Re: Guarding against DoS

2004-07-02 Thread Chris G.
In our setup, our clients call us because we are their upstream. We block it at our routers, then call our providers asking them to block it at their upstream. There is no way a client can refuse traffic (at least in most setups I've seen) without it passing through their port. The only opti

Guarding against DoS

2004-07-02 Thread Micah Anderson
Lets suppose we get targeted for a DOS attack. We can pretty much assume this will eventually happen. If a colo'ed box gets hit with 20 mbps of incoming traffic, even if it ignores it all, then we might have to pay $2200 that month. That is not good! How can we keep ourselves from getting hig

Re: Guarding against DoS

2004-07-02 Thread Chris G.
In our setup, our clients call us because we are their upstream. We block it at our routers, then call our providers asking them to block it at their upstream. There is no way a client can refuse traffic (at least in most setups I've seen) without it passing through their port. The only opti

Guarding against DoS

2004-07-02 Thread Micah Anderson
Lets suppose we get targeted for a DOS attack. We can pretty much assume this will eventually happen. If a colo'ed box gets hit with 20 mbps of incoming traffic, even if it ignores it all, then we might have to pay $2200 that month. That is not good! How can we keep ourselves from getting hig