26 Nov
2008
26 Nov
'08
6:53 a.m.
One of my customers, a host at 64.8.105.15, is feeling a "bonus" ~130kpps from 88.191.63.28. I've null-routed the source, though our Engine2 GE cards don't seem to be doing a proper job of that, unfortunately. The attack is a solid 300% more pps than our aggregate traffic levels.
Null routing the source isn't going to stop the inbound packets from reaching the target of the attack. All that's going to do is blackhole packets back to the attacker from anyone hopping through the router carrying the null route. - Darrell