Jump to content

"BGP DDoS Protection"

Mornincupofhate

So I was browsing some cloud mitigation solutions online and I came across a few companies that give you a gre tunnel, but also re route your traffic to a scrubbing center during an attack. Couldn't they just scrub at the data center where the gre route is located? There's something I'm just not understanding here.

Link to comment
Share on other sites

Link to post
Share on other sites

Sounds like the idea is to provide DDoS mitigation only when its actually needed, rather than on a full time basis.  Thus reducing loading on the tunneling.  So if there is an attack, the BGP routes for your particular AS are altered.  Otherwise, they remain fully pointing at your hardware.

 

Sounds like a reasonable compromise.  After all, most hosts will only be the subject of occasional DDoS attacks, and it would be a giant waste of network resources to have everything routed through a 'scrubbing center'. 

Link to comment
Share on other sites

Link to post
Share on other sites

Routing traffic through a proper DDoS scrubbing cloud all the time would be really expensive. And I mean ridiculously expensive compared to a normal GRE tunnel connection.

Link to comment
Share on other sites

Link to post
Share on other sites

You able to name the service you were looking at? Would be interested in checking them out.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×