- Joined
- Nov 14, 2012
ask for a private address.
Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
ask for a private address.
PFSense can be a fucking whore to set up, and its not exactly suited to handle any ddos without proper configuration. Also, you'd have to turn an entire server into a router, CCR1016 has 16 cores @ 1.2Ghz, and yetPFSense does the same thing with High Availability Routing:
High Availability | pfSense Documentation
docs.netgate.com
I was mistaken that the routers would be unable to Round Robin without something in the middle to handle the traffic. Too much time in TEH CLOUD.
Yet again, cpu usage is mostly dependant on firewall rules - how properly or improperly they're made. No router/switch/ASA will save you if don't attempt to mitigate it properly.CPUs are all at 100%
Well I CAN'T attempt to mitigate it properly because if it's not blocking it with overly-strict rules I can't fucking access the router managementYet again, cpu usage is mostly dependant on firewall rules - how properly or improperly they're made. No router/switch/ASA will save you if don't attempt to mitigate it properly.
You won't be able to access it on any other router either way if its kept like this, that's the joke itself. DDOS mitigation is a long process of adjusting limits until it works just right.I can't fucking access the router management
1. Don't buy a server and turn it into a router. That's fine for playgrounds, not for production.PFSense can be a fucking whore to set up, and its not exactly suited to handle any ddos without proper configuration. Also, you'd have to turn an entire server into a router, CCR1016 has 16 cores @ 1.2Ghz, and yet
Yet again, cpu usage is mostly dependant on firewall rules - how properly or improperly they're made. No router/switch/ASA will save you if don't attempt to mitigate it properly.
Yeah - normal approach is Colo Handoff -> Router -> Switch. You only need two SFP+ ports on the router, unless you actually need to route more than just your internet traffic (You can even have a router with a single port, but not want you need - so called "router on a stick" approach with VLANs)Can the switch take a 10Gbps uplink and then offer 10Gbps lines to all devices? I'm confused
I'd make a specific argument here - Null needs effectively an Anti-DDOS appliance. If the best way to do that is a Linux server, then I'd go for it. Stripping crap traffic (without super expensive routers with dedicated hardware) is going to require CPU grunt over anything. This is also a web forum, not a Fortune 500 enterprise, so I'd be hesitant to reccomend the super expensive shit. Especially if the attackers just change to saturating the interface instead, which no router or firewall is going to fix. Don't buy a server and turn it into a router. That's fine for playgrounds, not for production
I'd assume they're doing it behind 7 proxiesQuestion do you have ip ranges that DDoSed the farms? Were they static or did they change location? Blanket blocking traffic from China wouldn't harm anyone for example.
They also wasted thousands upon thousands of dollars too lmaothe best part about the whole attack is that it accomplishes nothing long term. the only thing they accomplished is wasting their time.
And once again, the bills come in to greet them. And their landlords are wondering why they haven't paid in three days.They also wasted thousands upon thousands of dollars too lmao