22 Oct
2016
22 Oct
'16
12:20 p.m.
On 22 October 2016 at 16:40, marcel.duregards--- via NANOG <nanog@nanog.org> wrote:
What about BCP38+84 on 30 tier-1 instead of asking/hoping 55k others autonomous-system having good filters in place ?
The originating ISPs are in a far better position to check that traffic isn't from spoofed address ranges than transit networks are. The best thing to do is to ask EVERY network to do what they can, not just the few biggest ones. Any size ISP can be hit by and hurt by DDoS attacks, so every size ISP should be doing what they can to make sure they are not either the source or the victim of those attacks. Dan