taken right of way my legal traffic: an example; I have 75 Mbps, and the
legitimate traffic is of 70 Mbps. When an UDP flood of 20 Mbps(target 53)
arrive, it takes 20 Mbps and not the remaining 5 Mbps. So my legitimate
traffic will be decreased of 15 Mbps.
>
> Any reply will be appreciated.
>
> Regards,
>
> Mauro Marazzi
> Responsabile Divisione Wan, System & IT Security
> Netsystem.com S.p.A.