Re: UDP Flood handling
"Juan Carlos Davila" <[email protected]> Tue, 4 Nov 2003 17:18:27 -0600
| Newsgroups | gmane.comp.security.incident-handling |
|---|---|
| Message-ID | <007401c3a329$f42f40f0$0f010196@laplaboratorio> |
www.packeteer.com Soluciotions of bandwidth administrator. Hemac Teleinformatica Ing. Juan Carlos Davila Ortiz Ingenieria Chapultepec # 710 Col. Moderna 3616-3824 Guadalajara, Jal. [email protected] ----- Original Message ----- From: "Mauro Marazzi" <[email protected]> To: <[email protected]> Sent: Tuesday, November 04, 2003 3:40 AM Subject: UDP Flood handling > > > Hi again. I've tried and tested UDP Flood 2 (Foundstone). Is there any way to block an udp flood directed to a Red Hat DNS Server? I could do it on my Cisco router, but I have already implemented some rate limits and I could not add any other line. If I will drop the packet directly on the DNS server, will my bandwidth in any case used on my POS interface, so reducing the available overall bandwidth? And last, why any UDP flood I have received has taken right of way my legal traffic: an example; I have 75 Mbps, and the legitimate traffic is of 70 Mbps. When an UDP flood of 20 Mbps(target 53) arrive, it takes 20 Mbps and not the remaining 5 Mbps. So my legitimate traffic will be decreased of 15 Mbps. > > Any reply will be appreciated. > > Regards, > > Mauro Marazzi > Responsabile Divisione Wan, System & IT Security > Netsystem.com S.p.A.