11-25-03 DDoS Juniper Filter

25 Jan
2003
25 Jan
'03
8:17 a.m.
We have installed the following on all network ingress/egress points, and have found it to filter the packets in question very effectively:
show configuration firewall filter filter-012503 term deny-dos { from { packet-length 404; protocol udp; destination-port 1434; } then { count codered-4; discard; } } term allow-rest { then accept; }
--Phil ISPrime
8120
Age (days ago)
8120
Last active (days ago)
0 comments
1 participants
participants (1)
-
Phil Rosenthal