2021 DDoS Issue

2503562-Tina-Reber-Quote-You-don-t-really-know-how-much-you-miss-someone.jpg
 
I honestly cannot understand how can someone actually spend time and money on DDoSing Kiwifarms. What would it achieve? Do they think that the website would just die after a few days of DDoS? Kiwifarms in it's current iteration is 8 years old, it have seen worse shit than that.

Most troons are getting gibs because they are unemployable freaks. They have nothing to do all day but seethe and dilate.
 
You may want two devices - on dedicated to simply filtering out ddos and the second doing actual routing and fire walling

you want a 1G burst able to 10g line so you don’t have to pay for the whole 10G when not being ddos’d

An entirely unrelated IPv6 range that’s only know to you can be used as a management interface but lock that shit down like no tomorrow.
 
I am also a big fan of Mikrotik RouterOS systems, they are very simple to setup, manage, and apply firewall/access rules to. I've run multiple ones for SMB's and they are rock solid.

The CRS326-24S+2Q+RM is overkill as he will never get a QSFP+ line run from the Colo to his rack unless it's sub 10M. The cable cost alone will be fucking insane. A 10gbps native RouterOS built device CCR1036-8G-2S+ will give Dual 10gbps connetions to the colocation for redundancy, redundant power, and an m.2 slot for a quick network cache. Downside is only 8 network ports @ 1gpbs. I'd have to look to see if you can bond multiple lines together via the device.

I'll assume @Null that your server(s) have 1gb network cards in them? Would you be willing to upgrade them, or can you upgrade them, to 10gbps cards?

I personally would stay away from Fiber at all costs unless you want to go full on fiber for everything at which there are other models of Routers to recommend. Fiber is expensive and there is little to gain from using fiber sub 10gbps speed.

At some point you will reach the tipping point of separating your Router from your Switch for 2 devices. In fact that might be a better idea to have TWO routers in a Round Robin mode to alleviate some of the stress on your router. This will require some networking guru work and some special software but you alleviate the bottleneck and make it difficult (not impossible) to take your network down.

PFSense is a fantastic piece of software and very customizable, buy the hardware which comes with a support contract and you'll get some Sales Engineer support as well to advise you on Best practices:

Whatever you do, at this rate, DO NOT ROLL YOUR OWN ROUTER SOFTWARE AND INSTALL IT ON A SERVER! DO NOT! NO NO NO NO NO. Your life is fucking hell as it is, and to troubleshoot HARDWARE as well as SOFTWARE is a pain in the proverbial dick. If you want to enjoy your time in Estoniastan spend the money get a refurb ENTERPRISE grade equipment and call it a day. It's cute for the house but not for high traffic sites like this. If you like sleep you won't do this.

P.S. Don't hate me for tagging you.
 
I'll assume @Null that your server(s) have 1gb network cards in them? Would you be willing to upgrade them, or can you upgrade them, to 10gbps cards?
c1:00.0 Ethernet controller: Intel Corporation Ethernet Controller 10-Gigabit X540-AT2 (rev 01)
c1:00.1 Ethernet controller: Intel Corporation Ethernet Controller 10-Gigabit X540-AT2 (rev 01)

I bought a really fancy 10Gbps ethernet card after our mobo's network card blew.
 
You may want two devices - on dedicated to simply filtering out ddos and the second doing actual routing and fire walling

you want a 1G burst able to 10g line so you don’t have to pay for the whole 10G when not being ddos’d

An entirely unrelated IPv6 range that’s only know to you can be used as a management interface but lock that shit down like no tomorrow.
The colo will still charge you for the 95th percentile of usage for the month so he might as well pay for the 10gb line and enjoy it all he wants as he is going to start streaming video which sucks up bandwidth like a mother fucker.

Also, making your management interface on the PUBLIC network is fucking insane, as you did say to lock it down, I concur with that assessment. A completely separate network device with a VPN connection on IPV6 which then allows you to tunnel through to your Management Consoles is a good idea. Purchase that networking service through a completely different company that has 0 to do with the farms for ultimate security through obscurity. Two-Factor-Authentication for VPN access is even better.
 
Back