On Nov 14, 2023, at 00:12, Shawn L via NANOG <nanog@nanog.org> wrote:

The destination address is always one of our customer's ip addresses.

Attackers will sometimes use synthetic ESP, AH, GRE, or other protocols in DDoS attacks, because organizations often only think about TCP/UDP/ICMP in terms of ACLs, DDoS defense mechanisms, etc.

--------------------------------------------

Roland Dobbins <roland.dobbins@netscout.com>