Greetings! Mentions of RTBH or Bogons is like the Bat-signal for us at Team Cymru… In the world outside of Tier 1s, RTBH is one of a few DDOS mitigation techniques that a provider can utilize. Budgets are tight or get eaten up by other priorities so ISPs and enterprise networks have to rely on what their upstream provides in the free-99 realm. I haven’t heard of an upstream provider not offering RTBH (although I am sure it happens). UTRS was the braind-child of JTK and it is still running strong at TC. We see multiple signups weekly. It is a distributed RTBH model, so the null-route is handled by the entire community, not just the immediate upstream of the victim network, and it does support flowspec. Is it perfect or will it replace a scrubber? No, nor was it intended to. But it's efficacy grows with more adoption by larger networks. We will be rolling out some new features later this year so please stay-tuned! https://www.team-cymru.com/ddos-mitigation-utrs-services Thanks, Scott
On Jul 27, 2026, at 5:14 PM, David Bass via NANOG <nanog@lists.nanog.org> wrote:
RTBH is absolutely used to thwart DDOS attacks right now in production at some extremely large, and constantly attacked organizations that I’ve personally seen.
As far as use by attackers…possibly used as well, but haven’t witnessed this one.
David
On Mon, Jul 27, 2026 at 2:50 AM Saku Ytti via NANOG <nanog@lists.nanog.org> wrote:
Is there consensus that RTBH is desirable?
Isn't RTBH just aiding the attacker and extending the duration of outage outside the duration of attack? With RTBH implemented, how do we know when the issue subsides? Do we periodically remove RTBH to check?
I think downgrading traffic to scavenger class via a BGP community is superior to RTBH, you are transporting as much as you can, but yielding to best effort. This gives you observability, you know when the issue subsides, as you're still getting the packets, so you can automatically remove the downgrade, the moment the attack subsides. On your end you can push this market traffic to monitor box, scrubber box, through ACL, null0 or whatever is locally prudent right now.
On Mon, 27 Jul 2026 at 10:41, James Bensley via NANOG <nanog@lists.nanog.org> wrote:
Dear Community,
RTBH is not as effective as it could be, for various reason, just a few
include:
* Not all networks support RTBH. * Networks that do support RTBH implement it differently to each other. * There is no one place where one can easily find the info for how to
* Operators have different ideas about how / when / where / why someone should / shouldn't use RTBH.
To this end, below is the first of two surveys. This first one is quantitative and captures how networks have implemented RTBH and provides (1) a public repository which anyone can use to look-up the RTBH details for their peers/upstreams, and (2) an insight into the (mis-)alignment of RTBH implementations across the industry.
Please take the time to fill out the short survey for your own network (even if you don't support RTBH!), and if you can, please fill it out for other networks where you know how they have implemented RTBH (e.g., peers you use RTBH with): https://docs.google.com/forms/d/e/1FAIpQLScg2Bvr_14onOtZRdoK2SNd0kCHFtqsdw-e...
(^ No login required)
The data ends up in this public repository (you can of course make a
use RTBH with a given network. pull request directly if you want): https://remotely-triggered-black-hole.github.io/rtbh/
The second survey will be qualitative, to gather information from the
industry community on why you do / don't support RTBH, when do you use it, how do you think the routing should be secured, etc.
The long term goal is to use the data from both surveys as input in to a
community effort to improve RTBH alignment across the industry and improve it's effectiveness for all (e.g. maybe produce a new BCOP for implementing RTBH, or usage guidelines for blackholing, or maybe a new RFC is required to secure the filtering; regardless, the first step is to gather data about the status quo and review that data to get a baseline of where we are at today).
Any questions, please let me know, and thank you for your time and help,
it is appreciated.
With kind regards, James_______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/LOWUU7RH...
-- ++ytti _______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/ITDOCC6N...
_______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/KH6VPK6D...