[c-nsp] DDoS Attack detection and elimination suggestions

Lee Starnes lee.t.starnes at gmail.com
Fri Apr 1 01:08:54 EDT 2011


Hi,

I'm looking for pointers on how to best detect DDoS attacks and best
practices for stopping one once identified. Our current platform is using
12008 GRP-B routers, but I know they have their limits on what they can
handle when seeing things like 900000 packets per second input rates.

What is recommended as a replacement router and what would be recommended if
the routers are not replaced? Is there an easy way to see and identify the
traffic on these existing routers or is there a way to do something similar
to RSPAN on the switches that will allow me to see this traffic?

Any help or direction to resources would be greatly appreciated.

Thanks,

Lee.


More information about the cisco-nsp mailing list