Quote:
Originally Posted by PowerChaos
they only say that they block 10Gbit attacks but thats it ... not what firewall they use or other detais that i wanted to know (sad , would love to know what firewall they use xD )
i cant say mutch about them and i also see no reason for me personal to try them out xD
Greets From PowerChaos
|
to successfully re route a true 10gb/s ddos attack (not very likely to ever actually happen to a small gameserver)
one would need control over the gateway and 10gb nics (or the equivilent in bonded nics) and static routing
a firewall is secondary and gets to be a pain in the ass at that network level
monitoring filtering and creative routing.... (which use up a lot of server resources)
most attacks are in the 1gbs range though and easy to manage with a gigabit nic and good firewall rules .... past 3gb/s though just dropping packets will not help much
an ip failover though if properly setup from a seperate source / subnet would be a valid way to mitigate it however it would have to be an external system with the sub system running though it
if they attacked both gateways at the same time though then you would be in a pickle
most effective way to mitigate a ddos attack is to essentially let it in .....
but to filter the "unwanted traffic" to a different source (hint freebsd stateful packet filtering )
(as long as it has someplace to go then it doesnt slow the network)
.... the original source of the attack is usually a good place to send it if u have high speed nics
but if you dont have multiple or high volume network cards to speed them back to the source an internal source would work just fine ...
especially an internal network between bonded physical nics and or virtual nics
a crappy windows xp server with some honeypot software would work for a local source .... or a linux server with emultation if you want to be creative
the distributed denial of service protection that comes included with all my servers is mitigated up to 400gb/s

(yes that number is correct) as well as have hardware firewall options and network level virus filtering
paying for multiple services is wasting your money talk to your hosting provider and see what they can do for you before going to some website and adding another bill to a donation based gameserver